GRC Specialist (US Citizen,IL Based)

Tel Aviv, IsraelFull-timePosted Jul 20, 2026

About us

Oligo is a fast-growing cybersecurity startup transforming how organizations protect their applications, cloud environments, and AI systems at runtime. Backed by top-tier investors including Greenfield Partners, Red Dot Capital Partners, Lightspeed, Ballistic Ventures, and TLV Partners, we’re on a mission to make real-time security a reality.

Oligo’s industry’s leading runtime security platform built to stop attacks in real time without stopping the business. We transform security from passive visibility to active protection across applications, cloud services, workloads, and AI systems. By uncovering the deepest layers of what actually runs in production, Oligo helps organizations prioritize exploitable vulnerabilities, detect malicious behavior as it happens, and stop modern attacks in their tracks.

We're looking for a GRC Specialist to own and drive our compliance and authorization programs, with a strong emphasis on FedRAMP and NIST 800-53. This is a hands-on governance, risk, and compliance role for someone who can build and run a federal-grade compliance program from the ground up and manage it through continuous monitoring and reauthorization cycles.

U.S. citizenship is required for this role due to FedRAMP and federal customer requirements.

Key Responsibilities

  • Own the FedRAMP process end-to-end: System Security Plan (SSP) development and maintenance, POA&M tracking and remediation, control implementation statements, and continuous monitoring (ConMon) deliverables
  • Serve as primary point of contact for 3PAO assessments, coordinating testing, evidence collection, and finding resolution
  • Maintain compliance programs across SOC 2 Type II and ISO 27001
  • Respond to customers security questionnaires, and support sales enablement with SSPs, control narratives, and other security documentation
  • Partner with engineering, GTM, and leadership to ensure controls are implemented, evidenced, and operating effectively
  • Monitor changes to FedRAMP requirements, NIST guidance, and federal compliance obligations, and translate them into actionable program updates

Requirements

Qualifications

  • U.S. citizenship (required for FedRAMP program access and federal customer engagements)
  • 3-5 years of hands-on GRC experience, with direct, demonstrable work on NIST control implementation and assessment
  • Direct experience supporting or owning a FedRAMP authorization (Moderate or High baseline) - SSP authorship, POA&M management, or ConMon deliverables
  • Solid understanding of the FedRAMP process, including 3PAO coordination
  • Working knowledge of SOC 2 and ISO 27001 frameworks
  • Excellent written English - you will be authoring SSPs, policies, and customer- and agency-facing documentation
  • Strong cross-team communication skills and comfort working directly with auditors and assessors
  • Ability to work independently and manage multiple compliance workstreams in a fast-paced environment
  • Experience with GRC platforms (e.g., Vanta, Drata, Scytale, or similar)

Nice to Have

  • Relevant certifications: CISA, CISSP, CAP, or FedRAMP-specific training/certification
  • Familiarity with cloud environments (AWS GovCloud, Azure Government) and their native compliance/control mappings


Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free