HimalayasHimalayas logo
DispelDI

Compliance Officer, FedRAMP (Remote- US Based)

Dispel provides Zero Trust Access solutions for industrial control systems (ICS) and operational technology (OT), specializing in moving target defense to secure critical infrastructure.

Dispel

Employee count: 51-200

Salary: 122k-151k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About Dispel

Dispel is the fastest-growing cybersecurity company recognized in the 2025 Cybersecurity Excellence Awards. We deliver zero-trust secure remote access and real-time data streaming for operational technology (OT) and industrial control systems (ICS). Our patented Moving Target Defense technology—referenced in NIST 800-172—protects critical infrastructure for utilities serving 54 million+ people, manufacturers producing over 50% of U.S. baby formula, and major defense programs including a $950M IDIQ with the U.S. Air Force

The Role

We’re looking for a Compliance Officer to own Dispel’s FedRAMP authorization and steward our broader portfolio of compliance certifications. You’ll be the primary interface with our agency sponsor, and internal engineering teams—translating complex federal requirements into actionable work while maintaining rigorous evidence collection and documentation practices.

This role is critical to unlocking the federal market and sustaining customer trust across regulated industries. You’ll have the opportunity to shape the program from the ground up at a pivotal moment of growth.

Requirements

FedRAMP Authorization (Primary Focus)

• Own the FedRAMP authorization lifecycle from SSP development through continuous monitoring.

• Serve as primary liaison with our agency sponsor and their FedRAMP AODR.

• Coordinate with our 3PAO on assessment readiness, evidence collection, and remediation tracking.

• Manage SSP, SAR, POA&M, and all FedRAMP deliverables in OSCAL formats.

• Track control implementation across all FedRAMP controls and maintain the Control Responsibility Matrix (CRM).

• Prepare for annual assessments and significant change requests; monitor PMO guidance and Rev 5 requirements, adapting documentation accordingly.

Continuous Monitoring & POA&M (FedRAMP)

• Manage POA&M items end-to-end through remediation.

• Coordinate monthly ConMon deliverables and vulnerability scanning cadence.

• Track deviation requests and risk acceptances with agency authorizing officials.

• Ensure timely submission of significant change requests and security impact analyses.

Multi-Framework Compliance

• Coordinate SOC 2 Type II audits and evidence collection via Drata.

• Support ISO 27001, ISO 9001, and IEC 62443 certification efforts.

• Manage CMMC Level 2 compliance for DoD contract support.

• Map controls across frameworks to reduce duplication and streamline evidence collection.

• Maintain the compliance calendar and a continuous audit-ready posture.

OSCAL & Compliance Automation

• Lead adoption of OSCAL (Open Security Controls Assessment Language) for machine-readable compliance.

• Implement component-based documentation for reusable control narratives.

• Partner with engineering on internal OSCAL tooling and evidence-collection workflows.

• Define requirements for continuous-compliance automation.

Policy, Stakeholders & Security Program

• Maintain security policies aligned with NIST 800-53 Rev 5; keep corporate and FedRAMP boundary documentation consistent.

• Develop and exercise Contingency Plan (ISCP), DRP, and BCP with annual testing.

• Prepare compliance briefings for leadership and the board; interface with federal agency stakeholders.

• Support customer security questionnaires and due diligence requests.

• Partner with the SOC team on audit-log retention, incident response documentation, and playbook alignment.

What You Bring

Required:

• 5–8 years in cybersecurity compliance, GRC, or information security.

• Direct experience with the FedRAMP authorization process (Moderate or High).

• Strong working knowledge of NIST 800-53 Rev 5 and FedRAMP requirements.

• Hands-on experience with SSP development, POA&M management, and 3PAO coordination.

• Familiarity with compliance platforms (Drata, Vanta, Archer, or similar).

• Cloud security compliance experience (AWS required).

• Excellent technical writing, project management, and stakeholder communication skills.

