Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Risk and Compliance Analyst

$98.14k - $115k

9th Way Insignia

9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions. Our specialties include cybersecurity, cloud modernization, software development, data analytics, enterprise architecture, enterprise IT, analytics, process automation, and artificial intelligence. Learn more about 9th Way Insignia at Application password: Niner Team (Project) Introduction We are recruiting for a range of cybersecurity opportunities supporting federal customers, focused on strengthening enterprise security architecture, systems engineering, and the secure implementation of technologies across the environment. The work involves applying established cybersecurity standards, guidelines, and frameworks to help translate organizational and business requirements into secure, scalable technical solutions. Team members may contribute to security architecture and engineering efforts, implementation guidance, technical analysis, and the development of repeatable approaches that support the consistent deployment and operation of secure technologies across complex enterprise environments. Systems security engineering is an important component of this work, with an emphasis on incorporating security and stakeholder protection requirements throughout the system development life cycle, from concept and design through development, production, sustainment, and decommissioning. The team will apply established systems engineering and cybersecurity principles to help protect systems, applications, data, and supporting technologies. Ultimately, this work supports the broader mission to strengthen its cybersecurity posture, reduce organizational risk, and protect critical systems and information from evolving cyber threats, including external adversaries and insider threats. 9th Way Insignia is looking for an Engineer, 3, Risk and Compliance Analyst to join this team.

