Owning the architecture of compliance, the full-time GRC Program Architect will design and implement a governance, risk, and compliance framework, ensuring alignment with standards such as FedRAMP, CMMC, and SOC 2 while working remotely. Key responsibilities Design and implement Onebrief's GRC framework across various compliance standards Build and manage the control environment, including policies and evidence collection systems Collaborate with engineering teams to translate compliance requirements into effective technical controls Required qualifications 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks Hands-on experience implementing technical security controls such as IAM and encryption Working knowledge of security control frameworks like NIST 800-53 or NIST 800-171 Experience managing third-party audits and assessor relationships