Risk and Compliance Analyst

  1. Home
  2. Remote jobs
  3. Analyst
  • Company Jobgether
  • Employment Full-time
  • Location 🇺🇸 United States nationwide
  • Submitted Posted 20 hours ago - Updated 7 hours ago

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Risk and Compliance Analyst based in the United States.

The Risk and Compliance Analyst will support cybersecurity risk management, compliance, audit, and security governance initiatives across complex federal environments.
This role focuses on identifying and assessing security risks, control gaps, vulnerabilities, compliance deficiencies, and remediation needs.
You will apply established cybersecurity frameworks and federal requirements to help strengthen security posture and reduce organizational risk.
Working closely with system owners, security engineers, architects, auditors, government stakeholders, and technical teams, you will translate requirements into actionable recommendations.
You will contribute to Risk Management Framework, Authority to Operate, FISMA/FICAM, continuous monitoring, and security assessment activities throughout the system lifecycle.
The role also involves evaluating emerging technologies and evolving regulatory requirements to understand their impact on security and compliance.
Success will require strong analytical judgment, technical knowledge, clear communication, and the ability to balance security requirements with mission and operational needs.


Accountabilities:
  • Perform comprehensive cybersecurity risk assessments across information systems, applications, platforms, technologies, processes, and enterprise initiatives.
  • Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks.
  • Develop and implement risk-management processes covering risk identification, assessment, prioritization, mitigation, monitoring, and reporting.
  • Develop technically feasible and actionable risk-mitigation strategies and corrective-action recommendations aligned with government risk tolerance and mission requirements.
  • Monitor risks and approved mitigation actions throughout the system and program lifecycle, including continuous monitoring of cybersecurity risk and compliance posture.
  • Perform compliance assessments against applicable federal cybersecurity requirements, VA policies, organizational standards, and approved security baselines.
  • Assess systems against NIST standards, OMB mandates, VA cybersecurity requirements, NIST SP 800-53, the NIST Cybersecurity Framework, and other applicable federal security frameworks.
  • Support Federal Assessment and Authorization, Risk Management Framework, and Authority to Operate activities for assigned systems and initiatives.
  • Conduct and support internal and external cybersecurity audits, assessments, inspections, and reviews.
  • Coordinate with auditors, assessors, government representatives, cybersecurity SMEs, system owners, engineers, and other stakeholders throughout assessment activities.
  • Collect, validate, organize, and maintain audit evidence, including policies, procedures, system documentation, security reports, configurations, logs, diagrams, and other technical artifacts.
  • Evaluate audit and compliance findings and develop remediation strategies, corrective actions, responsible-party assignments, and resolution timelines.
  • Track findings through resolution and verify that corrective actions adequately address identified deficiencies.
  • Support annual FISMA/FICAM audit activities and develop actionable recommendations for identified findings.
  • Develop and maintain Remediation Reports, Security Risk Analysis Reports, and other documentation that communicates cybersecurity risks, findings, mitigation plans, and remediation progress.
  • Support Specialized Security Posture Reports evaluating risks associated with emerging technologies such as artificial intelligence, cloud security, post-quantum cryptography, medical devices, and Internet-of-Things technologies.
  • Assess changes in technology, systems, regulatory requirements, and government mandates to determine potential risk and compliance impacts.
  • Perform security architecture and compliance gap analyses and recommend mitigation strategies consistent with applicable requirements and enterprise risk tolerance.
  • Review security configuration and baseline-assessment findings to determine compliance status, deviations, risk implications, and remediation requirements.
  • Develop and maintain Requirements Traceability Matrices supporting accreditation, authorization, compliance, and security-control activities.
  • Assist system owners and technical teams in interpreting cybersecurity requirements and identifying appropriate evidence to demonstrate compliance.
  • Develop, review, maintain, and support enforcement of cybersecurity policies, procedures, standards, guidelines, and governance documentation.
  • Monitor regulatory, policy, and security-requirement changes and assess their potential impact on systems and cybersecurity programs.
  • Prepare risk and compliance reports, briefings, dashboards, risk summaries, and status updates for technical teams, program managers, government leadership, auditors, and other stakeholders.
  • Maintain accurate and auditable records of risk decisions, findings, mitigation plans, compliance evidence, corrective actions, and closure status.
  • Coordinate with government and regulatory stakeholders regarding compliance issues, assessments, findings, and remediation activities.
  • Support third-party and supplier risk-management activities, including vendor cybersecurity assessments, risk scoring, and supply-chain security requirements where assigned.
  • Collaborate with cybersecurity architects, security engineers, DevSecOps personnel, program managers, system owners, technical SMEs, and other stakeholders to integrate risk and compliance requirements throughout the technology lifecycle.
  • Participate in technical reviews, governance forums, risk meetings, audit meetings, engineering working groups, and other activities requiring cybersecurity risk or compliance expertise.
  • Promote risk-based cybersecurity decision-making that balances security requirements, mission needs, operational constraints, and remediation priorities.
  • Travel or occasional on-site visits may be required.

