Risk and Compliance Analyst

Jobgether

United States

On-site

USD 98,000 - 115,000

Full time

46 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) retirement plan
Paid time off

Job summary

Jobgether is seeking a Risk and Compliance Analyst in the United States to support cybersecurity risk management, compliance, audit, and security governance across federal environments. You will identify risks, gaps, and remediation needs, applying NIST and federal requirements to strengthen security posture and reduce organizational risk.

You will collaborate with system owners, auditors, and government stakeholders to translate requirements into actionable recommendations and support RMF, ATO,

Qualifications

  • Demonstrated expertise in cybersecurity risk management, compliance, auditing, or closely related functions.
  • Strong understanding of NIST cybersecurity standards and frameworks, federal security requirements, RMF, A&A, ATO.

Responsibilities

  • Perform comprehensive cybersecurity risk assessments across information systems, applications, platforms, technologies, processes, and enterprise initiatives.
  • Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks.
  • Develop risk-management processes covering identification, assessment, prioritization, mitigation, monitoring, and reporting.
  • Monitor risks and approved mitigation actions throughout the system and program lifecycle, including continuous monitoring of cybersecurity risk and compliance posture.
  • Perform security architecture and compliance gap analyses and recommend mitigation strategies.

Skills

Information security
Risk management
Auditing
Policy development
NIST frameworks

Education

Bachelor’s degree preferred
Advanced degree substitute for experience

Tools

CASP+ (SecurityX)
CCISO
CISA
CISM
CISSP

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Risk and Compliance Analyst based in the United States.

The Risk and Compliance Analyst will support cybersecurity risk management, compliance, audit, and security governance initiatives across complex federal environments.

This role focuses on identifying and assessing security risks, control gaps, vulnerabilities, compliance deficiencies, and remediation needs.

You will apply established cybersecurity frameworks and federal requirements to help strengthen security posture and reduce organizational risk.

Working closely with system owners, security engineers, architects, auditors, government stakeholders, and technical teams, you will translate requirements into actionable recommendations.

You will contribute to Risk Management Framework, Authority to Operate, FISMA/FICAM, continuous monitoring, and security assessment activities throughout the system lifecycle.

The role also involves evaluating emerging technologies and evolving regulatory requirements to understand their impact on security and compliance.

Success will require strong analytical judgment, technical knowledge, clear communication, and the ability to balance security requirements with mission and operational needs.

