Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Risk and Compliance Analyst

Triumph Enterprises

Triumph Enterprises is building the team for a Department of Veterans Affairs Office of Information and Technology / Office of Information Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply chain reporting spine of the program.Program: VA Cybersecurity Architecture and Engineering Services (COSE) Location: Washington, DC (Remote) | Full-Time, Exempt | Contingent upon contract awardThis role is measured against numbers, not activity. You will run a weekly risk analysis rhythm, stand up and operate a full Cyber Supply Chain Risk Management program, and report against specific data quality thresholds the program has committed to meeting.RESPONSIBILITIES- Produce the Security Risk Analysis Report every Friday, 52 per option year.

  • Build and operate the annual Cyber Supply Chain Risk Management (C-SCRM) program, including the strategy and implementation plan, vendor risk assessment framework and scoring rubric, and quarterly briefing package.
  • Own SBOM validation procedures and quarterly SBOM compliance reporting.
  • Maintain the critical supplier inventory and risk prioritization, and implement banned vendor automation.
  • Report FISMA and CISA compliance quarterly, and report performance metrics against committed data quality thresholds: at least 97 percent asset coverage, at least 98 percent data accuracy and completeness on a 30-day rolling average, and 97 percent tagging accuracy.
  • Produce specialized security posture reports, remediation reports following audit activity, and requirements traceability matrices.
  • Support cyber engineering modernization with risk analysis and continuous monitoring.REQUIRED QUALIFICATIONS- Minimum 7 years of information security experience, of which at least 5 years are risk and compliance experience at a large company or Government agency similar in size and scope to VA, DoD, GSA, or IRS.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, Business Administration, Business Management, or a related field. An advanced degree in a related field may substitute for up to 2 years of experience, to a floor of 6 years.
  • Expertise in risk management, compliance, audit, or related roles within an organization.
  • Expertise conducting internal and external audits to assess compliance with regulatory requirements and organizational policies.
  • Expertise developing and implementing risk management programs, including risk assessments, risk mitigation strategies, and continuous monitoring.
  • Expertise in policy development, documentation, and enforcement.
  • Expertise handling and reporting compliance issues and coordinating with regulatory bodies.
  • Demonstrated ability to sustain a weekly reporting cadence in a federal environment.CERTIFICATION (REQUIRED)One or more of the following: Information Assurance Technician (IAT) III, Information Assurance Management (IAM) III, or Information Assurance System Architect and Engineer (IASAE) III. Commonly satisfied by CISSP, CISM, or CASP+. Certification is verified against the current DoD 8140 qualification matrix before an offer is extended. The credentials named above are those most commonly held; any other credential on the current matrix at the required level also qualifies.SUITABILITYThis position requires a Tier 4 / High Risk Public Trust background investigation. A Tier 4 investigation is adjudicated for suitability and fitness and is not a security clearance. Candidates must be U.S. citizens and able to obtain and maintain the investigation, VA systems access, and PIV credentialing. No work may begin until an interim determination is received.PREFERRED- Continuous Diagnostics and Mitigation (CDM) program experience.
  • Cyber supply chain risk management under EO 14028 or NSM-10.
  • Familiarity with CISA binding operational directives.
  • NIST Risk Management Framework and FISMA reporting at a federal agency.
  • Prior VA program experience, particularly within OIT or OIS.ADDITIONAL INFORMATIONTravel is expected to be 0-10%. This position is contingent upon contract award.Triumph Enterprises, Inc. is an SBA-certified Service-Disabled Veteran-Owned Small Business and an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by law.Location:
Job ID: 176 Clearance Type: Public Trust - T4 Employee Type : Regular Full Time Citizenship: US Citizen Only
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Risk and Compliance Analyst in Washington DC vacancy
  •  ...repeatable habit instead of a fire drill. If you're a compliance pro who thrives on building scalable, tech-enabled...  ...” mentality — that's not us. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team, where you'll own... 
    Suggested
    Full time
    Work experience placement
    Work at office

    Nordstrom

    Washington DC
    7 days ago
  • Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their... 
    Suggested
    Full time
    Remote work

    Districttechgroup

    Washington DC
    5 days ago
  • Governance, Risk & Compliance (GRC) Analyst Washington D.C. CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage domain dominance. The company's products are powered by Coherent Distributed Networks (CDN), empowering... 
    Suggested
    Contract work
    For subcontractor
    Casual work
    Relocation package

    Chaos, Inc.

    Washington DC
    4 days ago
  • $121.5k - $188.5k

     ...4 days/week to be considered for this position.Compliance doesn't have to mean dusty binders and once-a-year...  ..., and built to last. Nordstrom's Governance, Risk & Compliance (GRC) team is looking for a Compliance Analyst to help build out three of our most active programs... 
    Suggested
    Full time
    Work at office

    Nordstrom

    Washington DC
    7 days ago
  •  ...Job Description Job Description Job Title:  Compliance Analyst (GRC/RMF Focused)  Pay Type : SALARIED EXEMPT  Location: Hybrid, Washington...  ...Compliance Analyst (GRC/RMF Focused) supports governance, risk, and compliance (GRC) initiatives by developing, maintaining,... 
    Suggested
    Full time
    Monday to Friday

    Quzara LLC

    Washington DC
    17 days ago
  • $79.7k

     ...Budgeting (FPB) has an outstanding opportunity for a Senior Compliance Analyst to join their Office of Merchant Services (OMS) team.  About...  ...and apply expertise in payment security, PCI compliance, and risk management while navigating diverse technical infrastructures... 
    Full time
    Temporary work
    Work at office
    Shift work

