Onebrief Logo

Onebrief

Senior Program Architect - Governance, Risk, and Compliance

Sorry, this job was removed at 11:43 a.m. (CST) on Friday, Sep 11, 2026
Remote
Hiring Remotely in United States
160K-200K Annually
Senior level
Remote
Hiring Remotely in United States
160K-200K Annually
Senior level

Similar Jobs at Onebrief

3 Days Ago
Remote or Hybrid
United States
205K-255K Annually
Senior level
205K-255K Annually
Senior level
Software • Defense
Lead and develop the SRE team responsible for reliable, secure deployments across on-premises DoD and AWS environments. Own capacity planning, prioritization, reliability roadmaps, operational readiness, incident response, observability, and toil reduction. Coordinate delivery across engineering, security, and customer success teams while guiding infrastructure, automation, Kubernetes, CI/CD, networking, and application reliability decisions. Manage team performance, hiring, career development, on-call practices, postmortems, and stakeholder communication.
Top Skills: AnsibleAWSAws GovcloudBashCi/CdDatadogElkGitopsGoGrafanaHyper-VIcd 503Infrastructure As CodeKubernetesNode.jsNutanixProxmoxPythonRmfSlisSlosStigsTerraformTypescriptVMware
4 Days Ago
Remote
United States
151K-184K Annually
Senior level
151K-184K Annually
Senior level
Software • Defense
Create and maintain cohesive brand designs across marketing campaigns, digital and print collateral, social media, email, advertisements, trade shows, websites, and sales enablement materials. Translate complex technical concepts into accessible visuals, uphold brand guidelines, manage multiple projects and timelines, and collaborate with marketing, sales, product teams, and external vendors.
Top Skills: Adobe Creative SuiteCSSFigmaHTMLIllustratorIndesignPhotoshopSketch
5 Days Ago
Remote
United States
100K-123K Annually
Entry level
100K-123K Annually
Entry level
Software • Defense
Supports the Facility Security Officer in administering the company’s industrial security program. Responsibilities include coordinating personnel security processes, clearance onboarding and offboarding, briefings, visit requests, records management, government security system administration, DCSA review preparation, corrective-action tracking, insider-threat support, and process improvement. The role also serves as an employee resource for security questions and provides backup FSO responsibilities when delegated.
Top Skills: AccsDissJpcNbisNiss
Design and operate Onebrief's GRC program across RMF, FedRAMP, CMMC and SOC 2. Build control environments, partner with engineering to implement technical controls (IAM, logging, encryption, segmentation), manage audits and evidence collection, and serve as the compliance lead for customer security reviews.
The summary above was generated by AI
Consequential Work. Dedicated People.
About Onebrief

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination.

Military planning is complex by nature, requiring teams to coordinate information, people, and decisions across systems and locations. Onebrief brings planning, collaboration, simulation, and AI into one connected environment, helping teams test strategies, adapt to changing conditions, and make decisions with greater clarity when the stakes are real.

We are a distributed team of builders from military, operational, and technology backgrounds who care deeply about improving how important work gets done. Some team members work remotely, while others work directly alongside customers in operational environments around the world.

Founded in 2019, Onebrief is backed by leading investors including General Catalyst, Battery Ventures, Insight Partners, Sapphire Ventures, and Human Capital. Valued at more than $2 billion, we continue to invest in product innovation, AI capabilities, and team growth.

Why This Role Exists

Onebrief sells to defense and government customers. Those customers require proof, not promises, that our systems protect their data. We need a GRC Program Architect to inform and build the proof and keep it current as our compliance obligations grow.

This role owns the architecture behind our compliance posture. FedRAMP, CMMC, SOC 2, and international frameworks each impose different controls. Someone has to translate those requirements into systems, processes, and evidence that hold up under audit. That work falls to this person.

Compliance and security engineering can't operate as separate tracks here. Controls that exist only on paper don't protect anyone and don't survive an audit. This person will work hands-on with engineering to implement the technical controls that back up our compliance claims, not just document them after the fact.

The stakes are direct. A gap in our compliance program can block a contract, delay an authorization, or put customer data at risk. A strong program does the opposite. It opens doors to new customers and gives existing ones confidence to expand their use of our platform.

What You’ll Do

Core responsibilities:

  • Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.

  • Build and manage the control environment, including policies, procedures, and evidence collection systems.

  • Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT including access management, logging, encryption, and vulnerability management practices.

  • Partner with Engineering, Infrastructure, and Corporate IT to translate compliance requirements into working technical controls, not just documented ones.

Minimum Qualifications
  • 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role

  • Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks

  • Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption

  • Working knowledge of security control frameworks such as NIST 800-53 or NIST 800-171

  • Experience managing third-party audits and assessor relationships

  • Strong written communication skills, with the ability to translate regulatory language into clear technical and internal guidance

Preferred Qualifications
  • Experience in a startup or scaling company environment

  • Background in military, defense, or government contracting

  • Relevant certifications, such as CISSP, CISA, CRISC, or a technical security certification (AWS Solutions Architect)

  • Experience building GRC automation using infrastructure-as-code or scripting

Indicators of Success

This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.

A successful GRC Program Architect will:

  • Identify and remediate at least one significant security control gap before it surfaces in an external audit

  • Serve as the trusted point of contact for customer security questionnaires and compliance inquiries

  • Be recognized by engineering and security teams as a partner who makes compliance workable and technically sound, not just another gate to pass

  • Win buy-in from engineering leads who previously treated compliance requests as low priority

  • Get through a customer or third-party security review without escalations or fire drills

Tools, Systems & Technologies (Optional)

Experience with GRC platforms (such as RegScale, eMASS, or similar), cloud security tooling relevant to Federal environments, logging systems, CI/CD pipelines, and infrastructure-as-code for control automation is a plus.


Notice to Third Party Recruitment Agencies

Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account