• Ability to translate technical controls into business-understandable terms.

Nice to Have:

• FedRAMP authorization experience specifically.

• Background with federal civilian agencies (Department of State, DHS, etc).

• Knowledge of IEC 62443 and OT/ICS security standards.

• CMMC and DoD compliance experience.

• Hands-on OSCAL experience (catalogs, profiles, component definitions, SSP models).

• AWS GovCloud compliance experience.

• Working knowledge of SOC 2, ISO 27001, and ISO 9001 frameworks.

• Prior startup or high-growth company experience.

Certifications (Preferred, Not Required)

• CISA, CISM, or CISSP.

• FedRAMP 3PAO experience.

• ISO 27001 Lead Auditor or Lead Implementer.

• AWS Certified Security – Specialty.

• CompTIA Security+ or equivalent.

Eligibility:

• Must be a U.S. citizen.

• Ability to obtain and maintain a security clearance preferred.

• Public Trust or higher clearance is a plus for agency interactions.

Benefits

What We Offer:

  • 122-151K base + equity and performance bonus eligible
  • Full medical, vision, and dental insurance
  • Generous PTO
  • Remote-first culture with flexible hours
  • Opportunity to protect critical infrastructure at scale
  • Work with patented, cutting-edge security technology
  • Direct ownership of SOC maturation
  • Collaborative team with military, federal, and private sector expertise

Security Clearance

  • Due to federal customer and FedRAMP requirements, this role requires US Person status (citizen or permanent resident) under ITAR/EAR regulations.
  • Ability to obtain and maintain a security clearance preferred

Dispel is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We are committed to building a diverse team and encourage applicants from all backgrounds to apply.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 122k-151k USD

Experience

5 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About Dispel

Learn more about Dispel and their company culture.

View company profile

At Dispel, we're on a mission to connect people to their industrial control systems, wherever they are in the world. We do this through a product that is fast, easy to implement, and simple to use. We were founded in 2015 with a vision to harness the power of moving target defense in cybersecurity and data privacy. Since then, we've pioneered the first network-level moving target defense SD-WANs and now hold over 42 patents across networking, access control, managed attribution, and zero trust. Our core focus is on providing Zero Trust Access solutions for industrial control systems, serving critical sectors like manufacturing, utilities, and government. We're proud to protect the heart of industry and maximize efficiency for global operations, with our technology safeguarding over $500 billion in manufactured goods annually and supporting utilities for over 54 million people.

Our flagship product, the Dispel Zero Trust Engine (ZTE), simplifies secure remote access, data streaming, micro-segmentation, and ongoing threat detection for industrial control systems and other cyber-physical environments. We understand that in the world of operational technology (OT), every second counts. That's why our platform is designed to get your team on the job in under 30 seconds, a significant improvement over in-house systems that can take many minutes. We believe in building a safer, more resilient world. To that end, we actively collaborate with leading industry bodies like the National Institute of Standards and Technology (NIST), the US Cybersecurity and Infrastructure Security Agency (CISA), and the NATO Industrial Advisory Group (NIAG). By contributing our expertise, we help advance cybersecurity practices globally. We're a team that values diverse backgrounds and innovative thinking, and we offer a nimble startup environment where every member can make a substantial impact on the essential systems that underpin our global economy.

Employee benefits

Learn about the employee benefits and perks provided at Dispel.

View benefits

Stock Option Plan

Company option pool.

Wellness benefits

Wellness benefits for physical fitness.

Life Insurance (Basic, Voluntary & AD&D)

Life Insurance (Basic, Voluntary & AD&D)

Family Leave (Maternity, Paternity)

Equal paternal and maternal parental leave.

View Dispel's employee benefits
Claim this profileDispel logoDI

Dispel

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

3 remote jobs at Dispel

Explore the variety of open remote roles at Dispel, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Dispel

Remote companies like Dispel

Find your next opportunity by exploring profiles of companies that are similar to Dispel. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan