Staff Compliance Analyst - Federal

Okta Okta · Enterprise · Washington, DC · Security-770

Okta is seeking a Staff Federal Security Compliance Analyst to lead their compliance strategy for public sector clients, focusing on FedRAMP and DoD authorizations. This role involves strategic audit leadership, continuous monitoring, advising engineering and product teams on NIST requirements, and driving automation for evidence collection and control validation, particularly for FedRAMP 2.0 standards.

What you'd actually do

  1. Lead end-to-end FedRAMP and DoD audits, serving as the primary point of contact for external 3PAOs and government agencies.
  2. Oversee and evolve the continuous monitoring (ConMon) program. Design sophisticated reporting mechanisms for vulnerability management and risk posture for executive leadership.
  3. Act as a senior consultant to Engineering and Product teams, translating complex NIST 800-53 requirements into actionable technical specifications for cloud-native environments.
  4. Lead the assessment of high-impact changes to federal systems. Ensure that system evolutions maintain a rigorous security posture without sacrificing innovation.
  5. Drive synchronization between GRC, Security, Marketing, Sales, Engineering, and Product to ensure federal requirements are integrated into the broader corporate roadmap.

Skills

Required

  • 7+ years of experience in security compliance
  • 4-5 years specifically focused on the FedRAMP/NIST 800-53 framework
  • Demonstrated experience with automation tools or scripting (e.g., Python, Go, or SQL) for automated evidence collection
  • Familiarity with API-based control validation and OSCAL-based tooling (e.g., Trestle, LULA, or similar GRC automation frameworks)
  • Deep understanding of cloud-native infrastructure (IaaS, PaaS, SaaS)
  • Expert-level knowledge of NIST SP 800-53, FedRAMP High/Moderate, and DoD SRG (IL4, IL5, and familiarity with IL6)
  • Proven experience with access management, CI/CD pipelines, disaster recovery, and encryption/key management in a cloud context
  • Ability to analyze complex "edge-case" security scenarios
  • Exceptional presentation skills

Nice to have

  • CISSP
  • CISA
  • CCSK
  • AWS Certified Solutions Architect or Cloud Practitioner
  • Expert-level proficiency with JIRA, ServiceNow, and Okta
  • Prior experience in a DevOps, Security Engineering, or Systems Administration role

What the JD emphasized

  • FedRAMP
  • DoD
  • NIST 800-53
  • continuous monitoring
  • automated evidence collection
  • OSCAL integration