Staff Compliance Analyst - Federal
Position Overview
Job Description
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.
Position Overview
As a Staff Federal Security Compliance Analyst on the Federal Security and Compliance team, you will serve as a lead of our compliance strategy. Your mission is to safeguard and strengthen our position as a leading Identity-as-a-Service (IDaaS) provider for the public sector.
In this staff-level role, you are not just a practitioner but a strategic leader who bridges the gap between engineering, product, and federal regulatory bodies. You will drive the maintenance of our FedRAMP and DoD (IL4/IL5) authorizations, lead complex audits, and mentor junior analysts to ensure a security-first culture.
Job Duties and Responsibilities
The responsibilities listed below represent the core functions of this role. While a Staff Analyst is expected to have the capability to lead across all areas, the daily focus will typically involve a dynamic combination of these duties based on current mission priorities and team needs:
- Strategic Audit Leadership: Lead end-to-end FedRAMP and DoD audits, serving as the primary point of contact for external 3PAOs and government agencies.
- Continuous Monitoring Strategy: Oversee and evolve the continuous monitoring (ConMon) program. Design sophisticated reporting mechanisms for vulnerability management and risk posture for executive leadership.
- Engineering Advisory: Act as a senior consultant to Engineering and Product teams, translating complex NIST 800-53 requirements into actionable technical specifications for cloud-native environments.
- Impact Assessment & Risk Management: Lead the assessment of high-impact changes to federal systems. Ensure that system evolutions maintain a rigorous security posture without sacrificing innovation.
- Cross-Functional Alignment: Drive synchronization between GRC, Security, Marketing, Sales, Engineering, and Product to ensure federal requirements are integrated into the broader corporate roadmap.
- Programmatic Gap Analysis: Proactively identify and lead initiatives to close gaps between current capabilities and future regulatory requirements (e.g., emerging NIST standards, new DoD mandates, or IL6 requirements).
- Evidence Automation & FedRAMP 20x Readiness: Drive the build-out and support of automated evidence collection and control validation. Lead the transition toward "FedRAMP 2.0" standards (including OSCAL integration), defining and monitoring Key Security Indicators (KSIs) to provide real-time compliance visibility.
Minimum Required Knowledge, Skills, and Abilities
- Education: Bachelor’s degree in Computer Science, MIS, Cybersecurity, or a related technical field.
- Experience: 7+ years of experience in security compliance, with at least 4-5 years specifically focused on the FedRAMP/NIST 800-53 framework.
- Automation & Compliance Engineering: Demonstrated experience with automation tools or scripting (e.g., Python, Go, or SQL) for automated evidence collection. Familiarity with API-based control validation and OSCAL-based tooling (e.g., Trestle, LULA, or similar GRC automation frameworks).
- Technical Depth: Deep understanding of cloud-native infrastructure (IaaS, PaaS, SaaS) and how infrastructure components (networking, OS, databases) support a distributed cloud application.
- Framework Mastery: Expert-level knowledge of NIST SP 800-53, FedRAMP High/Moderate, and DoD SRG (IL4, IL5, and familiarity with IL6).
- Operational Knowledge: Proven experience with access management, CI/CD pipelines, disaster recovery, and encryption/key management in a cloud context.
- Analytical Leadership: Ability to analyze complex "edge-case" security scenarios and provide remediation paths that align with both business goals and regulatory requirements.
- Communication: Exceptional presentation skills with the ability to explain technical compliance risks to non-technical executive stakeholders.
Preferred Certifications & Skills
- Advanced Certifications: CISSP (highly preferred), CISA, or CCSK.
- Cloud Expertise: AWS Certified Solutions Architect or Cloud Practitioner.
- Tooling: Expert-level proficiency with JIRA, ServiceNow, and Okta.
- Technical Backgr...
Perks & Benefits
About This Role
Okta is seeking a Staff Compliance Analyst - Federal to join their Compliance team at the Mid level. This is a Full time, Onsite position based in Washington, United States.
Interested candidates are encouraged to review the full job description above and apply through LegalAlphabet to be considered for this opportunity.
Practice Area
Compliance
Position
Mid
Applicant Location Requirements
Applicants must be located in: US
Application Contact
Contact: Okta Hiring Team
Application Deadline
June 26, 2026
Employment Type
Full time
Share your experience and help others make informed career decisions.