GRC & Control Design Engineer FedRAMP VDR/VER Compliance

SPARIX GLOBAL PRIVATE LIMITED
Posted on

Experience
6 - 8 yrs
Job Location
Noida, India
Vacancy
1
Designation
GRC Consultant
Job Type
Not specified

Job Description

Title :- GRC & Control Design Engineer FedRAMP VDR/VER Compliance
Job Type :- Remote IST
Experience:- 6 - 8 years


Position Overview

This role owns the compliance architecture of a FedRAMP Vulnerability Detection & Response (VDR) program undergoing significant regulatory changes under the 2026 FedRAMP rules.

The position is responsible for translating approximately 22 VDR/VER requirements into concrete, auditable controls, ensuring that tooling and processes satisfy 3PAO assessors and federal agencies.

The engineer will:

  • Design evaluation rubrics.
  • Define accepted-vulnerability workflows replacing POA&Ms.
  • Author the complete documentation set, including policies and control narratives.
  • Validate machine-readable FedRAMP JSON outputs.

The role sits at the intersection of Governance, Risk & Compliance (GRC), security compliance, and technical architecture, requiring both deep regulatory expertise and sufficient technical literacy to evaluate API outputs, JSON schemas, and system architecture decisions for compliance implications.

The engineer will also support audit readiness and advise engineering teams on compliance impacts of implementation choices.

Key Responsibilities
  • Own the control-to-requirement traceability matrix by:
    • Mapping every VDR/VER rule (MUST / SHOULD / SHOULD NOT) to specific controls, tools, or processes.
    • Tracking implementation coverage to 22/22 requirements.
  • Design the PAIN evaluation rubric and policies supporting the LEV IRV N-rating scoring model, including:
    • Evaluation factors
    • Evaluation SLAs (2 14 day windows)
    • False-positive adjudication
  • Define the accepted-vulnerabilities process replacing POA&Ms, including:
    • Documentation standards
    • Evidence and rationale formats
    • 192-day marking workflow

    • Responsible disclosure alignment
  • Author compliance documentation, including:
    • Vulnerability Management Policy
    • Control Narratives
    • Standard Operating Procedures (SOPs)
    • Timeframe/SLA definitions by certification class
    • Audit narratives for the new architecture
  • Validate platform outputs such as:
    • FedRAMP VDT JSON exports
    • AVI JSON exports
    • MRH JSON exports
    • Monthly human-readable reports
  • Perform dry-run validations using realistic federal agency scenarios.
  • Define evidence collection requirements to prove:
    • Remediation activities
    • Evaluation decisions
    • SLA compliance
    • Boundary controls (e.g., preventing vulnerability metadata from being stored in Jira or other out-of-boundary systems)
  • Prepare audit packages and support 3PAO assessment readiness.
  • Brief internal stakeholders on compliance changes and expectations.
  • Advise engineering teams whenever implementation decisions have regulatory or compliance implications.
Required Skills
  • 5+ years of experience in:
    • Governance, Risk & Compliance (GRC)
    • Security Compliance
    • Audit roles
    • Direct FedRAMP experience
  • Experience with:
    • Authorization to Operate (ATO) packages
    • System Security Plans (SSPs)
    • Continuous Monitoring
    • 3PAO assessments
  • Deep understanding of vulnerability management compliance, including:
    • Scanning requirements
    • Remediation SLAs
    • POA&M lifecycle
    • Risk acceptance and deviation processes
  • Proven experience designing implementable and testable security controls from regulatory requirements.
  • Strong technical literacy with the ability to review:
    • API outputs
    • JSON schemas
    • Architecture diagrams
    • Compliance validation
  • Excellent technical writing skills for:
    • Policies
    • Control narratives
    • Audit documentation
    • Assessor-facing documentation
Preferred (Bonus) Skills
  • Working knowledge of:
    • FedRAMP 2026 VDR/VER rules
    • CISA BOD 26-04
  • Ability to quickly learn new regulatory frameworks.
  • Experience with:
    • NIST SP 800-53
    • SSDF (Secure Software Development Framework)
    • NIST SP 800-190 (Container Security)
  • Prior experience with:
    • Compliance-driven tooling migrations
    • Evidence automation initiatives
  • Familiarity with:
    • OSCAL (Open Security Controls Assessment Language)
    • FedRAMP JSON schemas
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.