Requirements

  • Minimum of 7 years of information security experience, including at least 5 years of risk and compliance experience within a large organization or government agency comparable in size or scope to GSA, IRS, DoD, or VA.
  • An advanced degree, such as a Master’s or PhD in a related field, may substitute for up to 2 years of required experience.
  • Demonstrated expertise in cybersecurity risk management, compliance, auditing, or closely related functions.
  • Extensive experience conducting internal and external audits to evaluate compliance with regulatory requirements, cybersecurity standards, and organizational policies.
  • Proven experience developing and implementing risk-management programs, including risk assessments, mitigation strategies, continuous monitoring, and risk reporting.
  • Strong expertise in cybersecurity policy development, documentation, governance, and enforcement.
  • Experience identifying, documenting, communicating, and resolving compliance issues and coordinating with regulatory or government stakeholders.
  • Strong understanding of NIST cybersecurity standards and frameworks, federal security requirements, RMF, A&A, ATO, and related compliance processes.
  • Bachelor’s degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or a related field is preferred.
  • Relevant certifications are preferred, including CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, or CCNP Security.
  • Strong analytical and problem-solving skills, with the ability to evaluate complex security information and make sound risk-based recommendations.
  • Excellent written and verbal communication skills, with the ability to present technical risk and compliance information to both technical and non-technical audiences.
  • Strong organizational and documentation skills, with the ability to manage multiple findings, assessments, remediation activities, and stakeholder priorities.
  • Ability to collaborate effectively across technical, engineering, program, audit, and government teams.
  • Ability to work independently, exercise sound judgment, and operate effectively in complex and evolving environments.
  • Up to two travel periods per year may be required.
  • Selected candidates will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

Benefits

  • Salary range of $98,135.18–$115,000 USD.
  • Medical, dental, and vision insurance.
  • Voluntary life insurance.
  • 401(k) retirement plan.
  • Basic accidental death and dismemberment coverage.
  • Short-term and long-term disability coverage.
  • Paid time off and paid holidays.
  • Telehealth services.
  • Flexible Spending Account (FSA) and Health Savings Account (HSA) options.
  • Employee Assistance Program (EAP).
  • Traveling assistance resources.
  • Opportunity to support high-impact federal cybersecurity and risk-management initiatives.
  • Exposure to enterprise security architecture, compliance, emerging technologies, and complex government security environments.
  • Opportunities to collaborate with cybersecurity, engineering, DevSecOps, audit, and government stakeholders.
  • Equal employment opportunity workplace with a commitment to an inclusive and supportive environment.


How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

 Why Apply Through Jobgether? 

 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

 

 

#LI-CL1

Loading similar jobs...

USA Remote Jobs

Discover fully remote job opportunities in the United States at USA Remote Jobs. Apply for roles like Software Developer, Customer Service Specialist, Project Manager, and more!

© 2026 Created by USA Remote Jobs. All rights reserved.