חברות הייטק בישראלOligo SecurityGRC Specialist (US Citizen,IL Based)

GRC Specialist (US Citizen,IL Based)

Oligo Security logo
Oligo Security· Computer and Network Security
Tel Aviv, IsraelFULL_TIME

כישורים מהמשרה

Governance, Risk & Compliance (GRC)FedRAMP authorization (SSP, POA&M, continuous monitoring, 3PAO coordination)Security policies aligned with NIST 800-53SOC 2 Type II complianceISO 27001 complianceThreat modelingSecure code reviews and secure SDLCSAST/DAST integration into CI/CDVulnerability scanning and remediation workflowsPenetration testing and vulnerability management

תיאור המשרה

Description About us Oligo is a fast-growing cybersecurity startup transforming how organizations protect their applications, cloud environments, and AI systems at runtime. Backed by top-tier investors including Greenfield Partners, Red Dot Capital Partners, Lightspeed, Ballistic Ventures, and TLV Partners, we’re on a mission to make real-time security a reality. Oligo’s industry’s leading runtime security platform built to stop attacks in real time without stopping the business. We transform security from passive visibility to active protection across applications, cloud services, workloads, and AI systems. By uncovering the deepest layers of what actually runs in production, Oligo helps organizations prioritize exploitable vulnerabilities, detect malicious behavior as it happens, and stop modern attacks in their tracks. We're looking for a GRC Specialist to own and drive our compliance and authorization programs, with a strong emphasis on FedRAMP and NIST 800-53. This is a hands-on governance, risk, and compliance role for someone who can build and run a federal-grade compliance program from the ground up and manage it through continuous monitoring and reauthorization cycles. U.S. citizenship is required for this role due to FedRAMP and federal customer requirements. Key Responsibilities Own the FedRAMP process end-to-end: System Security Plan (SSP) development and maintenance, POA&M tracking and remediation, control implementation statements, and continuous monitoring (ConMon) deliverables Serve as primary point of contact for 3PAO assessments, coordinating testing, evidence collection, and finding resolution Maintain compliance programs across SOC 2 Type II and ISO 27001 Respond to customers security questionnaires, and support sales enablement with SSPs, control narratives, and other security documentation Partner with engineering, GTM, and leadership to ensure controls are implemented, evidenced, and operating effectively Monitor changes to FedRAMP requirements, NIST guidance, and federal compliance obligations, and translate them into actionable program updates Requirements Qualifications U.S. citizenship (required for FedRAMP program access and federal customer engagements) 3-5 years of hands-on GRC experience, with direct, demonstrable work on NIST control implementation and assessment Direct experience supporting or owning a FedRAMP authorization (Moderate or High baseline) - SSP authorship, POA&M management, or ConMon deliverables Solid understanding of the FedRAMP process, including 3PAO coordination Working knowledge of SOC 2 and ISO 27001 frameworks Excellent written English - you will be authoring SSPs, policies, and customer- and agency-facing documentation Strong cross-team communication skills and comfort working directly with auditors and assessors Ability to work independently and manage multiple compliance workstreams in a fast-paced environment Experience with GRC platforms (e.g., Vanta, Drata, Scytale, or similar) Nice to Have Relevant certifications: CISA, CISSP, CAP, or FedRAMP-specific training/certification Familiarity with cloud environments (AWS GovCloud, Azure Government) and their native compliance/control mappings
Oligo Security logo

על Oligo Security

Oligo Security is a runtime security platform that protects cloud applications from real-world attacks. Using deep application inspection, real-time monitoring, and context-aware analysis, Oligo helps teams discover vulnerabilities in production, prioritize what matters, and stop application-based exploits at runtime. Download the new CADR for Dummies guide: https://www.oligo.security/cadr-for-dummies

לעמוד החברה

עוד משרות ב-Oligo Security