RAJ
Verified from Jobgether's careers page · Lever

Risk and Compliance Analyst

JobgetherUs7 YearsPosted Sep 7, 2026
Apply now

Apply faster

Fill most application fields automatically from your RealAnalystJobs profile. You review, you submit.

Included with the from $2 for 30 days unlock

About this role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Risk and Compliance Analyst based in the United States. The Risk and Compliance Analyst will support cybersecurity risk management, compliance, audit, and security governance initiatives across complex federal environments. This role focuses on identifying and assessing security risks, control gaps, vulnerabilities, compliance deficiencies, and remediation needs. You will apply established cybersecurity frameworks and federal requirements to help strengthen security posture and reduce organizational risk. Working closely with system owners, security engineers, architects, auditors, government stakeholders, and technical teams, you will translate requirements into actionable recommendations. You will contribute to Risk Management Framework, Authority to Operate, FISMA/FICAM, continuous monitoring, and security assessment activities throughout the system lifecycle. The role also involves evaluating emerging technologies and evolving regulatory requirements to understand their impact on security and compliance. Success will require strong analytical judgment, technical knowledge, clear communication, and the ability to balance security requirements with mission and operational needs. Accountabilities: • Perform comprehensive cybersecurity risk assessments across information systems, applications, platforms, technologies, processes, and enterprise initiatives. • Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks. • Develop and implement risk-management processes covering risk identification, assessment, prioritization, mitigation, monitoring, and reporting. • Develop technically feasible and actionable risk-mitigation strategies and corrective-action recommendations aligned with government risk tolerance and mission requirements. • Monitor risks and approved mitigation actions throughout the system and program lifecycle, including continuous monitoring of cybersecurity risk and compliance posture. • Perform compliance assessments against applicable federal cybersecurity requirements, VA policies, organizational standards, and approved security baselines. • Assess systems against NIST standards, OMB mandates, VA cybersecurity requirements, NIST SP 800-53, the NIST Cybersecurity Framework, and other applicable federal security frameworks. • Support Federal Assessment and Authorization, Risk Management Framework, and Authority to Operate activities for assigned systems and initiatives. • Conduct and support internal and external cybersecurity audits, assessments, inspections, and reviews. • Coordinate with auditors, assessors, government representatives, cybersecurity SMEs, system owners, engineers, and other stakeholders throughout assessment activities. • Collect, validate, organize, and maintain audit evidence, including policies, procedures, system documentation, security reports, configurations, logs, diagrams, and other technical artifacts. • Evaluate audit and compliance findings and develop remediation strategies, corrective actions, responsible-party assignments, and resolution timelines. • Track findings through resolution and verify that corrective actions adequately address identified deficiencies. • Support annual FISMA/FICAM audit activities and develop actionable recommendations for identified findings. • Develop and maintain Remediation Reports, Security Risk Analysis Reports, and other documentation that communicates cybersecurity risks, findings, mitigation plans, and remediation progress. • Support Specialized Security Posture Reports evaluating risks associated with emerging technologies such as artificial intelligence, cloud security, post-quantum cryptography, medical devices, and Internet-of-Things technologies. • Assess changes in technology, systems, regulatory requirements, and government mandates to determine potential risk and compliance impacts. • Perform security architecture and compliance gap analyses and recommend mitigation strategies consistent with applicable requirements and enterprise risk tolerance. • Review security configuration and baseline-assessment findings to determine compliance status, deviations, risk implications, and remediation requirements. • Develop and maintain Requirements Traceability Matrices supporting accreditation, authorization, compliance, and security-control activities. • Assist system owners and technical teams in interpreting cybersecurity requirements and identifying appropriate evidence to demonstrate compliance. • Develop, review, maintain, and support enforcement of cybersecurity policies, procedures, standards, guidelines, and governance documentation. • Monitor regulatory, policy, and security-requirement changes and assess their potential impact on systems and cybersecurity programs. • Prepare risk and compliance reports, briefings, dashboards, risk summaries, and status updates for technical teams, program managers, government leadership, auditors, and other stakeholders. • Maintain accurate and auditable records of risk decisions, findings, mitigation plans, compliance evidence, corrective actions, and closure status. • Coordinate with government and regulatory stakeholders regarding compliance issues, assessments, findings, and remediation activities. • Support third-party and supplier risk-management activities, including vendor cybersecurity assessments, risk scoring, and supply-chain security requirements where assigned. • Collaborate with cybersecurity architects, security engineers, DevSecOps personnel, program managers, system owners, technical SMEs, and other stakeholders to integrate risk and compliance requirements throughout the technology lifecycle. • Participate in technical reviews, governance forums, risk meetings, audit meetings, engineering working gro

Description from Jobgether's public careers feed, reproduced so you can read the role here. Apply on the company's own site; RealAnalystJobs never submits anything for you.

Raj