Onebrief is collaboration and AI-powered workflow software designed specifically for military staffs. By transforming this work, Onebrief makes the staff as a whole superhuman - meaning faster, smarter, and more efficient.
We take ownership, seek excellence, and play to win with the seriousness and camaraderie of an Olympic team. Onebrief operates as an all-remote company, though many of our employees work alongside our customers at military commands around the world.
Founded in 2019 by a group of experienced planners, today, Onebrief’s team spans veterans from all forces and global organizations, and technologists from leading-edge software companies. We’ve raised $123m+ from top-tier investors, including Battery Ventures, General Catalyst, Insight Partners, and Human Capital, and today, Onebrief is valued at $1.1B. With this continued growth, Onebrief is able to make an impact where it matters most.
What you will achieveYou will play a critical role in building and sustaining Onebrief’s cybersecurity compliance program. Leveraging your expertise with CMMC 2.0 and SOC 2, you will ensure compliance evidence is created, validated, and continuously organized in our GRC platform. You will lead efforts to automate control testing, close gaps, and prepare for audits, directly contributing to Onebrief’s ability to obtain and maintain accreditations.
About YouYou are a seasoned cybersecurity compliance professional with hands-on experience in industry frameworks and regulatory standards. You excel at translating complex compliance obligations into practical, cloud-native solutions. You thrive in remote, collaborative environments, enjoy solving compliance challenges with both precision and creativity, and are driven by continuous learning and professional growth. Most importantly, you are motivated by building secure, compliant IT ecosystems that enable organizations to scale with confidence.
Responsibilities
Maintain compliance documentation and evidence in the GRC platform
Coordinate internal assessments and readiness checks ahead of external audits
Partner with engineering and IT to design compliant cloud-native solutions
Track regulatory changes and advise leadership on compliance implications
Conduct periodic risk assessments and suggest appropriate risk treatment actions
Develop internal cybersecurity awareness and training presentations for employees
Conduct supply chain risk management assessments for current and future vendors
7+ years in Cybersecurity Compliance and related roles
Experience with GRC platforms and leveraging automated evidence collection and testing capabilities
Familiarity with cloud security standards (e.g., FedRAMP, ISO 27001, NIST 800-171)
Strong background in policy development, control testing, and evidence gathering
Excellent communication skills for working with both technical and non-technical stakeholders
Certifications (one or more required):
CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA
Must-Have Skills and Qualifications:
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
Hands-on expertise with CMMC 2.0 and SOC 2 frameworksAbout Us
Compensation Range: $170K - $210K
#BI-Remote
Top Skills
Similar Jobs at Onebrief
What you need to know about the Colorado Tech Scene
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute