Abnormal logo

Abnormal

FedRamp Compliance Analyst

Work from homeNew this week

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it yesterday · Added yesterday

First listed yesterday.

Salary

$115k to $173k per year

Location

United States only

Timezone

US East

Contract

Full-time

Experience

Mid

Category

Software

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote - USA"

What Nomaders makes of it

  • Residency required in United States
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About the Role

Abnormal AI is looking for a Federal Security and Compliance Analyst who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company.

You will work at the intersection of security engineering, cloud operations, security, and federal compliance, helping Abnormal Gov scale its FedRAMP High/Class D security and compliance program. You will own security requirement implementation and evidence, work directly with technical teams to drive risk and remediation to closure, and help build our compliance as code capabilities in alignment with FedRAMP 20x.

You'll have meaningful ownership early, with the opportunity to improve processes rather than simply inherit them. The strongest candidate will be technically curious, highly organized, comfortable navigating ambiguity, and motivated by making compliance more accurate, automated, measurable, and operationally useful.

What you will do

Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness.

Drive recurring continuous monitoring and evidence workflows , coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is current, complete, traceable, and retained correctly.

Support vulnerability detection and response , including reconciling findings from tools such as Wiz, Nessus, and Burp; risk-based triage; Jira routing; SLA tracking; remediation follow-through; validation; and audit-ready evidence.

Partner with technical teams on security and compliance impact , supporting Security Impact Assessments, Significant Change Requests, control implementation decisions, and other change-management activities before changes reach production.

Help build Abnormal's compliance-as-code program , including structured control content, JSON/YAML or other machine-readable artifacts, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows.

Maintain accurate control, evidence, remediation, risk, and ownership records , proactively identifying gaps, aging items, dependencies, and decisions requiring escalation.

Contribute to federal authorization and assessment artifacts , including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables.

Support federal customer assurance by providing clear, accurate compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government or regulated customer requests.

Must Haves

2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment.

Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence.

Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring .

Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions.

Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance.

Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders.

Strong operational discipline: you can manage multiple workstreams, dependencies, owners, and deadlines while identifying problems and escalating risk early.

A demonstrated tendency to improve the way work gets done through automation, better processes, clearer documentation, reusable templates, better data, or simpler workflows.

Nice to Have

Experience with FedRAMP High, FedRAMP Moderate, FISMA, CMMC, GovRAMP, or other U.S. government security frameworks .

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Abnormal, mentioning your remote working experience and working hours (US East).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$115k to $173k per year · You'll be taken to the employer's careers page.