Position: GRC & Control Design Engineer — FedRAMP VDR/VER Compliance
Engagement Mode: Not specified
Location: Not specified
Position Overview:
This role owns the compliance architecture of a FedRAMP vulnerability
management program undergoing
significant regulatory change under the 2026 FedRAMP rules. The position is
responsible for translating
approximately 22 VDR/VER requirements into concrete, auditable controls,
ensuring that tooling and
processes satisfy 3PAO assessors and federal agencies. The engineer will
design evaluation rubrics, define
accepted-vulnerability workflows replacing POA&Ms;, author the full
documentation set including policies
and control narratives, and validate machine-readable FedRAMP JSON outputs.
The role sits at the
intersection of GRC, security compliance, and technical architecture,
requiring both deep regulatory
expertise and sufficient technical literacy to evaluate API outputs, JSON
schemas, and system architecture
decisions for compliance consequences. The engineer will also support audit
readiness and advise
engineering teams on compliance implications of implementation choices.
Key Responsibilities:
• Own the control-to-requirement traceability matrix: map every VDR/VER rule
(MUST/SHOULD/SHOULD
NOT) to a specific control, tool capability, or process, and track coverage to
22/22
• Design the PAIN evaluation rubric and the policies behind the LEV × IRV ×
N-rating scoring model,
including evaluation factors, evaluation SLAs (2–14 day windows), and
false-positive adjudication
• Define the accepted-vulnerabilities process replacing POA&Ms;: formal
documentation standards,
rationale/evidence string formats, the >192-day marking workflow, and
responsible-disclosure alignment
• Author the documentation set: vulnerability management policy, control
narratives, standard operating
procedures, timeframe/SLA definitions per certification class, and the audit
narrative for the new
architecture
• Validate that platform outputs (FedRAMP VDT/AVI/MRH JSON exports, monthly
human-readable
reports) meet schema and content requirements; run a dry-run against a
realistic agency scenario
• Define evidence-collection requirements so that remediation, evaluation
decisions, and SLA adherence
are provable — including boundary controls (e.g., keeping vulnerability
metadata out of
Jira/outside-boundary systems)
• Prepare the audit pack and support 3PAO assessment readiness; brief internal
stakeholders on what
changes for them
• Advise the engineering team when implementation choices have compliance
consequences
Required Skills:
• 5+ years in GRC, security compliance, or audit roles with direct FedRAMP
experience
• Experience with ATO packages, SSPs, continuous monitoring, and 3PAO
assessments
Deep familiarity with vulnerability management compliance: scanning
requirements, remediation SLAs,
POA&M; lifecycle, deviation/risk-acceptance processes
• Proven control design skills: ability to take regulatory text and produce
implementable, testable controls
and supporting documentation
• Strong technical literacy — able to read API outputs, JSON schemas, and
architecture diagrams and
judge whether they satisfy a requirement
• Excellent writing skills: policies, control narratives, and audit-facing
documentation that hold up under
assessor scrutiny
Preferred (Bonus) Skills:
• Working knowledge of the FedRAMP 2026 VDR/VER rules and CISA BOD 26-04
• Demonstrated ability to rapidly master new regulatory frameworks
• Experience with NIST SP 800-53
• Experience with SSDF (Secure Software Development Framework)
• Familiarity with container-relevant guidance (NIST SP 800-190)
• Prior involvement in a compliance-driven tooling migration or
evidence-automation initiative
• Familiarity with machine-readable compliance reporting (OSCAL)
• Familiarity with FedRAMP JSON schemas
Apply through whichever channel suits you best.