GovCloud Compliance Analyst (Cloud Controls & Audit) — E-level

Sciata

New York (NY)

Hybrid

USD 65,000 - 79,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading compliance firm is seeking a GovCloud Compliance Analyst to support audit readiness for cloud environments. The role includes maintaining evidence in AuditBoard, executing control assessments, and working alongside cross-functional teams. Candidates should have a background in compliance or IT risk, with a bachelor's degree and at least 3 years of relevant experience. This position is hybrid remote with occasional travel expected for audits.

Qualifications

  • Minimum 3 years of compliance, IT risk, or audit experience in regulated cloud environments.
  • Working knowledge of NIST SP 800-53 Rev 5 and FedRAMP.
  • Strong technical writing skills; able to explain control status.

Responsibilities

  • Own assigned control families and maintain control evidence in AuditBoard.
  • Execute control assessment activities and perform internal validations.
  • Map inherited controls and update control mapping artifacts.

Skills

Compliance experience
Technical writing
Stakeholder communication
Evidence management

Education

Bachelor's degree in Information Security, Computer Science, or Risk Management

Tools

AuditBoard
Power BI

Job description

GovCloud Compliance Analyst (Cloud Controls & Audit) — E-level

Seeking a GovCloud Compliance Analyst (Cloud Controls & Audit)

Remote on EST, with possibility of travel 1-2 times a year near New York

Note: Only U.S. citizens or Lawful Permanent Residents (Green Card holders) can be considered at this time. We are unable to partner with any 3rd parties.

Pay Rate: Up to $36 per hour

Position summary

The GovCloud Compliance Analyst supports regulatory compliance and audit readiness for our GovCloud environments. This role implements and validates controls, manages evidence in AuditBoard (system of record), and coordinates ATO/SA&A activities mapped to federal and state frameworks (NIST SP 800-53 Rev 5 — Moderate, FedRAMP, StateRAMP, MARS-E where applicable) and internal Canon Protocol mapping (ARC‑AMPE). This is a hybrid/remote-eligible role reporting to the Director of Regulatory Compliance Environments.

Key responsibilities (measurable)
  • Own assigned control families and maintain control evidence in AuditBoard; achieve and sustain 65% evidence attachment completeness for assigned controls.
  • Execute control assessment activities and perform internal validations at defined cadence (quarterly or as required by framework).
  • Map inherited and system‑specific controls to canonical mappings and update control mapping artifacts within AuditBoard.
  • Partner with engineering, platform, and risk teams to track ATO/SA&A milestones (maintain ATO readiness dashboard; elevate blockers within 48 hours).
  • Prepare documentation packets and evidence bundles for external audits and customer assessments; support 100% on‑time audit deliverables.
  • Identify compliance gaps, propose prioritized remediation plans, and track remediation closure (target: close high/critical findings within 30 days or per SLA).
  • Contribute to Power BI dashboards that visualize control health, evidence SLAs, and audit cycles; support monthly compliance reporting.
  • Maintain procedures and update policies tied to assigned controls; document changes in the governance repository.
Required qualifications
  • Minimum 3 years of compliance, IT risk, or audit experience in regulated cloud environments (AWS GovCloud, Azure Government, or equivalent).
  • Working knowledge of NIST SP 800-53 Rev 5, FedRAMP, StateRAMP; experience mapping to MARS‑E/ ARC‑AMPE is a plus.
  • Practical experience with GRC platforms (AuditBoard preferred) and evidence management processes.
  • Strong technical writing and stakeholder communication skills; able to explain control status to technical and non‑technical audiences.
  • Bachelor's degree in Information Security, Computer Science, Risk Management, or equivalent experience.
Preferred qualifications
  • Experience supporting ATO or SA&A efforts and coordinating external assessors.
  • Certifications: CISA, CISSP, CRISC, or Security+.
  • Experience with Power BI or advanced Excel for KPI tracking and reporting.
  • Familiarity with ADO/IT ticketing or change management processes.
Location & reporting
  • Work location: Hybrid / Remote eligible (onsite visits expected periodically for audits and triage).
  • Reporting to: Director of Regulatory Compliance Environments.
Equal opportunity & accommodations

MMC is an equal opportunity employer. Candidates from diverse backgrounds are encouraged to apply. If you require an accommodation during the application or interview process, please contact HR.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GOVERNANCE, RISK, AND COMPLIANCE ANALYST
GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
Cleared "Cloud" Cyber Analyst
Cleared "Cloud" Cyber Analyst

General Atomics Intelligence • City of Rome (NY)

On-site
USD 141,000 - 263,000
CLOUD SECURITY ENGINEER - AWS GOVCLOUD / MULTI-CLOUD
CLOUD SECURITY ENGINEER - AWS GOVCLOUD / MULTI-CLOUD

Zermount, Inc. • Arlington (VA)

Hybrid
USD 155,000 - 190,000
Senior DevSecOps Engineer, GovCloud & Compliance
Senior DevSecOps Engineer, GovCloud & Compliance

United States Digital Space LLC • United States

Remote
USD 170,000 - 185,000
Medical, dental, vision
Generous PTO
Remote work within United States
Security Control Assessor
Security Control Assessor

Guidehouse • McLean (VA)

On-site
USD 120,000 - 165,000
Medical Insurance
401(k) Plan
Tuition Reimbursement
+2
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000