IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks)
$98k - $163kGuidehouse
Job Family:
IT Risk & Controls Consulting Travel Required:
None Clearance Required:
Ability to Obtain Public Trust
What You Will Do:
Guidehouse is seeking an IT Audit & Compliance professional to help our client at a large federal agency pursue and maintain compliance with federal cybersecurity frameworks. This role focuses on audit preparation and coordination. The candidate will:
Coordinate internal and external audit activities across federal information systems, ensuring teams, schedules, evidence, and documentation remain audit‑ready.
Prepare, maintain, and organize assessor‑ready artifacts including SSPs, control narratives, SOPs, POA&Ms, continuous monitoring reports, and structured evidence packages.
Interpret and apply requirements from federal cybersecurity and audit frameworks, including:
NIST SP 800‑53 (security and privacy controls), NIST SP 800‑37 (RMF), NIST SP 800‑171 (CUI), FISMA, FISCAM, OMB Circular A‑123, FedRAMP, and adjacent frameworks such as SOC 1/2, HIPAA, the Privacy Act, and IRS Publication 1075.
Support audit readiness activities by coordinating evidence collection with engineering, ISSO/ISSM, infrastructure, cloud, and application teams.
Track audit findings, maintain POA&M items, and facilitate remediation progress across technical and business teams.
Translate technical implementations into clear, assessor‑ready documentation through strong technical writing and stakeholder coordination.
Draft and refine policies, procedures, and control narratives, and coordinate teams through internal audits, readiness assessments, and corrective action plans.
What You Will Need:
Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred.
Bachelor’s degree in information systems, Cybersecurity, Computer Science, Accounting/IS Audit, or a discipline related to this project.
US Citizenship is required.
Three (3) or more years of IT Audit & Compliance experience.
Experience implementing or assessing NIST SP 800‑53 control requirements in production environments (cloud and/or on‑prem).
Knowledge of federal cybersecurity and audit frameworks. (This could include NIST SP 800‑37 (RMF), NIST SP 800‑171, FISMA, FISCAM, OMB Circular A‑123, or FedRAMP.)
Demonstrated ability to create accurate, assessor‑ready documentation (This could include: SSPs, procedures/SOPs, control narratives, POA&Ms, ConMon reporting, evidence packages).
Preference will be given to candidate's located within the DC Metropolitan area.
What Would Be Nice to Have:
Active and/or the ability to maintain a Top-Secret security clearance.
Federal consulting experience.
Relevant certifications including, but not limited to: CISA, CGRC, CISM, CISSP, and CCSP.
Experience supporting internal audits or external assessments (e.g., 3PAO, independent assessor, IG, state/federal auditors).
Familiarity with enterprise processes such as IT Service Management, Change Management, and SDLC/DevSecOps workflows that commonly supply audit evidence.
Experience collecting and organizing technical and procedural evidence such as IAM configurations, logging/monitoring outputs, vulnerability scans, patch evidence, change records, architecture diagrams, and DR/backup artifacts.
Understanding of common security domains: access management, configuration hardening, vulnerability management, logging/monitoring, incident response, backup/DR, encryption/key management, and SDLC/DevSecOps.
Strong written and verbal communication skills, with the ability to work across diverse teams and translate technical concepts into assessor‑friendly language.
The annual salary range for this position is $98,000.00-$163,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs. What We Offer:
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical, Rx, Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Position may be eligible for a discretionary variable incentive bonus
Parental Leave and Adoption Assistance
401(k) Retirement Plan
Basic Life & Supplemental Life
Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
Short-Term & Long-Term Disability
Student Loan PayDown
Tuition Reimbursement, Personal Development & Learning Opportunities
Skills Development & Certifications
Employee Referral Program
Corporate Sponsored Events & Community Outreach
Emergency Back-Up Childcare Program
Mobility Stipend
About Guidehouse
Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at View phone number on click.appcast.io or via email at View email address on click.appcast.io. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or View email address on click.appcast.io. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact View email address on click.appcast.io. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
Vacancy posted 2 hours ago
Similar jobs that could be interesting for youBased on the IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks) in New York, NY vacancy
$78.9k - $123.3k
...seeking a detail-oriented cybersecurity compliance professional to support system... ...activities within a Federal environment. This role is responsible... ...Federal Risk Management Framework (RMF) requirements.... ...Participate in security assessments, audits, and compliance reviews...SuggestedPermanent employmentFull timeContract workPart timeWork at officeLocal areaRemote work$130k - $170k
...cutting edge security compliance program aligned with FedRAMP... ...security/privacy framework you can think of,... ...performant service. As a GRC Analyst at Virtru, you will be... ...information security, IT audit and/or IT Risk... ...by applicable national, federal, state, or local law.SuggestedFull timeLocal areaFlexible hoursShift work$100k - $125k
## Risk and Compliance AnalystApplyremote type: Hybridlocations... ...Risk and Compliance Analyst will play a key role in... ..., client assessments, audit support, and policy... ...in conducting internal IT risk assessments by gathering... ...with ISO 27001 framework, as well as NIST, SOC 2...Suggested- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York... ...compliance frameworks, conducting risk assessments, supporting audits, and developing policies... ...+ years leading GRC, IT compliance, security,... ...characteristic protected by federal, state, or local laws...SuggestedWork at officeLocal areaRemote workFlexible hours
- ...TECHNOLOGY CONTROLS AND COMPLIANCE ANALYST- REMOTE Job Summary... ...program and improve the framework for ensuring... ...compliance by partnering with IT and business teams. The... ...coordinating with IT, Legal, Auditing and other business... ...with all applicable federal, state, and local laws...SuggestedLocal areaRemote workFlexible hours
$72k - $90k
...growing its Regulatory Compliance team and looking for a Licensing Compliance Analyst to join the US licensing... ...various state and federal rules. These cover money... ...LogicGate), setting the framework for regional SMEs to complete... ...time off when you need it Industry-leading...Full timeWork experience placementWork at officeLocal area$35k - $48k
...Junior Compliance Officer (Operations, Junior Analyst) Position Location New York, NY The MIL Corporation seeks a Junior Compliance... ...Officer (Operations, Jr. Analyst) to support a federal law enforcement client with I ‑ 9 audit support services and worksite enforcement...Full timeContract workFor contractorsWork at officeRemote workWeekend work$310k - $420k
...Title: ~ Privacy & Cybersecurity Associate Attorney (Mid-level... ...Information Security Regulatory Compliance Location: ~... ...unparalleled bench of former federal prosecutors, AUSA veterans,... ...Formulating comprehensive compliance frameworks for cutting-edge, data-...Full timeFixed term contractFlexible hours- ...To support a growing security and compliance program, the full-time remote Security & Compliance Analyst will assist in operating and strengthening the compliance framework, manage SOC 2 audit evidence, and respond to customer inquiries while learning from senior teammates...Full timeRemote work
- ...Polymarket is hiring an AML Compliance Officer to oversee and implement... ...adherence to all applicable federal regulations — including the... ...regulatory examinations and audits Stay current on regulatory changes... ..., and U.S. AML regulatory framework Experience with AML transaction...Contract work
$60k - $80k
...Job Title: Global Trade Compliance Analyst Department : Operations Primary Location... ...and procedures. Review/audit import and export transactions... ...continue to study relevant federal regulations and to continue learning... ...with Sales, Finance, IT, Import and Export personnel,...Full timeWork at officeImmediate startRemote workWork from homeFlexible hours$155k - $175k
...monitoring of FAA, TSA, and other federal regulatory requirements... ...Ensure all aviation IT programs align with federal security frameworks, airport operational standards... ...with federal agencies during audits, inspections, and compliance reviews. Develop and...$85k - $108k
...oriented professional to join our Compliance & Governance team in New York... ...program and governance framework. Reporting directly to the Head... ...relevant local, state, and federal laws and regulations applicable... ...for quarterly risk review, audit sessions, and leadership briefings...Work at officeLocal area$99k - $128.5k
...looking for a Senior Compliance Analyst based in the United States... ...controls, supporting audits and certifications,... ...Evaluate IT General Controls (ITGCs... ...requirements related to cybersecurity, privacy, artificial... ...initiatives, including frameworks such as SOC 1, SOC 2,...Temporary workRemote work- ...GRC function and needs a Senior Compliance Analyst to be the operational engine of... ...owners across Engineering, IT, and Legal to ensure we are continuously audit-ready, not just audit-reactive.... ...timelines. Map findings to applicable framework requirements across SOC 2, ISO...
- ...seeking a detail-oriented and collaborative Compliance Associate to support a broad range of... ..., inquiries, and internal or external audits. Draft, maintain, and update compliance... ...products is preferred. Working knowledge of federal securities regulations and compliance...Work at office
$140k - $185k
...description represents a sample Fund Compliance Analyst position commonly found... ...Launch AI Talent Network. It is intended to help job... ...and the specific regulatory framework they operate under. For more... ...risk assessments, and internal audits of fund activities Identify,...Full time- ...Senior GRC Analyst job at Quantexa. New... ...government security and compliance, applying deep... ...of federal security frameworks is essential particularly... ..., to facilitate audits and ensure... ...development of cybersecurity plans and procedures... ...Teams Partner with IT, legal, and...Contract workTemporary workWork experience placementImmediate start
- ...dynamic healthcare setting. You will verify licenses, complete primary source verifications, audits, and ensure compliance with Joint Commission, NCQA, CMS, and state/federal requirements. Strong attention to detail and communication with medical staff and internal teams...
$21.3 - $35.4 per hour
...other roles. See Yourself as a Compliance Analyst The Compliance Analyst is... ...supporting Radian in meeting critical audit and compliance requirements,... ...the future of our industry. It means seeing each other for... ...complies with all applicable federal, state, and local laws...Remote jobHourly payWork experience placementWork at officeLocal areaImmediate startFlexible hours$56.2k - $94.1k
...Position The State Filing Compliance Analyst plays a critical role in safeguarding... ..., defensible, and auditable. Maintain governance over filing... ...with applicable regulatory frameworks and corporate compliance... ...protected by federal, state, or local law in employment...Contract workWork at officeLocal area- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help... ...directly shape how AI understands and reasons about governance frameworks, audit processes, and control environments - making a...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves... ...compliance roles. Strong skills in GRC tools and risk frameworks are crucial. This position offers competitive compensation...
- ...investments. We are actively seeking a Compliance Analyst to join our team. This remote U.S.-... ...VP of Global Risk Management & Internal Audit. Position Summary The Compliance Analyst... ...and complies with all applicable Federal, State, and Local Laws regarding recruitment...Full timeContract workLocal areaRemote work
$160k - $170k
...Plan, DataCT LLC’s Reporting & Compliance Operations team plays a pivotal... ...oversees the end-to-end compliance framework governing subscriber usage submissions, audit readiness, and operational... ...characteristic protected by applicable federal, state, or local law. DataCT...Interim roleLocal area$120k - $140k
...Position Summary: The Trading and Surveillance Compliance Specialist supports the front office... ...& trading, middle office operations and IT on a timely basis to inquire about matters... ...attributes protected under applicable federal, state, or local laws. #J-18808-Ljbffr...Full timeTemporary workWork at officeLocal areaRemote workFlexible hours3 days per week$90k - $155k
...schedules, FR 2644, FR 2900, and related Federal Reserve, FDIC, and OCC reporting requirements... ...maintenance Internal and external audit requests Assist with implementation and enhancement... ...Familiarity with U.S. banking regulatory framework applicable to large financial...Temporary work$60k
...seeks a motivated and detail-oriented Compliance Analyst to join our Compliance team.This entry... ...moving and cleaning operations adhere to federal and state-specific regulations.You... ...Building and maintaining a pre-cleared rules framework for recurring desk queries.Adv... Show...Hourly payPermanent employmentFull timeWork at officeLocal areaRemote workWork from home$60k - $90k
...sectors. Norton Rose Fulbright is seeking an experienced Compliance (Conflicts) Analyst with conflicts review experience to join our US team.... ...Equal Opportunity Employer and complies with all applicable federal laws and their implementing regulations that require the...Full timeFor contractorsWork at officeRemote workWorldwideFlexible hours- ...requires frequent interaction with Accounting, Operations, and IT to ensure data integrity. Responsibilities: Responsible for preparation... ...for the US Branch, including: Daily & Weekly reports to Federal Reserve: FR2420, FR 2900 & FR 2644 / monthly and quarterly International...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Audit & Compliance Analyst (Federal Cybersecurity Frameworks). Be the first to apply!
Related searches
- regulatory affairs specialist New York, NY
- healthcare compliance officer New York, NY
- regulatory compliance specialist New York, NY
- regulatory reporting analyst New York, NY
- compliance data analyst New York, NY
- risk compliance officer New York, NY
- senior regulatory affairs specialist New York, NY
- research compliance officer New York, NY
- regulatory analyst New York, NY
- compliance coordinator New York, NY

