Abnormal AI is looking for a Security & Compliance Analyst, Public Sector who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company.
You will work at the intersection of security engineering, cloud operations, security, and federal compliance, helping Abnormal Gov scale its FedRAMP High/Class D security and compliance program. You will own security requirement implementation and evidence, work directly with technical teams to drive risk and remediation to closure, and help build our compliance-as-code capabilities in alignment with FedRAMP 20x.
You'll have meaningful ownership early, with the opportunity to improve processes rather than simply inherit them.
What you'd do
- Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness
- Drive recurring continuous monitoring and evidence workflows, coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is current, complete, traceable, and retained correctly
- Support vulnerability detection and response, including reconciling findings from tools such as Wiz, Nessus, and Burp; risk-based triage; Jira routing; SLA tracking; remediation follow-through; validation; and audit-ready evidence
- Partner with technical teams on security and compliance impact, supporting Security Impact Assessments, Significant Change Requests, control implementation decisions, and other change-management activities before changes reach production
- Help build Abnormal's compliance-as-code program, including structured control content, JSON/YAML or other machine-readable artifacts, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows
- Maintain accurate control, evidence, remediation, risk, and ownership records, proactively identifying gaps, aging items, dependencies, and decisions requiring escalation
- Contribute to federal authorization and assessment artifacts, including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables
- Support federal customer assurance by providing clear, accurate compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government or regulated customer requests
What they want
- 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment
- Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence
- Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring
- Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions
- Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance
- Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders
- Strong operational discipline: you can manage multiple workstreams, dependencies, owners, and deadlines while identifying problems and escalating risk early
- A demonstrated tendency to improve the way work gets done through automation, better processes, clearer documentation, reusable templates, better data, or simpler workflows