Professional Level Information: An Engineer, 3 typically plans and directs research or development work on complex projects, along with engaging various parties in design and development. Costs and recommendations of new components may also involve part of the job scope. Performs multiple engineering-related tasks in various assignments within the project and firm. An Engineer, 3 oversees the design, development, implementation, and analysis of technical products and systems. An Engineer, 3 has broad knowledge of engineering procedures and assists in the resolution of complex problems. An Engineer, 3 has strong technical skills and background, a knack for learning new technologies, and a blend of good problem-solving and innovation needed to resolve a wide variety of technical production challenges. Responsibilities: Perform and support comprehensive cybersecurity risk assessments for information systems, applications, platforms, technologies, processes, and enterprise initiatives. Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks. Develop and implement risk-management processes and programs, including risk identification, assessment, prioritization, mitigation, monitoring, and reporting. Develop risk-mitigation strategies and corrective-action recommendations that are technically feasible, actionable, and aligned with Government risk tolerance and mission requirements. Monitor identified risks throughout the system and program lifecycle and track the status and effectiveness of approved mitigation actions. Support continuous monitoring activities to provide ongoing visibility into cybersecurity risk, compliance posture, control implementation, and outstanding remediation requirements. Perform compliance assessments against applicable Federal cybersecurity requirements, VA policies, organizational standards, and approved security baselines. Assess systems and cybersecurity activities for compliance with applicable NIST standards, OMB mandates, VA cybersecurity requirements, and other Federal security frameworks identified within the program. Support risk-management activities aligned with NIST SP 800-53 and the NIST Cybersecurity Framework. Evaluate compliance findings and provide clear recommendations supporting risk-based decisions regarding system accreditation and authorization. Conduct and support internal and external cybersecurity audits, assessments, inspections, and reviews. Coordinate with auditors, assessors, Government representatives, cybersecurity SMEs, system owners, engineers, and other stakeholders throughout audit and assessment activities. Collect, review, organize, and validate supporting evidence requested during audits and assessments, including policies, procedures, system documentation, security reports, configuration information, logs, diagrams, and other technical artifacts. Evaluate audit findings and develop remediation strategies, corrective actions, responsible-party assignments, and resolution timelines. Track audit and compliance findings through resolution and verify that corrective actions adequately address identified deficiencies. Support annual FISMA/FICAM audit activities and assist in developing actionable remediation recommendations for identified findings. Develop and maintain Remediation Reports documenting audit findings, recommended corrective actions, responsible parties, mitigation strategies, and planned resolution timelines. Develop and maintain Security Risk Analysis Reports that identify, evaluate, monitor, and communicate system-security risks. Support development of Specialized Security Posture Reports evaluating the risks associated with new and emerging technologies such as Artificial Intelligence, Cloud Security, Post-Quantum Cryptography, medical devices, and Internet-of-Things technologies. Assess changes in technologies, systems, regulatory requirements, and Government mandates to determine potential risk and compliance impacts. Perform security architecture and compliance gap analyses to identify differences between existing implementations and required VA or Federal security requirements. Document compliance gaps and recommend mitigation strategies consistent with Government security policies and enterprise risk tolerance. Review security configuration and baseline-assessment findings to determine compliance status, deviations, risk implications, and required remediation actions. Support requirements traceability between security controls, architectural requirements, system implementation, evidence, and Authority to Operate (ATO) activities. Develop and maintain Requirements Traceability Matrices (RTMs) supporting accreditation, authorization, and compliance activities. Support Federal Assessment and Authorization (A&A), Risk Management Framework (RMF), and ATO processes as applicable to assigned systems and initiatives. Assist system owners and technical teams with interpreting cybersecurity requirements and determining appropriate evidence needed to demonstrate compliance. Develop, review, maintain, and support enforcement of cybersecurity policies, procedures, standards, guidelines, and governance documentation. Evaluate existing policies and procedures to identify gaps, inconsistencies, or changes needed to maintain alignment with evolving regulatory and organizational requirements. Monitor relevant regulatory, policy, and security-requirement changes and assess their potential impact on VA systems and cybersecurity programs. Identify and report compliance issues, material deviations, and areas of increased risk to appropriate program and Government stakeholders. Prepare risk and compliance information suitable for technical teams, program managers, Government leadership, auditors, and other non-technical stakeholders. Develop reports, briefings, dashboards, risk summaries, compliance status updates, and other materials communicating cybersecurity posture and remediation progress. Maintain accurate and auditable records of risk decisions, findings, mitigation plans, compliance evidence, corrective actions, and closure status. Coordinate with appropriate Government and regulatory stakeholders regarding compliance issues, assessments, findings, and remediation actions. Support Government audit and inspection activities by ensuring requested information and documentation are provided accurately and in a timely manner. Monitor adherence to approved security policies and requirements and escalate significant compliance issues when necessary. Support third-party and supplier risk-management activities where assigned, including evaluation of vendor cybersecurity risk and compliance posture. Assist in developing risk-assessment criteria, scoring methodologies, and risk thresholds for evaluating third-party or supplier cybersecurity risk. Support cybersecurity supply-chain risk-management activities involving vendor assessments, third-party risk, and regulatory compliance. Collaborate with cybersecurity architects, security engineers, DevSecOps personnel, program managers, system owners, technical SMEs, and other stakeholders to integrate risk and compliance requirements throughout the technology lifecycle. Participate in technical reviews, governance forums, risk meetings, audit meetings, engineering working groups, and other activities requiring cybersecurity risk or compliance expertise. Promote a risk-based approach to cybersecurity decision-making, balancing security requirements, mission needs, operational constraints, and remediation priorities May require occasional on-site visits Requirements: Minimum of 7 years of Information Security Experience of which at least 5 years are of risk and compliance experience at a large company or Government agency similar in size/scope to GSA, IRS, DoD or VA. An advanced degree (e.g. Master’s or PhD) in related field may substitute for up to 2 years of the required experience. Expertise in risk management, compliance, audit, or related roles within an organization. Expertise conducting internal and external audits to assess compliance with regulatory requirements and organizational policies. Expertise developing and implementing risk management programs, including risk assessments, risk mitigation strategies, and continuous monitoring. Expertise policy development, documentation, and enforcement. Expertise handling and reporting compliance issues and coordinating with regulatory bodies. Up to two travel times per year Preferred/Desired: Bachelor’s degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or related fields. CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, CCNP Security Salary Range $98,135.18—$115,000 USD 9th Way Insignia’s range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. Clearance/Background Investigation Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information. Benefits Eligible employees will have access to our comprehensive benefits package which includes Medical, Dental, Vision, Voluntary Life Insurance, 401(k), Basic Life A&D, STD, LTD, PTO, Telehealth, paid holidays, FSA, HSA. Additional resources include our Employee Assistance Program (EAP) and Traveling Assistance. Legal We’re an equal employment opportunity employer that empowers our people to fearlessly drive change – no matter their race, color, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, age, marital status, sexual orientation, gender identity, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, or local law. Equal Employment Opportunity Notice Applicants have the right to be free from unlawful workplace discrimination. Please review the EEOC’s

Know Your Rights: Workplace Discrimination is Illegal

notice. Accessible formats and translations are also available from the EEOC.

Application Accommodations If you require a reasonable accommodation to complete this application or participate in the hiring process, please contact View email address on click.appcast.io. Requests will be considered individually.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Risk and Compliance Analyst in Oregon State vacancy
  • $80k - $90k

     ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a IT Risk and Compliance Analyst based in Canada. This role supports the day-to-day execution of a growing IT risk, compliance, privacy, and governance... 
    Suggested
    Contract work
    Remote work

    Jobgether

    Oregon State
    1 day ago
  • $80k - $90k

     ...Location: This position is remote within the United States. The role. We are looking for a Compliance Officer to join the IT Risk and Compliance team and carry the day-to-day execution of the program. This is a generalist role spanning client contracts and security... 
    Suggested
    Contract work
    Currently hiring
    Local area
    Remote work