Accountabilities
  • Perform comprehensive cybersecurity risk assessments across information systems, applications, platforms, technologies, processes, and enterprise initiatives.
  • Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks.
  • Develop and implement risk-management processes covering risk identification, assessment, prioritization, mitigation, monitoring, and reporting.
  • Develop technically feasible and actionable risk-mitigation strategies and corrective-action recommendations aligned with government risk tolerance and mission requirements.
  • Monitor risks and approved mitigation actions throughout the system and program lifecycle, including continuous monitoring of cybersecurity risk and compliance posture.
  • Perform compliance assessments against applicable federal cybersecurity requirements, VA policies, organizational standards, and approved security baselines.
  • Assess systems against NIST standards, OMB mandates, VA cybersecurity requirements, NIST SP 800-53, the NIST Cybersecurity Framework, and other applicable federal security frameworks.
  • Support Federal Assessment and Authorization, Risk Management Framework, and Authority to Operate activities for assigned systems and initiatives.
  • Conduct and support internal and external cybersecurity audits, assessments, inspections, and reviews.
  • Coordinate with auditors, assessors, government representatives, cybersecurity SMEs, system owners, engineers, and other stakeholders throughout assessment activities.
  • Collect, validate, organize, and maintain audit evidence, including policies, procedures, system documentation, security reports, configurations, logs, diagrams, and other technical artifacts.
  • Evaluate audit and compliance findings and develop remediation strategies, corrective actions, responsible-party assignments, and resolution timelines.
  • Track findings through resolution and verify that corrective actions adequately address identified deficiencies.
  • Support annual FISMA/FICAM audit activities and develop actionable recommendations for identified findings.
  • Develop and maintain Remediation Reports, Security Risk Analysis Reports, and other documentation that communicates cybersecurity risks, findings, mitigation plans, and remediation progress.
  • Support Specialized Security Posture Reports evaluating risks associated with emerging technologies such as artificial intelligence, cloud security, post-quantum cryptography, medical devices, and Internet-of-Things technologies.
  • Assess changes in technology, systems, regulatory requirements, and government mandates to determine potential risk and compliance impacts.
  • Perform security architecture and compliance gap analyses and recommend mitigation strategies consistent with applicable requirements and enterprise risk tolerance.
  • Review security configuration and baseline-assessment findings to determine compliance status, deviations, risk implications, and remediation requirements.
  • Develop and maintain Requirements Traceability Matrices supporting accreditation, authorization, compliance, and security-control activities.
  • Assist system owners and technical teams in interpreting cybersecurity requirements and identifying appropriate evidence to demonstrate compliance.
  • Develop, review, maintain, and support enforcement of cybersecurity policies, procedures, standards, guidelines, and governance documentation.
  • Monitor regulatory, policy, and security-requirement changes and assess their potential impact on systems and cybersecurity programs.
  • Prepare risk and compliance reports, briefings, dashboards, risk summaries, and status updates for technical teams, program managers, government leadership, auditors, and other stakeholders.
  • Maintain accurate and auditable records of risk decisions, findings, mitigation plans, compliance evidence, corrective actions, and closure status.
  • Coordinate with government and regulatory stakeholders regarding compliance issues, assessments, findings, and remediation activities.
  • Support third-party and supplier risk-management activities, including vendor cybersecurity assessments, risk scoring, and supply-chain security requirements where assigned.
  • Collaborate with cybersecurity architects, security engineers, DevSecOps personnel, program managers, system owners, technical SMEs, and other stakeholders to integrate risk and compliance requirements throughout the technology lifecycle.
  • Participate in technical reviews, governance forums, risk meetings, audit meetings, engineering working groups, and other activities requiring cybersecurity risk or compliance expertise.
  • Promote risk-based cybersecurity decision-making that balances security requirements, mission needs, operational constraints, and remediation priorities.
  • Travel or occasional on-site visits may be required.
Requirements
  • Minimum of 7 years of information security experience, including at least 5 years of risk and compliance experience within a large organization or government agency comparable in size or scope to GSA, IRS, DoD, or VA.
  • An advanced degree, such as a Master’s or PhD in a related field, may substitute for up to 2 years of required experience.
  • Demonstrated expertise in cybersecurity risk management, compliance, auditing, or closely related functions.
  • Extensive experience conducting internal and external audits to evaluate compliance with regulatory requirements, cybersecurity standards, and organizational policies.
  • Proven experience developing and implementing risk-management programs, including risk assessments, mitigation strategies, continuous monitoring, and risk reporting.
  • Strong expertise in cybersecurity policy development, documentation, governance, and enforcement.
  • Experience identifying, documenting, communicating, and resolving compliance issues and coordinating with regulatory or government stakeholders.
  • Strong understanding of NIST cybersecurity standards and frameworks, federal security requirements, RMF, A&A, ATO, and related compliance processes.
  • Bachelor’s degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or a related field is preferred.
  • Relevant certifications are preferred, including CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, or CCNP Security.
  • Strong analytical and problem-solving skills, with the ability to evaluate complex security information and make sound risk-based recommendations.
  • Excellent written and verbal communication skills, with the ability to present technical risk and compliance information to both technical and non-technical audiences.
  • Strong organizational and documentation skills, with the ability to manage multiple findings, assessments, remediation activities, and stakeholder priorities.
  • Ability to collaborate effectively across technical, engineering, program, audit, and government teams.
  • Ability to work independently, exercise sound judgment, and operate effectively in complex and evolving environments.
  • Up to two travel periods per year may be required.
  • Selected candidates will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.
Benefits
  • Salary range of $98,135.18–$115,000 USD.
  • Medical, dental, and vision insurance.
  • Voluntary life insurance.
  • 401(k) retirement plan.
  • Basic accidental death and dismemberment coverage.
  • Short-term and long-term disability coverage.
  • Paid time off and paid holidays.
  • Telehealth services.
  • Flexible Spending Account (FSA) and Health Savings Account (HSA) options.
  • Employee Assistance Program (EAP).
  • Traveling assistance resources.
  • Opportunity to support high-impact federal cybersecurity and risk-management initiatives.
  • Exposure to enterprise security architecture, compliance, emerging technologies, and complex government security environments.
  • Opportunities to collaborate with cybersecurity, engineering, DevSecOps, audit, and government stakeholders.
  • Equal employment opportunity workplace with a commitment to an inclusive and supportive environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Lead (INFOSEC) - Office of the Chief Information Officer
Network Security Lead (INFOSEC) - Office of the Chief Information Officer

GSA • Washington

On-site
USD 125,000 - 150,000
Network Security Lead (INFOSEC) - Office of the Chief Information Officer
Network Security Lead (INFOSEC) - Office of the Chief Information Officer

GSA • Raleigh (NC)

On-site
USD 115,000 - 141,000
Junior Cybersecurity GRC Analyst
Junior Cybersecurity GRC Analyst

Talanto • Northern (KY)

Hybrid
USD 5,500 - 12,000
Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
+5
Cloud Security Architect / Engineer
Cloud Security Architect / Engineer

9th Way Insignia • Washington

On-site
USD 98,000 - 150,000
Network Security Lead (INFOSEC) - Office of the Chief Information Officer
Network Security Lead (INFOSEC) - Office of the Chief Information Officer

GSA • Lakewood (CO)

On-site
USD 115,000 - 141,000
Health insurance
Life insurance
Sick leave and vacation time
+5
Compliance & Audit Support (Mid)
Compliance & Audit Support (Mid)

Koniag Government Services • Washington

Hybrid
USD 70,000 - 110,000
Health, dental and vision insurance
401K with company matching
Flexible spending accounts
+2
Network Security Lead (INFOSEC) - Office of the Chief Information Officer
Network Security Lead (INFOSEC) - Office of the Chief Information Officer

GSA • Tacoma (WA)

On-site
USD 128,000 - 150,000
Network Security Lead (INFOSEC) - Office of the Chief Information Officer
Network Security Lead (INFOSEC) - Office of the Chief Information Officer

GSA • Kansas City (MO)

On-site
USD 115,000 - 141,000
Health insurance
Thrift Savings Plan
Paid holidays
Senior Security Compliance Engineer, Public Sector
Senior Security Compliance Engineer, Public Sector

Jobgether • United States

On-site
USD 139,000 - 196,000
Equity
Health benefits
Flexible PTO
+2
Risk and Compliance Analyst
Risk and Compliance Analyst

Boston Government Services, LLC (BGS) • Knoxville (TN)

Hybrid
USD 136,000 - 161,000
Health Insurance
Dental Insurance
Vision Insurance
+4