Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks)

$98k - $163k
Full-time

Guidehouse

Job Family: IT Risk & Controls Consulting Travel Required: None Clearance Required: Ability to Obtain Public Trust What You Will Do: Guidehouse is seeking an IT Audit & Compliance professional to help our client at a large federal agency pursue and maintain compliance with federal cybersecurity frameworks. This role focuses on audit preparation and coordination. The candidate will: Coordinate internal and external audit activities across federal information systems, ensuring teams, schedules, evidence, and documentation remain audit‑ready. Prepare, maintain, and organize assessor‑ready artifacts including SSPs, control narratives, SOPs, POA&Ms, continuous monitoring reports, and structured evidence packages. Interpret and apply requirements from federal cybersecurity and audit frameworks, including: NIST SP 800‑53 (security and privacy controls), NIST SP 800‑37 (RMF), NIST SP 800‑171 (CUI), FISMA, FISCAM, OMB Circular A‑123, FedRAMP, and adjacent frameworks such as SOC 1/2, HIPAA, the Privacy Act, and IRS Publication 1075. Support audit readiness activities by coordinating evidence collection with engineering, ISSO/ISSM, infrastructure, cloud, and application teams. Track audit findings, maintain POA&M items, and facilitate remediation progress across technical and business teams. Translate technical implementations into clear, assessor‑ready documentation through strong technical writing and stakeholder coordination. Draft and refine policies, procedures, and control narratives, and coordinate teams through internal audits, readiness assessments, and corrective action plans. What You Will Need: Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred. Bachelor’s degree in information systems, Cybersecurity, Computer Science, Accounting/IS Audit, or a discipline related to this project. US Citizenship is required. Three (3) or more years of IT Audit & Compliance experience. Experience implementing or assessing NIST SP 800‑53 control requirements in production environments (cloud and/or on‑prem). Knowledge of federal cybersecurity and audit frameworks. (This could include NIST SP 800‑37 (RMF), NIST SP 800‑171, FISMA, FISCAM, OMB Circular A‑123, or FedRAMP.) Demonstrated ability to create accurate, assessor‑ready documentation (This could include: SSPs, procedures/SOPs, control narratives, POA&Ms, ConMon reporting, evidence packages). Preference will be given to candidate's located within the DC Metropolitan area. What Would Be Nice to Have: Active and/or the ability to maintain a Top-Secret security clearance. Federal consulting experience. Relevant certifications including, but not limited to: CISA, CGRC, CISM, CISSP, and CCSP. Experience supporting internal audits or external assessments (e.g., 3PAO, independent assessor, IG, state/federal auditors). Familiarity with enterprise processes such as IT Service Management, Change Management, and SDLC/DevSecOps workflows that commonly supply audit evidence. Experience collecting and organizing technical and procedural evidence such as IAM configurations, logging/monitoring outputs, vulnerability scans, patch evidence, change records, architecture diagrams, and DR/backup artifacts. Understanding of common security domains: access management, configuration hardening, vulnerability management, logging/monitoring, incident response, backup/DR, encryption/key management, and SDLC/DevSecOps. Strong written and verbal communication skills, with the ability to work across diverse teams and translate technical concepts into assessor‑friendly language. The annual salary range for this position is $98,000.00-$163,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs. What We Offer: Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace. Benefits include: Medical, Rx, Dental & Vision Insurance Personal and Family Sick Time & Company Paid Holidays Position may be eligible for a discretionary variable incentive bonus Parental Leave and Adoption Assistance 401(k) Retirement Plan Basic Life & Supplemental Life Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts Short-Term & Long-Term Disability Student Loan PayDown Tuition Reimbursement, Personal Development & Learning Opportunities Skills Development & Certifications Employee Referral Program Corporate Sponsored Events & Community Outreach Emergency Back-Up Childcare Program Mobility Stipend About Guidehouse Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation. Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco. If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at View phone number on click.appcast.io or via email at View email address on click.appcast.io. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation. All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or View email address on click.appcast.io. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact View email address on click.appcast.io. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties. Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks) in United States vacancy
  • $62.6k - $98.34k

