IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks)
$98k - $163kGuidehouse
Job Family :
IT Risk & Controls Consulting
Travel Required :
None
Clearance Required :
Ability to Obtain Public Trust
What You Will Do:
Guidehouse is seeking an IT Audit & Compliance professional to help our client at a large federal agency pursue and maintain compliance with federal cybersecurity frameworks. This role focuses on audit preparation and coordination. The candidate will:
Coordinate internal and external audit activities across federal information systems, ensuring teams, schedules, evidence, and documentation remain audit-ready.
Prepare, maintain, and organize assessor-ready artifacts including SSPs, control narratives, SOPs, POA&Ms, continuous monitoring reports, and structured evidence packages.
Interpret and apply requirements from federal cybersecurity and audit frameworks, including:
NIST SP 800-53 (security and privacy controls), NIST SP 800-37 (RMF), NIST SP 800-171 (CUI), FISMA, FISCAM, OMB Circular A-123, FedRAMP, and adjacent frameworks such as SOC 1/2, HIPAA, the Privacy Act, and IRS Publication 1075.
Support audit readiness activities by coordinating evidence collection with engineering, ISSO/ISSM, infrastructure, cloud, and application teams.
Track audit findings, maintain POA&M items, and facilitate remediation progress across technical and business teams.
Translate technical implementations into clear, assessor-ready documentation through strong technical writing and stakeholder coordination.
Draft and refine policies, procedures, and control narratives, and coordinate teams through internal audits, readiness assessments, and corrective action plans.
What You Will Need:
Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred.
Bachelor's degree in information systems, Cybersecurity, Computer Science, Accounting/IS Audit, or a discipline related to this project.
US Citizenship is required.
Three (3) or more years of IT Audit & Compliance experience.
Experience implementing or assessing NIST SP 800-53 control requirements in production environments (cloud and/or on-prem).
Knowledge of federal cybersecurity and audit frameworks. (This could include NIST SP 800-37 (RMF), NIST SP 800-171, FISMA, FISCAM, OMB Circular A-123, or FedRAMP.)
Demonstrated ability to create accurate, assessor-ready documentation (This could include: SSPs, procedures/SOPs, control narratives, POA&Ms, ConMon reporting, evidence packages).
Preference will be given to candidate's located within the DC Metropolitan area.
What Would Be Nice to Have:
Active and/or the ability to maintain a Top-Secret security clearance.
Federal consulting experience.
Relevant certifications including, but not limited to: CISA, CGRC, CISM, CISSP, and CCSP.
Experience supporting internal audits or external assessments (e.g., 3PAO, independent assessor, IG, state/federal auditors).
Familiarity with enterprise processes such as IT Service Management, Change Management, and SDLC/DevSecOps workflows that commonly supply audit evidence.
Experience collecting and organizing technical and procedural evidence such as IAM configurations, logging/monitoring outputs, vulnerability scans, patch evidence, change records, architecture diagrams, and DR/backup artifacts.
Understanding of common security domains: access management, configuration hardening, vulnerability management, logging/monitoring, incident response, backup/DR, encryption/key management, and SDLC/DevSecOps.
Strong written and verbal communication skills, with the ability to work across diverse teams and translate technical concepts into assessor-friendly language.
The annual salary range for this position is $98,000.00-$163,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.
What We Offer :
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical, Rx, Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Position may be eligible for a discretionary variable incentive bonus
Parental Leave and Adoption Assistance
401(k) Retirement Plan
Basic Life & Supplemental Life
Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
Short-Term & Long-Term Disability
Student Loan PayDown
Tuition Reimbursement, Personal Development & Learning Opportunities
Skills Development & Certifications
Employee Referral Program
Corporate Sponsored Events & Community Outreach
Emergency Back-Up Childcare Program
Mobility Stipend
About Guidehouse
Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at View phone number on click.appcast.io or via email at View email address on click.appcast.io . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or View email address on click.appcast.io . Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact View email address on click.appcast.io . Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
- ...Decisions is a leading Cybersecurity Architecture and... ...and Maintenance IT service provider... ...faced by our federal government... ...Governance, Risk & Compliance (GRC) Analyst to support a... ...compliance efforts, and audit readiness... ...requirements and frameworks. * Maintain governance...SuggestedContract workRemote work
$35k - $48k
The MIL Corporation is looking for a Junior Compliance Officer in Washington, DC. This role supports federal law enforcement clients with I-9 audit services, ensuring compliance with employment eligibility verification processes. Ideal candidates should have an associate...SuggestedWork at office$78.9k - $123.3k
...seeking a detail-oriented cybersecurity compliance professional to support system... ...activities within a Federal environment. This role is responsible... ...in security assessments, audits, and compliance reviews... ...with the NIST Risk Management Framework (RMF). Subject matter...SuggestedPermanent employmentFull timePart timeWork at officeLocal areaRemote work$80k - $120k
...Description SAIC is seeking a Cybersecurity Compliance analyst in Arlington, VA. The roles... ...of the Risk Management Framework with knowledge of network... ...across the defense, space, federal civilian, and intelligence... ...and integration; enterprise IT, including cloud services;...Suggested$105.1k - $122.67k
...billions of dollars in federal broadband funding... ...protected from audit risk through... ...currently serves as the compliance and program... ...Senior Compliance Analyst in our Washington... ...subgrantee tracking frameworks, documentation practices... ..., if it isn't written down...SuggestedFull timeWork at officeLocal areaFlexible hours3 days per week- ...Title: IT Risk and Compliance Professional Location: Washington, DC Duration: 6+ Months... ...The IT risk and compliance or IT audit professional will support Client's IT... ...approach ~ Familiarity with industry frameworks (e.g. COSO, COBIT, NIST, etc.), best practices...
- ...We are hiring a Security & Compliance Analyst to support multiple client environments... ...working closely with client IT leadership and internal... ...and keeping environments audit-ready without unnecessary... ...supporting audits or compliance frameworks such as SOC 2, NIST, CIS, or...Work from homeFlexible hours
- ...chance to work on revolutionary federal IT infrastructure, and the... ..., data operations and cybersecurity. We secure some of the most... ...PTO and more ISSO / Security Compliance Analyst Must be a United States citizen... ...High FedRAMP documentation Audit evidence collection and...Temporary work
$146k - $194k
...THE JOB As a Senior Compliance Analyst, you will serve as a... ...enterprise. Alongside the Cybersecurity Risk and Compliance... ...compliance framework. Operating at the intersection... ...risks, lead external audit readiness, and... ...including Engineering, IT, Legal, Manufacturing...Full timeWork experience placementImmediate start$35k - $48k
...Citizenship: Required Summary The MIL Corporation seeks a Junior Compliance Officer (Operations, Jr. Analyst) to support a federal law enforcement client with I-9 audit support services and worksite enforcement compliance activities. The role assists in...Full timeContract workFor contractorsWork at officeRemote workWeekend work- ...LIS Solutions is seeking a Junior Compliance Officer to join their team in Arlington, VA. This role focuses on supporting federal law enforcement by handling sensitive data and conducting audits related to Employment Eligibility Verification Forms (I-9). The ideal candidate...Work at office
- ...Cybersecurity Compliance Analyst Seeking a skilled Cybersecurity Compliance Analyst to support our client in Washington, DC. The ideal candidate... ...will possess a robust understanding of cybersecurity frameworks and controls, with a specific focus on NIST standards and...
- ...security issues, suspicious activities, and compliance with established standards. Assists... ...issues as necessary. Assists with audits, data calls, and the coordination of... ...checks. Experience: ~5+ years of cybersecurity experience is expected for a mid-level...
- Federal Management Systems is seeking a detail-oriented Junior Compliance Officer in Washington, D.C. This role focuses on data management and compliance auditing, ensuring the integrity of immigration compliance and employment eligibility systems. Key responsibilities...
$77.6k - $176k
Cybersecurity Compliance Analyst Designs, implements, and manages policies and procedures to ensure database and software security. Applies advanced... ...veteran or any other status protected by applicable federal, state, local, or international law. #J-18808-Ljbffr Phase...Full timePart timeWork at officeLocal areaRemote work$77.6k - $176k
....You Have:10+ years of experience with compliance analysisKnowledge of the DoW, its Components... ...to interpret DoD policy regarding cybersecurity, information security, and or information... ...other status protected by applicable federal, state, local, or international law. #J...Full timeContract workPart timeWork at officeLocal areaRemote work$44.8k
...Maximus is searching for an IT Auditor role supporting upcoming federal OPTN work, contingent upon contract award... ...systems by planning and executing audits across information systems and... ...strategies or suggestions. Ensures compliance with IS audit standards, guidelines...Contract work$55k - $165k
...Federal Immigration Compliance Specialist (Department of State) The Position: We are seeking driven... ...and internal policies, supporting audits and risk assessments Monitor partner... ...implement surveys and evaluation frameworks to measure program effectiveness and...Full timeWork at officeRemote workWork from homeFlexible hoursNight shift- Compliance Specialist: The Housing Opportunities Commission of Montgomery County (HOC) was established... ...visits and participate in external agency audits to ensure program property compliance. Will review customer data to ensure Federal, State and Local program compliance for...Local area
- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and... ...policies, supporting compliance audits, and collaborating with... ...deep knowledge of compliance frameworks, and a bachelor's degree in a...Remote job
- ...Payroll & Compliance Specialist At Panda Exteriors, payroll is about more than processing... ...commissions, bonuses, and incentive programs. Audit payroll data for accuracy prior to... ...independent contractors. Ensure compliance with federal, state, and local payroll laws and...Hourly payFull timeFor contractorsFor subcontractorWork at officeLocal areaMonday to FridayShift work
- ...Solutions is hiring a Government Financial and Contract Analyst to support U.S. Federal Government clients in McLean, VA. This hybrid role requires... ...include gathering requirements, data analysis, compliance oversight, and process improvement. Candidates must have...Contract work
$230.4k - $263k
...all interactions with Federal Banking Regulators. We... ...of risk management as it relates to financial services... ...associated regulatory frameworks and risk management... ...services, risk management, audit, consulting, regulatory... ...non-discrimination in compliance with applicable federal...Full timePart timeLocal area$120k - $180k
...Compliance and Data Governance Specialist - Department... ...FAM/NIST compliance and federal enforcement processes... ...Strengthen data governance and cybersecurity protocols, ensuring... ...and maintain audit‑ready documentation, including... ...program’s compliance framework aligns with OMB A-123,...Full timeFor contractorsWork at officeRemote workWork from homeFlexible hoursNight shift- ...information technology, cybersecurity, and cloud support services to the Federal Government. We support... ...the Information Security Compliance Specialist position... ...responses to data calls, audits, and other external requests... ...NIST Risk Management Framework, NIST SP 800-53...Full timeFlexible hours
- ...Compliance Data Analyst ProSidian is a Management And Operations Consulting... ...Compliance | Business Process | IT Effectiveness | Engineering... ...& IT Modernization for Federal science agency HR modernization... ...| ensure accuracy | support audits. Further, they Analyze compliance...Contract workH1bWork at office
- SGI Global is seeking a qualified Junior Compliance Officer to support a federal law enforcement client with I‑9 audit support services and worksite enforcement compliance activities. The role assists in reviewing employment eligibility documentation, conducting database...Contract workFor contractorsLocal areaRemote workWeekend work
- LIS Solutions is looking for a Junior Compliance Officer to support the Department of Homeland Security's worksite enforcement unit. The role involves inputting and evaluating data, conducting database queries, and supporting compliance review activities. Candidates must...Work at office
- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time... ...the complex landscape of cybersecurity compliance and risk management... ...them through compliance frameworks including HIPAA, SOC 2, NIST... ..., and other compliance audits • Perform risk assessments...Full timeRemote work
$310k - $420k
...legal market!Title: Privacy & Cybersecurity Associate Attorney (Mid-... ...Information Security Regulatory Compliance Location: Washington, D.C.,... ...bench of former federal prosecutors, AUSA veterans,... ...Formulating comprehensive compliance frameworks for cutting-edge, data-driven...Full timeFixed term contractFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks). Be the first to apply!
- compliance analyst Washington DC
- regulatory compliance analyst Washington DC
- coding compliance specialist Washington DC
- compliance associate Washington DC
- regulatory compliance specialist Washington DC
- regulatory affairs specialist Washington DC
- compliance consultant Washington DC
- senior compliance officer Washington DC
- senior compliance analyst Washington DC
- information security compliance analyst Washington DC

