Senior Governance Risk and Compliance (GRC) Analyst
C2 Labs, Inc.
Job Description
Job Description
Job Summary:
As a Senior Governance Risk and Compliance (GRC) Analyst at C2 Labs you will lead a team of security analysts and engineers to implement regulatory frameworks such as the Federal Information Security Modernization Act (FISMA), the Federal Risk Authorization Management Program (FedRAMP) and the State Risk Authorization Management Program (StateRAMP). You will leverage GRC tools to develop security authorization package documentation such as the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), and the Plan of Actions & Milestones (POA&M) in human readable and machine-readable formats. You will serve as a Subject Matter Expert (SME) at key stakeholder meetings and will develop and maintain client relationships. You will draft security control implementation statements with enough detail to facilitate the testing of the controls and will develop supporting documentation including the Contingency Plan (CP), Incident Response Plan (IRP), and Configuration Management Plan (CMP). As a Senior GRC Analyst your primary responsibility will be to ensure the timely development of the security authorization package in accordance with C2 Labs quality standards. You will be expected to lead multiple teams and will work on up to 2 packages at a time.
Job Responsibilities:
Categorize systems in accordance with Federal Information Processing Standards (FIPS) 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60. Select and tailor security controls by applying scoping guidance in accordance with NIST SP 800-53 and FedRAMP specific guidance. Document the implementation characteristics for security controls with enough detail to permit the testing of the security control by an independent assessor/Third Party Assessment Organization (3PAO).
- Develop, review, and update security authorization package documentation to include the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), and Plan of Actions and Milestones (POA&M).
- Develop, review, and update supporting documentation including the Contingency Plan (CP), Incident Response Plan (IRP), and Configuration Management Plan (CMP).
- Conduct Security Impact Assessments (SIAs) on changes to information systems.
- Create the Control Implementation Summary (CIS)/Customer Responsibility Matrix (CRM) workbook outline Cloud Service Provider (CSP) and customer responsibilities.
- Develop, review, and update policies and procedures to support the implementation of the NIST 800-53 control families.
- Leverage the next generation of Governance Risk and Compliance (GRC) tools to automate the creation of the SSP.
- Review current security assessment and authorization processes and provide recommendations for improvement.
- Develop Risk Assessment Reports (RAR).
- Provide guidance on NIST 800-53, FedRAMP, and StateRAMP control requirements.
- Develop and deliver training to educate stakeholders on the various tasks and activities associated with the RMF.
Qualifications:
- Minimum 8 years’ experience in IT consulting specializing in Governance, Risk, and Compliance using the RMF.
- CISSP, CISM, or CAP certification, or equivalent preferred
- Excellent communication and interpersonal skills, with the ability to build a rapport and trust with clients.
- Knowledge of the cybersecurity industry to include regulatory frameworks such as the National Institute of Standards in Technology (NIST) Risk Management Framework (RMF), Federal Risk Authorization Management Program (FedRAMP), Department of Defense (DoD) Impact Levels (2-6), and the State Risk Authorization Management Program (StateRAMP).
- Possesses an in-depth understanding of the FedRAMP authorization process and associated templates and deliverables.
- Must have extensive experience creating security authorization package documentation (i.e., SSP, SAP. SAR, & POA&M) and managing system authorization artifacts for a FedRAMP authorized cloud environment.
Working knowledge of:
- NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations
- FedRAMP Security Controls Baselines (i.e., Low, Moderate, High, and Li-SaaS)
- StateRAMP Security Control Baselines (i.e., Low Impact Ready, Low Impact Authorized, Moderate Impact Ready, Moderate Impact Authorized)
- NIST SP 800-37 Guide for Applying the Risk Management Framework to Federal Information Systems
- Must have strong technical writing skills.
- Must be able to work independently under only general direction.
- Must be able to interpret and provide consulting expertise on FedRAMP security requirements.
- Will serve as an RMF Subject Matter Expert (SME) at key stakeholder meetings.
- Must have extensive knowledge in reviewing, analyzing, and documenting the secure implementation of logical controls, physical controls, environmental controls, personnel security, and incident handling.
- Experience preparing monthly continuous monitoring deliverables (e.g., vulnerability scans, POA&Ms, and asset inventory) for submission to the FedRAMP PMO.
- Must be a US Citizen and capable of passing a Public Trust background investigation.
EEO Statement
We are an equal opportunity employer. All qualified applicants will be considered without discrimination based on race, color, religion, sex, national origin, age, disability, or protected veteran status. Employment offers will be contingent on passing a pre-employment drug screen.
Practical AI Application
- Applies AI tools to streamline workflows, enhance decision-making, and improve outcomes
- Understands the strengths and limitations of AI systems and exercises sound judgment in their use
- Continuously explores new AI capabilities and integrates them into day-to-day work where appropriate
- Uses AI in alignment with company and customer-specific policies, data privacy standards, and ethical guidelines
- Exercises discretion when using AI with sensitive or proprietary information
- Demonstrates awareness of bias, accuracy, and risk considerations when leveraging AI tools
- ...C2 Labs is hiring a Senior FedRAMP Consultant (GRC Analyst III equivalent) to act as a lead technical writer... ...• 5+ years experience in GRC/compliance, security documentation, or audit support... ...awareness of bias, accuracy, and risk considerations when leveraging AI tools...SeniorFor contractorsRemote work
- ...Senior Risk Compliance Officer – BSA Systems and Data Analytics Location: On site in Memphis, TN, Nashville, TN, Knoxville, TN, Orlando,... ...the company's compliance with laws, regulations and rules governing bank operations, products, and services. The incumbent provides...SeniorWork at office
- ...Junior FedRAMP Consultant (GRC Analyst I) to support technical writing... ...policies, plans, appendices) under Senior Consultant guidance. •... ...in GRC, audit support, compliance operations, or security documentation... ...of bias, accuracy, and risk considerations when leveraging...SuggestedFor contractorsRemote work
$95k - $105k
...Job Description Sr. GRC Analyst About Subsplash Subsplash... ...About the Role The Senior GRC Analyst acts as a... ...advance security and risk operations. In this role... ...building an AI-first compliance function, and this... ...cadence. 2. Access Governance & Identity Management...SeniorTemporary workCurrently hiringRemote workRelocation$136.85k - $161k
...Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Risk and Compliance Analyst to support our clients in various locations across the US. BGS is an engineering, technology, and...SuggestedFull timeContract workTemporary workRemote workMonday to FridayNight shift- ...learn more, visit inhabit.com. Job Description Summary As a Senior Credit and Risk Analyst, the primary responsibilities include identifying and... ...findings to management. This role will focus on ensuring compliance, preventing risk, and mitigating losses for the company....SeniorFull timeTemporary workWork experience placementWork at officeLocal areaRemote workFlexible hours
$30 per hour
...Role Overview The Ongoing Due Diligence (ODD) Analyst plays a critical role in ensuring ongoing AML and compliance standards for business customers through periodic and... ...reviews. The role focuses on reassessing the risk profile of existing business clients, validating...Odd jobContract workTemporary work$107.06k - $147.21k
...The role involves preparing regulatory submissions, managing product complaints, and collaborating with internal stakeholders on compliance issues. Candidates should have a BS/MS in a scientific discipline, at least 5 years of regulatory experience, and strong communication...Senior- ...Risk Specialist I - Sanctions Location: On site in Miami Lakes, FL; Memphis, TN; Orlando, FL; Johnson City, TN; Birmingham, AL,... ...and apply sanctions regulations to ensure the Bank remains in compliance. Assist with sanction screening system testing for implementation...Work at office
- ## Compliance AnalystApplylocations: Knoxville-Bearden: Chattanooga-Miller Plaza: Sevierville... ...Support assigned compliance monitoring, risk assessment, policy, training, audit,... ...managers.*Advertising, Complaints, and Governance** Maintain advertising tracking records...Local area
- ...Chief Risk Officer (CRO) About the Company Respected banking organization Industry Banking Type Privately... ...credit, interest rate, liquidity, price, operational, compliance, strategic, and reputation risks. This role involves integrating...
- ...Chief Risk Officer (CRO) About the Company Respected banking organization Industry Banking Type Privately Held... ...including credit, interest rate, liquidity, price, operational, compliance, strategic, and reputation risks. This role involves integrating...
$165k - $185k
...provides relocation support to the Germantown area. The SME will be trained to conduct classification review and analysis of government material in accordance with applicable laws, regulations, DOE orders, and DOE Office of Classification procedures for Restricted...SeniorFull timeTemporary workWork at officeRelocation package$75k - $100k
...Senior Analyst, Edits | Payment Integrity (Remote) CGI is seeking a results-oriented Senior... ...) to ensure clinical appropriateness. Compliance: Ensure all edits strictly comply with... ...assignment and/or level of US government security clearance held. Dependent upon...SeniorLocal areaRemote work$130k - $135k
...security, or equivalent experience/certifications. The ability to balance security principles with business realities as part of a risk-managed program. Hands‑on experience performing responsibilities aligned to incident response, security operations, and security...SeniorFull timeRemote workFlexible hoursShift workWeekend workAfternoon shift- Covenant Health is seeking a Reimbursement Financial Senior Analyst to coordinate the reimbursement functions across Covenant Health system entities. The role ensures regulatory reporting compliance, prepares financial filings, and provides leadership for the reimbursement...Senior
- ...Senior Vice President, Corporate Development About the Company Executive leading acquisitions and post-close integration aligned with strategy and values. Type Privately Held About the Role The Company is in need of an SVP, Corporate Development...Senior
- Amentum in Knoxville, Tennessee is seeking a Paralegal/Legal Assistant II to provide direct legal support to the affirmative Civil Enforcement Unit. The role includes reviewing legal documents, supporting investigations, and providing litigation support. Applicants must...Senior
- ...of experience in field surveys. This role involves significant fieldwork and collaboration with project teams to ensure environmental compliance while contributing to sustainable design solutions. A Bachelor's degree in a relevant field is required. #J-18808-Ljbffr...Senior
- ...Eisai US is looking for a Medical Science Liaison (MSL) / Senior Medical Science Liaison (Sr. MSL) to serve as a field representative engaging with healthcare providers and contributing to Eisai’s mission in Oncology and Hematology across Arkansas, Louisiana, Mississippi...Senior
- Cemex US in Knoxville, TN is seeking a Superintendent Maintenance II to lead hourly maintenance staff, oversee daily maintenance activities, and ensure reliability of heavy equipment across our production lines. Under the Maintenance Manager, you will plan, schedule, and...SeniorHourly pay
- ...Addicks CPA Firm is seeking a Tax Senior CPA in Knoxville, Tennessee. This role focuses on providing accurate tax preparation and advisory services while building strong client relationships. Candidates should have between 1 to 4 years of public accounting experience...Senior
- Comfort Systems USA, through Amteck, is seeking a Project Manager to lead large-scale electrical construction projects ranging from $30M–$50M+. In this key role, you’ll oversee project performance, ensure client satisfaction, and manage a collaborative team. The ideal ...Senior
- Keurig Dr Pepper is hiring for a role focused on maintenance management in Knoxville, TN. The position involves leading a substantial team to enhance operational efficiency and improve equipment reliability while managing the site's budget and improvement initiatives. ...Senior
- Pilot Company is seeking a qualified accounting professional in Knoxville, TN to perform core accounting duties and support financial reporting. The role emphasizes accurate ledger maintenance, reporting, and adherence to GAAP and SOX controls. The position requires a ...Senior
- Ardurra is seeking a Water/Wastewater Engineer to join our Knoxville, TN team. In this role, you will plan, design, and manage projects related to water/wastewater treatment and collection. We prioritize a collaborative culture that emphasizes innovation in our engineering...Senior
- Are you a credentialed life insurance producer who feels constrained by corporate caps, captive carrier limitations, or opaque lead structures? We are expanding our network of established financial protection specialists. This 1099 entrepreneurial partnership is tailored...Contract workWork at officeImmediate startRemote work
- ...Overview Corporate office location in the Knoxville area has immediate opening for a Senior Cost Accountant. This job is with a manufacturing organization that is growing steadily, by organic growth and acquisitions. Responsibilities The Senior Cost Accountant reports...SeniorWork at officeImmediate start
- ...design and execution. This hybrid role involves managing complex projects from initial concept through construction, ensuring client satisfaction and compliance. The compensation range is $120,973 - $211,723, with discretionary bonuses available. #J-18808-Ljbffr CDM SmithSenior
$95k - $110k
...Senior Tax Accountant / Tax Supervisor – REMOTE (Atlanta based CPA Firm) To Apply Now - email your resume to job-knemkq7d-1e4ngrk... ...experience in public accounting ● Strong technical skills in tax compliance, research, and planning ● Excellent client communication and...SeniorWork at officeImmediate startRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Governance Risk and Compliance (GRC) Analyst. Be the first to apply!
- risk consultant Knoxville, TN
- operational risk consultant Knoxville, TN
- it risk analyst Knoxville, TN
- operational risk specialist Knoxville, TN
- risk officer Knoxville, TN
- risk analyst Knoxville, TN
- senior hvac project manager Knoxville, TN
- senior medical science liaison Knoxville, TN
- senior accountant remote Knoxville, TN
- sr project manager Knoxville, TN


