GRC & Control Design Engineer

Posted on July 30, 2026

Apply Now

Job Description

GRC & Control Design Engineer

Overview

We are seeking an experienced GRC & Control Design Engineer to lead the compliance architecture and control design for a FedRAMP vulnerability management program undergoing significant regulatory changes under the 2026 FedRAMP requirements. The selected candidate will translate approximately 22 VDR/VER requirements into practical, measurable, and auditable security controls. This role will work closely with security, engineering, compliance, and audit teams to ensure that vulnerability management tools, processes, workflows, and technical implementations meet FedRAMP expectations and satisfy 3PAO assessors and federal agency requirements. The ideal candidate will have strong expertise in FedRAMP, NIST security controls, GRC, vulnerability management, audit readiness, control design, and compliance documentation, along with sufficient technical knowledge to evaluate APIs, JSON schemas, machine-readable compliance outputs, and system architecture decisions.

Key Responsibilities

  • Own the compliance architecture and control design for the FedRAMP vulnerability management program.
  • Translate approximately 22 VDR/VER regulatory requirements into clear, actionable, testable, and auditable security controls.
  • Design control evaluation rubrics, assessment criteria, and evidence requirements.
  • Define and implement accepted-vulnerability and risk-acceptance workflows aligned with updated FedRAMP requirements.
  • Support the transition from traditional POA&M-based processes to updated vulnerability acceptance and remediation workflows.
  • Develop and maintain vulnerability remediation requirements, including remediation SLAs, risk classifications, and escalation procedures.
  • Create and maintain compliance documentation, including:
    • Security policies
    • Control narratives
    • Standard operating procedures
    • System Security Plan (SSP) content
    • Control implementation statements
    • Audit evidence requirements
    • ATO package documentation
  • Ensure vulnerability management processes align with FedRAMP, NIST SP 800-53, CISA BOD 26-04, and other applicable federal security requirements.
  • Validate machine-readable FedRAMP JSON outputs for completeness, accuracy, schema compliance, and regulatory alignment.
  • Review API outputs, JSON schemas, system integrations, and technical architecture decisions from a compliance and security perspective.
  • Work with engineering and security teams to identify compliance implications of design and implementation decisions.
  • Define evidence automation approaches to improve control validation, continuous monitoring, and audit readiness.
  • Support 3PAO assessments, federal agency reviews, audit preparation, and compliance evidence collection.
  • Develop control testing procedures and support remediation of audit findings and compliance gaps.
  • Support continuous monitoring activities and ensure controls remain effective throughout the system lifecycle.
  • Collaborate with vulnerability management, DevSecOps, engineering, product, and GRC teams.
  • Track compliance activities, control gaps, remediation actions, and audit deliverables using Jira or similar tools.
  • Provide subject-matter guidance on FedRAMP compliance, vulnerability risk, control implementation, and regulatory changes.

Required Skills and Experience

  • 6–8 years of relevant experience in GRC, cybersecurity compliance, security controls, vulnerability management, or security architecture.
  • Strong hands-on experience with FedRAMP compliance and authorization requirements.
  • Experience working with 3PAO assessments, audit evidence, control testing, and federal compliance reviews.
  • Strong knowledge of NIST SP 800-53 security and privacy controls.
  • Experience designing, implementing, and assessing security controls.
  • Strong understanding of vulnerability management processes and vulnerability lifecycle management.
  • Experience with VDR/VER compliance requirements and FedRAMP vulnerability reporting.
  • Strong knowledge of CVSS, vulnerability severity classification, risk evaluation, and remediation prioritization.
  • Experience defining vulnerability remediation SLAs and risk-based remediation workflows.
  • Knowledge of POA&M processes, risk acceptance, accepted vulnerabilities, and compensating controls.
  • Understanding of CISA BOD 26-04 and applicable federal vulnerability management requirements.
  • Experience with OSCAL and machine-readable security authorization artifacts.
  • Knowledge of FedRAMP JSON, JSON schemas, and structured compliance data.
  • Ability to review and validate API outputs and technical integrations for compliance requirements.
  • Experience developing or reviewing System Security Plans (SSPs) and ATO packages.
  • Strong understanding of continuous monitoring and compliance evidence collection.
  • Experience with evidence automation and automated control validation.
  • Knowledge of NIST SP 800-190 and container security principles.
  • Understanding of the Secure Software Development Framework (SSDF).
  • Experience using Jira or similar tools for compliance tracking and remediation management.
  • Strong documentation, analytical, stakeholder-management, and communication skills.

Preferred Qualifications

  • Experience supporting FedRAMP authorization or reauthorization initiatives.
  • Prior experience working directly with 3PAOs, federal agencies, or government cloud environments.
  • Experience with automated compliance platforms and security evidence collection tools.
  • Knowledge of cloud security architecture and cloud vulnerability management.
  • Experience with responsible disclosure programs and vulnerability intake processes.
  • Familiarity with DevSecOps, secure software development, and security automation.
  • Experience evaluating security architecture decisions for regulatory and compliance impact.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CAP, CCSP, or equivalent are preferred.

Key Competencies

  • Strong regulatory interpretation and control-design capabilities.
  • Ability to convert complex compliance requirements into practical technical controls.
  • Strong understanding of security risk, vulnerability remediation, and risk acceptance.
  • Ability to communicate compliance requirements clearly to technical and non-technical stakeholders.
  • Strong attention to detail and documentation quality.
  • Ability to work independently in a remote, cross-functional environment.
  • Strong audit-readiness, evidence-management, and problem-solving skills.

Engagement Details

  • Role: GRC & Control Design Engineer
  • Experience: 6–8 Years
  • Engagement Type: Contractual
  • Duration: 6 Months
  • Work Mode: Remote
  • Timezone: India (IST)

Candidate Requirements

  • Candidates should have relevant hands-on experience in FedRAMP, GRC, security control design, and vulnerability management.
  • Strong experience with 3PAO assessments, SSP documentation, ATO packages, and audit evidence is required.
  • Candidates must be comfortable reviewing technical artifacts such as APIs, JSON outputs, JSON schemas, and system architecture decisions.
  • Immediate or short-notice joiners will be preferred.
  • Candidates should be available for the complete 6-month contractual engagement.

Required Skills

No specific skills listed.

Community Discussion

Ask questions, share feedback, or discuss this opportunity. Your comment will be visible to everyone.
Be the first to share your thoughts on this opportunity.

Clarification Board

Your Clarifications
"Send your Job Related Query - you'll get a reply soon."