HHiring Reality
← Abnormal

FedRamp Compliance Analyst

Abnormal
Location
Remote - USA
Posted
19 days ago
Department
Security
What they actually want (must-haves)
  • 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment.
  • Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence.
  • Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring.
  • Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions.
  • Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance.
  • Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders.
Nice to have
  • Experience with FedRAMP High, FedRAMP Moderate, FISMA, CMMC, GovRAMP, or other U.S. government security frameworks.
  • Exposure to compliance-as-code, OSCAL, JSON/YAML schemas, Git-based workflows, automated validation, Markdown/PDF generation, or machine-readable authorization artifacts.
  • Familiarity with tools or environments such as AWS GovCloud, Wiz, Splunk, Okta, Jira, GitLab, Nessus, Burp, or cloud-native vulnerability-management platforms.
  • Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon workflows, 3PAO assessments, or federal authorization packages.
  • Basic scripting or automation experience—such as Python, APIs, CI/CD workflows, or data transformation —or a strong interest in developing those skills.
What the job really is

The Federal Security and Compliance Analyst at Abnormal AI will focus on enhancing the company's FedRAMP High/Class D security and compliance program. Daily responsibilities include managing security compliance workstreams, driving continuous monitoring processes, supporting vulnerability detection and response, and collaborating with technical teams on compliance impacts. The role emphasizes ownership and process improvement within a fast-paced cybersecurity environment.

Benefits
  • Base salary range: $114,800 — $173,250 USD
  • This role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.
Things to weigh
  • No specific details on the company's tech stack or tools used beyond those mentioned in the nice to have section.
  • The role involves navigating ambiguity, which may require a high level of adaptability and problem-solving skills.
  • The position is remote, which may impact team dynamics and communication.
Job score2.8/5
Benefits1/5
Freshness4/5
Career value4/5
Role clarity5/5
Pay transparency0/5

Applying to Abnormal?

See how your résumé matches this role — and tailor it from what actually gets interviews.