Title :- GRC & Control Design Engineer - FedRAMP VDR/VER Compliance
Job Type :- Remote IST
Experience:- 6 - 8 years
Position Overview
This role owns the compliance architecture of a FedRAMP Vulnerability Detection & Response (VDR) program undergoing significant regulatory changes under the 2026 FedRAMP rules.
The position is responsible for translating approximately 22 VDR/VER requirements into concrete, auditable controls, ensuring that tooling and processes satisfy 3PAO assessors and federal agencies.
The engineer will:
- Design evaluation rubrics.
- Define accepted-vulnerability workflows replacing POA&Ms;.
- Author the complete documentation set, including policies and control narratives.
- Validate machine-readable FedRAMP JSON outputs.
The role sits at the intersection of Governance, Risk & Compliance (GRC), security compliance, and technical architecture, requiring both deep regulatory expertise and sufficient technical literacy to evaluate API outputs, JSON schemas, and system architecture decisions for compliance implications.
The engineer will also support audit readiness and advise engineering teams on compliance impacts of implementation choices.
Key Responsibilities
- Own the control-to-requirement traceability matrix by:
- Mapping every VDR/VER rule (MUST / SHOULD / SHOULD NOT) to specific controls, tools, or processes.
- Tracking implementation coverage to 22/22 requirements.
- Design the PAIN evaluation rubric and policies supporting the LEV IRV N-rating scoring model, including:
- Perform dry-run validations using realistic federal agency scenarios.
- Define evidence collection requirements to prove:
- Remediation activities
- Evaluation decisions
- SLA compliance
- Boundary controls (e.g., preventing vulnerability metadata from being stored in Jira or other out-of-boundary systems)
- Prepare audit packages and support 3PAO assessment readiness.
- Brief internal stakeholders on compliance changes and expectations.
- Advise engineering teams whenever implementation decisions have regulatory or compliance implications.
Required Skills
- 5+ years of experience in:
- Governance, Risk & Compliance (GRC)
- Security Compliance
- Audit roles
- Direct FedRAMP experience
- Experience with:
- Authorization to Operate (ATO) packages
- System Security Plans (SSPs)
- Continuous Monitoring
- 3PAO assessments
- Deep understanding of vulnerability management compliance, including:
- Proven experience designing implementable and testable security controls from regulatory requirements.
- Strong technical literacy with the ability to review: