Onebrief is collaboration and AI-powered workflow software designed specifically for military staffs. By transforming this work, Onebrief makes the staff as a whole superhuman - meaning faster, smarter, and more efficient.
We take ownership, seek excellence, and play to win with the seriousness and camaraderie of an Olympic team. Onebrief operates as an all-remote company, though many of our employees work alongside our customers at military commands around the world.
Founded in 2019 by a group of experienced planners, today, Onebrief’s team spans veterans from all forces and global organizations, and technologists from leading-edge software companies. We’ve raised $320m+ from top-tier investors, including Battery Ventures, General Catalyst, Sapphire Ventures, Insight Partners, and Human Capital, and today, Onebrief is valued at $2.15B. With this continued growth, Onebrief is able to make an impact where it matters most.
About the RoleYou will play a critical role in building and sustaining Onebrief’s governance, risk and compliance program. Leveraging your expertise with NIST RMF and FedRAMP High, you will ensure compliance evidence is created, validated, and continuously organized in various GRC platforms. You will lead efforts to automate control testing, close gaps, and prepare for audits, directly contributing to Onebrief’s ability to obtain and maintain authorizations.
About YouYou are a seasoned cybersecurity compliance professional with hands-on experience in federal frameworks and regulatory standards. You excel at translating complex compliance obligations into practical, cloud-native solutions. You thrive in remote, collaborative environments, enjoy solving compliance challenges with both precision and creativity, and are driven by continuous learning and professional growth. Most importantly, you are motivated by building secure, compliant IT ecosystems that enable organizations to scale with confidence.
What You’ll DoLead and support the full NIST RMF lifecycle for Onebrief deployments, on-prem or cloud-native, across multiple security boundaries
Maintain, and review authorization packages, including SSPs, SAPs, SARs, POA&Ms, STIGs, and supporting artifacts
Coordinate internal assessments and readiness checks ahead of external audits
Partner with Engineers, Product teams, and Security leadership to integrate compliance requirements into system design and operations
Provide guidance on secure architecture and control implementation
Track regulatory changes and advise leadership on compliance implications
Conduct periodic risk assessments and suggest appropriate risk treatment actions
Develop internal cybersecurity awareness and training presentations for employees
Conduct supply chain risk management assessments for current and future vendors
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
Hands-on expertise with Risk Management Framework across multiple security domains
U.S. Citizen
8+ years in Cybersecurity Compliance and related roles
Experience with Enterprise Mission Assurance Support Service (eMASS) and leveraging automated evidence collection and testing capabilities
Familiarity with cloud security standards (e.g., FedRAMP, ISO 27001, NIST 800-171, DoD Cloud Computing Security Requirements Guide)
Strong background in policy development, control testing, and evidence gathering
Excellent communication skills for working with both technical and non-technical stakeholders
CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA
Proven ability to prioritize, adapt, and deliver under tight timelines in dynamic, compliance-driven environments
Experience in DoD environments and compliance frameworks (RMF and ICD 503)
Familiarity with agency-specific overlays (DoD, DHS, or civilian agencies)
Experience working with 3PAOs, Security Control Assessors, and Federal Customers
Notice to Third Party Recruitment Agencies
Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.
Top Skills
Similar Jobs at Onebrief
What you need to know about the Chicago Tech Scene
Key Facts About Chicago Tech
- Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
- Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
- Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
- Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