     ...We are hiring an IT Security Compliance Analyst to join our IT Team...  ...management, and the Internal Audit functions. You'll...  ..., and support cybersecurity and compliance initiatives...  ...and regulatory frameworks, and help maintain a...  ...In compliance with federal law, all persons hired... 
    Suggested
    Full time
    Local area
    Shift work

    Masco Corporation

    Vista, CA
    17 hours ago
  •  ...purpose. We're hiring an IT Compliance Analyst to support our Information...  ...Risk Management team through audit coordination, risk tracking...  ...in Information Technology, Cybersecurity, Computer Science, or a...  ...understanding of risk and control frameworks such as NIST, ISO, or FFIEC... 
    Suggested
    Work at office
    Local area

    Northpointe Bank

    Grand Rapids, MI
    4 days ago
  •  ...is currently seeking an IT Security Compliance Analyst to join our team!Since 19...  ...risk assessments, support audits, and help optimize our security...  ...and grow your career in cybersecurity compliance, come join us!...  ...of information security frameworks and standards (NIST, ISO... 
    Suggested
    Work at office
    Remote work
    Flexible hours

    GUARANTEE TRUST LIFE INS CO

    Elkhorn, WI
    1 day ago
  •  ...Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the...  ...governance, risk, and compliance activities aligned with regulatory frameworks and internal policies. Core...  ...with Enterprise Risk, Audit (internal and external),... 
    Suggested
    Work at office
    Remote work

    Trustmark

    Ridgeland, MS
    1 day ago
  •  ...is looking for a talented Analyst III, IT Infosec to join us in...  ...IT governance, risk, and compliance program. This role is responsible...  ...and testing, maintaining audit-ready evidence, and...  ...requirements, SOX obligations, cybersecurity frameworks, internal policies, and UCT... 
    Suggested
    Contract work
    Local area

    Ultra Clean Technology Systems & Svc Inc

    Manor, TX
    27 days ago
  •  ...LOCALS PLEASE IT Auditor /Government & risk compliance consultant...  ...to stand up within cybersecurity. They're looking to...  ...what will be many audits of controls (understanding...  ...for the data analyst. Issues...  ...requirements and control frameworks (e.g., SOX, COSO,... 
    Local area

    RIT Solutions, Inc.

    Fernandina Beach, FL
    2 days ago
  •  ...sensing applications. Job Title IT Compliance Analyst Location Tempe, AZ Division...  ...for the compliance frameworks are designed, managed, and...  ...continuous monitoring and driving audit actions to ensure adherence...  ...protected by applicable federal, state, or local law. Incumbent... 
    Local area

    Quantum Computing Inc.

    Tempe, AZ
    11 hours ago
  • ## IT Compliance AnalystApplylocations: Midland, TXtime type...  ...**The IT Compliance Analyst is responsible for administering...  ..., corporate, and cybersecurity requirements. The Analyst coordinates audits, manages compliance...  ...of IT compliance frameworks and standards, including... 

    ProPetro Services

    Midland, TX
    1 day ago
  • $75k - $85k

     ...Solution Architects (CSA) is seeking an IT Compliance Analyst to join our growing company in support...  ...services to meet the defense and federal sector's most complex enterprise needs...  ...experience executing the NIST Risk Management Framework (RMF) and/or the DoD Information Navy... 
    Full time
    Contract work
    For contractors
    Work at office
    Remote work

    CSA Global

    Pensacola, FL
    1 day ago
  •  ...IT Compliance Analyst Location: Billerica, MA (Hybrid) ROLE SUMMARY The IT Compliance Analyst...  ...compliance across a range of frameworks, including SOX, cybersecurity, and applicable regulations...  ...control monitoring, documentation, and audit support activities, strengthening... 
    Work at office
    Remote work

    Quanterix

    Billerica, MA
    1 day ago
  • $105k - $130k

     ...IT Compliance Analyst Billerica, MA (Hybrid) Quanterix is a global leader in ultra...  ...compliance across a range of frameworks, including SOX, cybersecurity, and applicable regulations impacting...  ...monitoring, documentation, and audit support activities. This role plays... 
    Work at office
    Work from home

    Quanterix

    Billerica, MA
    17 hours ago
  • Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's...  ...Governance, Risk, and Compliance program, with...  ...engagements, maintain the policy framework, and manage auditor...  ...Information Technology, Cybersecurity, or a related field (equivalent... 
    Work at office
    Remote work

    CMG Financial

    United States
    20 hours ago
  •  ...Career Opportunities: Cybersecurity Compliance Analyst (17423) Functional Title: Cybersecurity...  ...Comm; Department: SP28 IT Security; Posting Number: 1...  ...cybersecurity compliance, audit coordination, policy and...  ...security principles, compliance frameworks, security policies,... 
    Permanent employment
    Full time
    Contract work
    Temporary work
    Part time
    Shift work

    Fall Creek Farm & Nursery

    Austin, TX
    17 hours ago
  •  ...organization's security and compliance objectives, the...  ...Program Analyst II will manage system...  ...coordinate with federal agencies and...  ...assessments and audits. Key responsibilities...  ...Systems, Cybersecurity, Computer Science...  ...knowledge of NIST-based frameworks and the ATO lifecycle... 
    Full time
    For contractors
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst Job Category: Information...  ...compliance, IT risk management, security...  ...assess risks, support audits, and develop policies...  ...security best practices and frameworks, such as NIST Special...  ...rights pursuant to federal employment laws.For... 
    Full time
    Casual work
    Work at office
    Work from home
    Home office
    Night shift
    Weekend work

    Delta Dental of Missouri

    Kansas City, MO
    2 days ago
  •  ...Position: Security & Compliance Analyst LCAT: Mid Location: SOUTHCOM...  ...Bachelor's degree in Cybersecurity, Information...  ...policies, regulatory frameworks, and cybersecurity best...  ...security assessments and audits to verify adherence...  ...benefits PTO 11 paid federal holidays Tuition... 
    Temporary work
    Work at office
    Flexible hours

    NALLEY CONSULTING, LLC

    Florida, NY
    1 day ago
  • $109k - $181.5k

     ...Senior Compliance Analyst Elevate your career with MANTECH International...  ...of Defense, and Federal Civilian sectors. Dive into...  ...in Digital Transformation, Cybersecurity, IT, Data Analytics and Software...  ...Familiarity with common regulatory frameworks related to government... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Local area
    Remote work

    ManTech

    Herndon, VA
    3 days ago
  • $125k - $175k

    IT Security Compliance Analyst At Five Rivers IT, we build and service reliable IT infrastructures for...  ...scoping, execution and documentation of audits primarily in areas associated with...  ...information technology management frameworks such as ISO 27001, NIST, CIS, ITIL,... 
    Full time
    Work experience placement

    Five Rivers IT

    Fair Lawn, NJ
    2 days ago
  • $78.9k - $123.3k

     ...seeking a detail-oriented cybersecurity compliance professional to support system...  ...activities within a Federal environment. This role is responsible...  ...in security assessments, audits, and compliance reviews...  ...with the NIST Risk Management Framework (RMF). Subject matter... 
    Permanent employment
    Full time
    Part time
    Work at office
    Local area
    Remote work

    Noblis

    Bismarck, ND
    17 hours ago
  • $80k

     ...Information Security Risk & Compliance Analyst will be responsible...  ...existing and future frameworks, legal and regulatory...  ...Design and document IT general controls to...  ...timely delivery to audit. Assist with third party...  ...Systems, NIST Cybersecurity Framework, NIST 800,... 
    Full time

    Ryder

    Coral Gables, FL
    1 day ago
  • $95k - $105k

     ...Description Sr. GRC Analyst About Subsplash...  ...take our word for it—head to Glassdoor...  ...operational excellence and framework maturity. You will...  ...an AI-first compliance function, and this...  ...Management & Audit Leadership Audit...  ...moments" to keep cybersecurity top-of-mind for all... 
    Temporary work
    Currently hiring
    Remote work
    Relocation

    Subsplash

    Indianapolis, IN
    15 days ago
  •  ...Cross-Functional Governance, Risk, and Compliance Consultant We are seeking a skilled...  ...Compliance consultant that can work with IT Compliance and IT Risk on assessments,...  ...Qualifications: Experience with conducting IT/Cybersecurity audits, risk assessments, privacy assessments.... 

    Samprasoft

    Urbandale, IA
    17 hours ago
  •  ...Job description Risk and Compliance Analyst Houston, TX(5 days onsite)...  ...mitigation planning. Lead or coordinate IT related projects including planning, execution...  ...updates. Collaborate with cybersecurity, infrastructure, and operations teams to... 

    VDart

    Houston, TX
    2 days ago
  • $70k - $80k

    As a GRC Cybersecurity Analyst (CA), you will play a pivotal role...  ..., Risk, and Compliance (GRC) directly to our...  ...Internal Cybersecurity Audits to ensure our clients...  ..., technical auditor, IT administrator with security...  ...Experience with any security frameworks (NIST CSF, CIS, COBIT... 
    Full time
    Work at office

    Fractional CISO

    Newton, MA
    1 day ago
  •  ...Governance, Risk & Compliance (GRC) Analyst Client is seeking a...  ...strengthening their cybersecurity posture, ensuring regulatory...  ...supporting strategic IT goals. Key...  ...Develop and maintain GRC frameworks aligned with SOC 2,...  ...Conduct internal audits and risk assessments... 

    Group Nine LLC

    Middleton, WI
    1 day ago
  • $60k - $75k

     ...problems, managing compliance, and helping keep cybersecurity and government contract...  ...is seeking a GRC Analyst for our client in...  ..., risk management, audit readiness, and government...  ...Work closely with IT, HR, Operations,...  ...of compliance frameworks, cybersecurity controls... 
    Contract work
    Relocation
    Relocation package
    Monday to Thursday

    Qualified Staffing

    Macon, GA
    3 days ago
  • $160k - $190k

     ...Description Job Description Senior Federal Cybersecurity & Compliance Consultant  (Expert in CMMC,...  ...organizations meet stringent IT and regulatory frameworks, including CMMC, NIST, FedRAMP, ISO...  ...strategies, and evidence artifacts for audits  ~ Continuously enhance... 
    Full time
    Remote work
    Flexible hours

    Elevate

    Coral Gables, FL
    a month ago
  • $100k - $150k

     ...Job Title: Lead Security Compliance Advisor (GRC) Location:...  ...Required Skills: ~5+ years of cybersecurity consulting/assessment...  ...projects or engagements ~ U.S. Federal Framework Mastery ( FedRAMP ,...  ...corporate red tape and checklist auditing; here, you own the client... 
    Permanent employment
    Contract work
    Remote work
    Shift work

    Field of Talent

    Columbus, OH
    15 days ago
  • $130k - $170k

     ...cutting edge security compliance program aligned with FedRAMP...  ...security/privacy framework you can think of,...  ...performant service. As a GRC Analyst at Virtru, you will be...  ...information security, IT audit and/or IT Risk...  ...by applicable national, federal, state, or local law.
    Full time
    Local area
    Flexible hours
    Shift work

    Virtru

    United States
    3 days ago
  •  ...We are from US IT Solutions, an ISO Certified, E-Verify, WMBE Certified organization established in 2005 in CA. O ur company...  ...and/or ongoing maturation of SCDHHS security and compliance efforts. Audit and Assess internal agency systems as well as business partner... 
    Work at office
    Local area
    Flexible hours

    US IT Solutions Inc

    Columbia, SC
    17 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks). Be the first to apply!