    HugeInc

    Oregon State
    3 days ago
  •  ...Information Security Experience of which at least 5 years are of risk and compliance experience at a large company or Government agency similar...  ...seeking a highly skilled and experienced Risk & Compliance Analyst to join our dynamic team supporting a large Federal... 
    Suggested
    Temporary work
    Remote work
    Flexible hours

    PingWind

    Oregon State
    1 day ago
  •  ...transactions, making sure we stay compliant with regulations, internal policies, and procedures. This role reports to the Group Head of Risk & Compliance. What you’ll do day to day AML & Customer Onboarding: Reviewing AML documentation against our policies and complete... 
    Suggested
    Work at office

    Token.io

    Oregon State
    13 hours ago
  •  ...GRC Analyst Parallels has an immediate vacancy for this role. Push the boundaries of tech. In your sweatpants. Parallels...  ...Analyst to support the ongoing maturity of our Governance, Risk, and Compliance program. The ideal candidate is experienced in third-party risk... 
    Suggested
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Parallels Inc

    Oregon State
    2 days ago
  •  ...region. Lower salary ranges will apply for other labor markets outside of NCAL.Support Health Plan Risk Adjustment operations through government audit readiness, compliance oversight, and internal quality assurance reviews. Perform coding validation, documentation review... 
    Work experience placement

    Kaiser Permanente

    Portland, OR
    3 days ago
  •  ...and technically proficient Principal GRC Analyst to join our Information Security team, with...  ...security control validation and compliance frameworks to the CDT organization and its...  ...procedures, and reporting mechanismsPrepare risk reports and dashboards for management and... 
    Full time

    SRI Tech

    Portland, OR
    3 days ago
  • $85k - $108k

     ...technology, and customer experience – with long-term success in mind every step of the way. As a GRC Analyst, you will be a key contributor to our Governance, Risk, and Compliance (GRC) program. In this role, your primary focus will be on our third-party risk management... 
    Immediate start

    Forward Financing

    Oregon State
    3 days ago
  • $134k - $202k

     ...PayPal, Ramp, Supreme, and millions of developers worldwide. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    Vercel

    Oregon State
    13 hours ago
  •  ...Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side...  ...strengthen their cybersecurity and compliance programs. You will: Assess and improve...  ...Develop policies, processes, and risk assessments aligned to top frameworks including... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work

    Hotman Group

    Oregon State
    13 hours ago
  • $26 - $30 per hour

     ...ago Requisition ID: 1224 Salary Range: $26.00 To $30.00 Hourly Compliance Specialist AllCare Health | Compliance Department | Grants Pass...  ...HIPAA Privacy and Security referrals. Job Duties Investigations & Risk Management: Manage the investigative process for potential... 
    Hourly pay
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Local area
    Home office
    All shifts
    Monday to Friday
    Flexible hours

    AllCare Health, Inc.

    Grants Pass, OR
    4 days ago
  • $49.89 - $74.34 per hour

     ...strive every day to make life better for others. Our commitment to compliance reflects our dedication to delivering quality healthcare. As a...  ...Compliance Consultant: Leads the annual enterprise compliance risk assessment process and partners with organizational leaders to... 
    Work at office

    Legacy Health

    Portland, OR
    2 days ago
  • $80.05k - $165k

    About The Role Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and maintenance of IT operating model and facilitating the development of technology policies and standards. Maintain governance documentation... 

    Columbia Bank (WA, OR & ID)

    Hillsboro, OR
    5 days ago
  • $114k - $139k

     ...As a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital...  ...You will play a critical role in maintaining our Governance, Risk, and Compliance (GRC) posture. Working independently with review at critical... 
    Temporary work
    Work experience placement
    Remote work

    Clear Capital | CubiCasa | restb.ai

    Oregon State
    1 day ago
  •  ...exceptions and data breaks ✅ Collaborate with Treasury, Liquidity Risk, Finance, and IT teams ✅ Maintain reporting controls,...  ...Skills: Regulatory Reporting FR 2052a FDIC Reporting Risk & Regulatory Compliance Analytics Data Analysis & Reconciliation... 

    Delan Associates, Inc

    Oregon State
    13 hours ago
  • $62.2k - $100.2k

     ...Trade Compliance Analyst – Remote - US East Coast Come build something that matters. It takes great people to achieve greatness. People with a sense of purpose and integrity. People with a relentless pursuit of excellence. People who care about making things better... 
    Full time
    Work at office
    Local area
    Remote work

    Stanley Black & Decker, Inc.

