Responsibilities
- Maintain and enhance the System Security Plan, policies, procedures, and standards in alignment with NIST 800-53 and SOC 2 frameworks.
- Manage the full lifecycle of the Plan of Action and Milestones, including tracking, remediation validation, aging oversight, and monthly continuous monitoring reporting.
- Oversee the control evidence inventory, documenting existence, location, refresh dates, and upcoming renewals.
- Collaborate with U.S.-based security teams and third-party assessment organizations to support GovRAMP, FedRAMP, and state-level (TX-RAMP) authorizations and ongoing compliance.
- Lead the end-to-end third-party risk management program, including security assessments, due diligence reviews, contract evaluations, and periodic re-evaluations.
- Sustain the enterprise risk register, support risk acceptance processes, and communicate technical risks in business-appropriate terms to leadership.
- Ensure subcontractor agreements include required security obligations and protections for personally identifiable information.
- Monitor and verify compliance with security commitments across state customer contracts on schedule.
- Maintain and version-control the organization’s policy library using clear, non-generic language.
- Administer the security awareness training program, including phishing simulations and Rules of Behavior enforcement.
- Design, conduct, and document tabletop exercises with post-exercise reports that assign clear remediation actions.
- Coordinate with HR and IT on security aspects of employee onboarding and offboarding, access recertifications, and acceptable use policy enforcement.
Benefits
- Fully remote work setup
- Contribute to a platform that enables thousands to access workforce and education services
- Substantial ownership of a defined area within the GRC program
- Direct collaboration with security leadership, engineering teams, and executive stakeholders
- Opportunity to refine and improve policies, controls, and evidence collection processes
Work Arrangement
Remote (Worldwide)
Team
senior individual contributor
Other
- Must be based in the Philippines
- Required to work night shifts to align with U.S. team hours
- Expected to operate independently without extensive oversight
- Approaches compliance documentation as a skilled practice rather than a procedural formality