Risk and Compliance Analyst

9thwayinsignia

United States

On-site

USD 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

9th Way Insignia is recruiting for an Engineer, 3, Risk and Compliance Analyst to support federal cybersecurity efforts, focusing on risk assessments, compliance with NIST and VA requirements, and security program governance.

You will engage with auditors, government representatives, and cross-functional teams to identify, analyze, and mitigate cybersecurity risks across information systems and processes, ensuring accreditation readiness.

Responsibilities

  • Perform and support comprehensive cybersecurity risk assessments for information systems, applications, platforms, technologies, processes, and enterprise initiatives.
  • Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks.
  • Develop and implement risk-management processes and programs, including risk identification, assessment, prioritization, mitigation, monitoring, and reporting.
  • Develop risk-mitigation strategies and corrective-action recommendations that are technically feasible, actionable, and aligned with Government risk tolerance and mission requirements.
  • Monitor identified risks throughout the system and program lifecycle and track the status and effectiveness of approved mitigation actions.
  • Support continuous monitoring activities to provide ongoing visibility into cybersecurity risk, compliance posture, control implementation, and outstanding remediation requirements.
  • Perform compliance assessments against applicable Federal cybersecurity requirements, VA policies, organizational standards, and approved security baselines.
  • Assess systems and cybersecurity activities for compliance with applicable NIST standards, OMB mandates, VA cybersecurity requirements, and other Federal security frameworks identified within the program.
  • Support risk-management activities aligned with NIST SP 800-53 and the NIST Cybersecurity Framework.
  • Evaluate audit findings and provide clear recommendations supporting risk-based decisions regarding system accreditation and authorization.
  • Conduct and support internal and external cybersecurity audits, assessments, inspections, and reviews.
  • Coordinate with auditors, assessors, Government representatives, cybersecurity SMEs, system owners, engineers, and other stakeholders throughout audit and assessment activities.
  • Collect, review, organize, and validate supporting evidence requested during audits and assessments, including policies, procedures, system documentation, security reports, configuration information, logs, diagrams, and other technical artifacts.

Job description

9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions. Our specialties include cybersecurity, cloud modernization, software development, data analytics, enterprise architecture, enterprise IT, analytics, process automation, and artificial intelligence. Learn more about 9th Way Insignia at https://9thwayinsignia.com/.

Team (Project) Introduction

We are recruiting for a range of cybersecurity opportunities supporting federal customers , focused on strengthening enterprise security architecture, systems engineering, and the secure implementation of technologies across the environment.

The work involves applying established cybersecurity standards, guidelines, and frameworks to help translate organizational and business requirements into secure, scalable technical solutions. Team members may contribute to security architecture and engineering efforts, implementation guidance, technical analysis, and the development of repeatable approaches that support the consistent deployment and operation of secure technologies across complex enterprise environments.

Systems security engineering is an important component of this work, with an emphasis on incorporating security and stakeholder protection requirements throughout the system development life cycle, from concept and design through development, production, sustainment, and decommissioning. The team will apply established systems engineering and cybersecurity principles to help protect systems, applications, data, and supporting technologies.

Ultimately, this work supports the broader mission to strengthen its cybersecurity posture, reduce organizational risk, and protect critical systems and information from evolving cyber threats, including external adversaries and insider threats.

9 th Way Insignia is looking for an Engineer, 3, Risk and Compliance Analyst to join this team.

Professional Level Information:An Engineer, 3 typically plans and directs research or development work on complex projects, along with engaging various parties in design and development. Costs and recommendations of new components may also involve part of the job scope. Performs multiple engineering-related tasks in various assignments within the project and firm. An Engineer, 3 oversees the design, development, implementation, and analysis of technical products and systems. An Engineer, 3 has broad knowledge of engineering procedures and assists in the resolution of complex problems. An Engineer, 3 has strong technical skills and background, a knack for learning new technologies, and a blend of good problem-solving and innovation needed to resolve a wide variety of technical production challenges.

Responsibilities:
  • Perform and support comprehensive cybersecurity risk assessments for information systems, applications, platforms, technologies, processes, and enterprise initiatives.
  • Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks.
  • Develop and implement risk-management processes and programs, including risk identification, assessment, prioritization, mitigation, monitoring, and reporting.
  • Develop risk-mitigation strategies and corrective-action recommendations that are technically feasible, actionable, and aligned with Government risk tolerance and mission requirements.
  • Monitor identified risks throughout the system and program lifecycle and track the status and effectiveness of approved mitigation actions.
  • Support continuous monitoring activities to provide ongoing visibility into cybersecurity risk, compliance posture, control implementation, and outstanding remediation requirements.
  • Perform compliance assessments against applicable Federal cybersecurity requirements, VA policies, organizational standards, and approved security baselines.
  • Assess systems and cybersecurity activities for compliance with applicable NIST standards, OMB mandates, VA cybersecurity requirements, and other Federal security frameworks identified within the program.
  • Support risk-management activities aligned with NIST SP 800-53 and the NIST Cybersecurity Framework.
  • Evaluate compliance findings and provide clear recommendations supporting risk-based decisions regarding system accreditation and authorization.
  • Conduct and support internal and external cybersecurity audits, assessments, inspections, and reviews.
  • Coordinate with auditors, assessors, Government representatives, cybersecurity SMEs, system owners, engineers, and other stakeholders throughout audit and assessment activities.
  • Collect, review, organize, and validate supporting evidence requested during audits and assessments, including policies, procedures, system documentation, security reports, configuration information, logs, diagrams, and other technical artifacts.
  • Evaluate audit findings and develop
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Risk & Compliance Analyst — Government Security
Cyber Risk & Compliance Analyst — Government Security

9thwayinsignia • United States

On-site
USD 90,000 - 130,000
Cloud Security Architect / Engineer
Cloud Security Architect / Engineer

9thwayinsignia • Washington

On-site
USD 120,000 - 160,000
Remote Risk & Compliance Analyst (Federal IT Security)
Remote Risk & Compliance Analyst (Federal IT Security)

9th Way Insignia • Northern (KY)

Hybrid
USD 98,000 - 115,000
Medical Insurance
Dental Insurance
Vision Care
+4
DevSecOps Engineer
DevSecOps Engineer

9thwayinsignia • United States

On-site
USD 120,000 - 155,000
Program Manager
Program Manager

9thwayinsignia • United States

On-site
USD 110,000 - 170,000
Technical Lead Chief Security Architect / Engineer
Technical Lead Chief Security Architect / Engineer

9thwayinsignia • United States

Hybrid
USD 140,000 - 210,000
Cloud Security Architect / Engineer Washington, District of Columbia, United States
Cloud Security Architect / Engineer Washington, District of Columbia, United States

9th Way Insignia • Washington, Northern (KY)

Hybrid
USD 98,000 - 150,000
Medical insurance
Dental insurance
Vision plan
+1
Risk and Compliance Analyst
Risk and Compliance Analyst

Triumph Enterprises, Inc • Washington, Northern (KY)

Hybrid
USD 110,000 - 150,000
AI Engineer
AI Engineer

9thwayinsignia • United States

On-site
USD 100,000 - 150,000
Configuration Manager and Documentation Specialist / Tech Writer
Configuration Manager and Documentation Specialist / Tech Writer

9thwayinsignia • United States

On-site
USD 70,000 - 100,000