    Oregon State
    1 day ago
  • $80k - $90k

     ...Position Summary SRS Acquiom is currently searching for a Compliance Analyst for our Contract Administration department. The...  ...requests. Facilitate timely problem resolution to mitigate risk and prioritize action. Accountable for the quality, accuracy... 
    Contract work
    Work at office
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours
    Night shift
    Weekend work
    2 days per week
    1 day per week

    SRS Acquiom

    Oregon State
    1 day ago
  • $85k

     ...all applications and next steps. Our partner is looking for a Compliance Analyst based in United States. This remote role offers the...  ...quality, security, and network teams, you will help identify risks and drive effective remediation. You will also support regulatory... 
    Temporary work
    Remote work

    Jobgether

    Oregon State
    1 hour ago
  •  ...efficiently to provide exceptional legal and compliance services to our internal stakeholders,...  ...industry. We are hiring a Compliance Analyst to be an integral member of the Legal...  ...keeping up-to-date and managing compliance risks that impact our business and the DMEPOS... 
    Temporary work
    Local area
    Remote work

    Integra Partners

    Oregon State
    13 hours ago
  • $69.7k - $94.3k

    Compliance Analyst I, II or IIIHybrid role (3 days/week in office) at our Portland, Medford, Fargo, Burlington, Vancouver, Renton, Boise, Lewiston...  ...and other laws. Duties may include, but are not limited to, risk assessment, training, monitoring, auditing, regulatory audit,... 
    Full time
    Work at office
    Immediate start
    Work from home
    Flexible hours
    3 days per week

    Cambia Health Solutions

    Portland, OR
    1 day ago
  •  ...long-term growth.• To provide a return on investment to shareholders.• To promote employee development. Job DescriptionA Compliance Business Analyst within the Compliance Change Management (CCM) department is responsible for the ongoing implementation of compliance solutions... 
    Work at office

    Xinnovit

    Beaverton, OR
    4 days ago
  •  ...a central bank. We are seeking a meticulous and proactive Compliance Analyst to join our growing Legal & Compliance team in Brazil. This role...  ...Enhanced Due Diligence (EDD): Lead investigations for high-risk customers or complex corporate structures, preparing risk... 
    Local area

    Coins Ph

    Oregon State
    13 hours ago
  • $59.07k

     ...Description Job Description Wage starts at $59,066.00/annually. Rogue Community Health is looking to welcome a full-time Compliance Improvement Analyst to our team! This position is responsible for facilitating the ongoing assessment and maintenance of the Compliance... 
    Full time
    Temporary work
    Local area

    Rogue Community Health

    Medford, OR
    27 days ago
  • $69.7k - $94.3k

    Position Overview Compliance Analyst (Levels I, II or III) - Hybrid role (3 days/week in office). Candidates must be able to commute to one of...  ..., measure and refine compliance program activities. Conduct risk assessments, training, monitoring, auditing, regulatory audits... 
    Work at office
    Remote work
    3 days per week

    Cambia Health Solutions

    Portland, OR
    4 days ago
  • A leading trade compliance consulting firm is seeking a professional to develop effective communication and conduct research on Customs regulations. The role involves preparing analysis reports, performing audits, and ensuring compliance with U.S. Customs. Candidates should... 

    Tradewin

    Portland, OR
    4 days ago
  • $66k - $96.25k

     ...commitment. Are you ready to make a difference? Job Summary The Compliance Analyst supports insurance product compliance by researching...  ...to compliance programs, policies, procedures, training, and risk management activities. Skills and Background You'll Need Education... 
    Shift work

    Talentify.io

    Portland, OR
    4 days ago
  •  ...documentation. Meticulous attention to detail is required to troubleshoot and investigate information, resolve issues, and identify compliance risks. The Specialist will play a key role in process improvement projects such as commodity classification determination (HTS/ECCN)... 
    Temporary work
    Work at office
    Local area
    Remote work
    Worldwide

    Ichor Systems

    Myrtle Point, OR
    1 day ago
  •  ...growers protect crops while reducing the use of conventional pesticides. We're looking for a Regulatory & Environmental Compliance Analyst to join our Global Regulatory Affairs team at our headquarters in Bend, Oregon. This is an excellent opportunity for someone... 
    Full time
    Work at office
    Local area
    Remote work
    Relocation

    Suterra

    Bend, OR
    21 days ago
  • $38.56 - $57.88 per hour

     ...Assists in the creation and implementation of regulatory affairs department policies and procedures to ensure that regulatory compliance is maintained or enhanced Support operations by reviewing incoming project contracts and provide guidance for regulatory requirements... 
    Hourly pay
    Remote work
    Home office

    Adaptive Biotechnologies

    Oregon State
    1 day ago
  • $26 - $30 per hour

    The Compliance Coordinator is responsible for supporting and maintaining the company’s compliance with domestic and international shipping, import/export, transportation, and regulatory requirements. This position coordinates closely with internal departments, customers... 
    Hourly pay
    Work at office
    Night shift

    Valin Corporation

    Portland, OR
    1 hour ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Risk and Compliance Analyst. Be the first to apply!