About this role
Position Overview:
Our client is seeking a GRC & Control Design Engineer specializing in FedRAMP VDR/VER Compliance. This role is critical in owning the compliance architecture of a FedRAMP vulnerability management program, particularly in light of the significant regulatory changes expected under the 2026 FedRAMP rules. The engineer will be responsible for translating approximately 22 VDR/VER requirements into concrete, auditable controls, ensuring that tooling and processes meet the standards of 3PAO assessors and federal agencies.
Key Responsibilities:
- Own the control-to-requirement traceability matrix, mapping every VDR/VER rule to specific controls, tool capabilities, or processes, and tracking coverage to 22/22.
- Design the PAIN evaluation rubric and the associated policies for the LEV × IRV × N-rating scoring model, including evaluation factors and SLAs.
- Define the accepted-vulnerabilities process to replace POA&Ms, establishing formal documentation standards and workflows.
- Author a comprehensive documentation set, including vulnerability management policies, control narratives, and audit narratives for the new architecture.
- Validate platform outputs to ensure compliance with schema and content requirements, including running dry-runs against realistic agency scenarios.
- Define evidence-collection requirements to ensure provability of remediation and evaluation decisions.
- Prepare the audit pack and support 3PAO assessment readiness, briefing internal stakeholders on relevant changes.
- Advise the engineering team on compliance implications of implementation choices.
Required Skills:
- 5+ years of experience in GRC, security compliance, or audit roles with direct FedRAMP experience.
- Proficient in ATO packages, SSPs, continuous monitoring, and 3PAO assessments.
- Deep familiarity with vulnerability management compliance, including scanning requirements and remediation SLAs.
- Proven control design skills with the ability to translate regulatory text into implementable, testable controls.
- Strong technical literacy to evaluate API outputs, JSON schemas, and architecture diagrams for compliance.
- Excellent writing skills for policies, control narratives, and audit-facing documentation.
Preferred (Bonus) Skills:
- Working knowledge of the FedRAMP 2026 VDR/VER rules and CISA BOD 26-04.
- Experience with NIST SP 800-53 and SSDF (Secure Software Development Framework).
- Familiarity with container-relevant guidance (NIST SP 800-190) and machine-readable compliance reporting (OSCAL).
- Prior involvement in compliance-driven tooling migration or evidence-automation initiatives.
What we offer:
Our client provides a dynamic work environment, opportunities for professional growth, and the chance to work on impactful projects that shape the future of compliance in the technology landscape.