Governance, Risk, and Compliance (GRC) / Compliance Analyst

Ardent

Tallahassee (FL)

Remote

USD 110,000 - 160,000

Full time

23 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Ardent is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our team in a remote capacity with travel to Tallahassee, FL. The role integrates governance, risk, compliance, and internal-audit support requirements across a multi-agency environment.

You will lead testing design, map procedures to NIST CSF and applicable rules, review evidence for accuracy, and guide OCIG and OIG staff through knowledge transfer and QA reviews.

Qualifications

  • Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline.
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
  • 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
  • Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders.
  • Working knowledge of professional auditing or assurance standards and evidence requirements.

Responsibilities

  • Lead ingestion and analysis of agency documentation including risk assessments, remediation plans, and prior findings.
  • Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
  • Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
  • Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and the applicable approved criteria.
  • Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement.
  • Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
  • Validate that reports accurately state procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled.
  • Conduct independent QA reviews of technical deliverables not authored solely by the reviewer and document sign-off.
  • Lead technical briefings, workshops, job aids, and knowledge transfer so OCIG and OIG staff can understand and reuse procedures.
  • Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed.

Skills

Cybersecurity experience
Auditing
Risk assessment
Regulatory compliance
Stakeholder communication

Education

Bachelor's degree in cybersecurity / information assurance / audit / information systems

Tools

MITRE ATT&CK
Threat-informed kill chains
Active Directory
Cloud platforms
APIs
SIEM/EDR
Vulnerability scanners
Evidence repositories

Job description

Governance, Risk, and Compliance (GRC) Analyst

Remote

Ardent is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our team.

This is a remote position with expected travel to Tallahassee, FL.

Position Description:

Ardent is seeking a Governance, Risk, and Compliance (GRC) Analyst that integrates technical evidence with governance, risk, compliance, and internal-audit support requirements. The role maintains traceability among agency documentation, Rule 60GG-2, NIST CSF, approved procedures, factual findings, remediation actions, and deliverable acceptance criteria while protecting confidential and exempt information across a potentially broad multi-agency environment.

Responsibilities and Duties:

  • Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
  • Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
  • Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
  • Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and the applicable approved criteria.
  • Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement.
  • Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
  • Validate that reports accurately state procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled.
  • Conduct independent QA reviews of technical deliverables not authored solely by the reviewer and document sign-off.
  • Lead technical briefings, workshops, job aids, and knowledge transfer so OCIG and OIG staff can understand and reuse procedures.
  • Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed.

Requirements:

  • Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline.
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
  • 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
  • Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders.
  • Working knowledge of professional auditing or assurance standards and evidence requirements.

Preferred Qualifications:

  • Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains.
  • Government incident-command experience.
  • CISA, CIA, or other audit credential.
  • Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.

Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.

Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.

Ardent values your privacy and we will never share or sell your private data under any circumstances that are unrelated to your candidacy or employment.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Ardent’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Program Manager (PMP Required)
Program Manager (PMP Required)

ArdentMC • Atlanta (GA), Tallahassee (FL)

Hybrid
USD 120,000 - 145,000
Cyber Lead Auditor / Test Lead
Cyber Lead Auditor / Test Lead

Ardent • Tallahassee (FL)

Remote
USD 120,000 - 180,000
Cyber Lead Auditor / Test Lead
Cyber Lead Auditor / Test Lead

ArdentMC • Atlanta (GA), Tallahassee (FL)

Hybrid
USD 140,000 - 200,000
Cyber Lead Auditor / Test Lead
Cyber Lead Auditor / Test Lead

ardentmc • United States

Remote
USD 140,000 - 190,000
Detection & Monitoring Analyst New
Detection & Monitoring Analyst New

Ardent Management Consulting, Inc. • Tallahassee (FL), Northern (KY)

Hybrid
USD 90,000 - 140,000
Geospatial Trainer / Outreach Coordinator New
Geospatial Trainer / Outreach Coordinator New

Ardent Management Consulting, Inc. • Northern (KY)

Hybrid
USD 45,000 - 65,000
Senior Cybersecurity Program Manager
Senior Cybersecurity Program Manager

Ardent MC • Washington

On-site
USD 120,000 - 160,000
Competitive pay
Comprehensive health coverage
Flexible PTO
+2
Service Desk Engineer Washington, D.C. Metro
Service Desk Engineer Washington, D.C. Metro

Ardent Management Consulting, Inc • Washington

On-site
USD 85,000 - 120,000
Flexible PTO
Comprehensive health coverage
Tuition reimbursement
Expert Cyber Security Engineer
Expert Cyber Security Engineer

Amentum • Arlington (VA)

On-site
USD 185,000 - 200,000
Sr. Network/Systems Engineer New Remote, US
Sr. Network/Systems Engineer New Remote, US

AGE • Northern (KY)

Remote
USD 135,000 - 180,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5