    University of Washington

    Washington DC
    14 days ago
  •  ...Compliance Data Analyst ProSidian is a Management And Operations Consulting Services firm that focuses on providing value to clients through...  ...practices. ProSidian provides enterprise services/solutions for Risk Management | Compliance | Business Process | IT... 
    Contract work
    H1b
    Work at office

    ProSidian Consulting

    Alexandria, VA
    1 day ago
  • SME SCRM Policy & Compliance AnalystThis Department of War enterprise data and analytics program...  ...experienced SME SCRM Policy & Compliance Analyst to support the delivery, enhancement, and...  ..., maintain, and govern Supply Chain Risk Management (SCRM) policies, Standard Operating... 
    Contract work

    Navstar

    Alexandria, VA
    5 days ago
  •  ...Regulatory Compliance Specialist ProSidian is a Management and Operations Consulting Services firm that delivers value to clients through...  .... ProSidian provides enterprise services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering... 
    Contract work
    For contractors
    Work at office
    Local area
    Remote work

    ProSidian Consulting

    Washington DC
    4 days ago
  •  ...The Global Trade & Customs (GTC) team is responsible for the compliance execution of global export controls, sanction laws, and regulations...  ...Provide timely guidance and escalation support for high-risk, complex, or ambiguous compliance scenarios Independently prepare... 
    Full time
    Temporary work
    Work at office
    Monday to Friday
    Shift work

    Metrea

    Washington DC
    9 hours ago
  • $90k - $200k

     ...Investigations Kroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is...  ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters... 
    Temporary work
    Flexible hours

    Kroll

    Washington DC
    3 days ago
  •  ...markets. Under the general supervision of the Senior Market Compliance Analyst (Natural Gas, LNG, and Dry Bulk), this role supports the...  ...commercial operations. Working closely with Trading, Commercial, Risk, Operations, Legal, senior management, Market Analysts, and... 
    Full time
    Work at office
    Local area
    Visa sponsorship
    Work visa

    Total Energies

    Washington DC
    10 days ago
  • $62k - $141k

    Cyber Compliance SpecialistThe Opportunity:Designs, implements, and manages policies and procedures to ensure database and software security...  ...or Information Security policyExperience conducting cyber risk assessments, evidence reviews, and compliance checksExperience... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    5 days ago
  • $83.2k - $145.5k

    We're seeking a Compliance Specialist who will play a central role in ensuring product safety and regulatory compliance across Amazon's Store...  ...cross-functional compliance initiatives, identify emerging risks, engage directly with regulators, and collaborate with business... 
    Fixed term contract
    Flexible hours

    Amazon

    Arlington, VA
    14 days ago
  • $166k - $224.4k

     ...provide customers with control and transparency and reduce privacy risk, while enabling partner teams to innovate with appropriate...  ...moderation, privacy, accessibility, and trust.TPA is seeking a HIPAA Compliance Officer responsible for developing, maintaining, communicating,... 
    Flexible hours

    Amazon

    Arlington, VA
    3 days ago
  •  ...through tailored solutions grounded in industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering, Environmental, Sustainability, and Human Capital. We help forward-thinking... 
    Full time
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work
    Flexible hours

    Prosidian Consultng

    Washington DC
    a month ago
  •  ...clients through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness, Energy & Sustainability, and Talent Management. We help forward thinking clients... 
    Full time
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Flexible hours

    Prosidian Consultng

    Washington DC
    a month ago
  •  ...solutions based on industry-leading practices. ProSidian services focus on the broad spectrum of Enterprise Solutions for Risk Management | Compliance | Business Process | IT Effectiveness | Energy & Sustainability | Human Capital. We help forward-thinking clients solve... 
    Contract work
    For contractors
    Work at office
    Remote work

    Prosidian Consultng

    Washington DC
    a month ago
  • $80.05k - $165k

    About the Role:Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and maintenance of IT operating model and facilitating the development of technology policies and standards.Maintain governance documentation... 
    Full time
    Work at office

    Columbia Bank

    Washington DC
    a month ago
  • $62k - $141k

     ...Cyber threats evolve constantly. In this role, you’ll turn complex risk into clear action by supporting Risk Management Framework (RMF)...  ...+ years of experience within cyber risk management or security compliance functionsExperience applying NIST RMF across categorization,... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    5 days ago
  • A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating... 
    Remote job

    Districttechgroup

    Washington DC
    5 days ago
  • Security Compliance Support Role Provides direct support to the Director Security Governance, Risk and Compliance and security shared service team by assuring information system processes and procedures meet or exceed our contractual security compliance requirements. Primary... 

    Software Technology Inc

    Washington DC
    6 days ago
  • $112.7k - $193.2k

     ...Caring. Connecting. Growing together. This District of Columbia Compliance Officer will serve in a role providing direct support to...  ...while ensuring that resources are used effectively to mitigate risks and achieve compliance. This position follows a hybrid schedule... 
    Minimum wage
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Flexible hours
    Shift work

    UnitedHealth Group

    Washington DC
    5 days ago
  • Title: IT Risk and Compliance Professional Location: Washington, DC Duration: 6+ Months Description The IT risk and compliance or IT audit professional will support Client's IT Risk & Compliance team in its efforts to establish an ongoing monitoring program over its information... 

    Two95 International Inc.

    Washington DC
    6 days ago
  • Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship... 
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    2 days ago
  •  ...that holds a high bar for itself - keep reading. Overview Socure is seeking an Analyst, GRC - Public Sector to own the hands-on execution of the company's governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC -... 
    Permanent employment
    Contract work

    Socure Inc

    Washington DC
    6 days ago
  • $95k - $105k

     ...Contingent Upon Contract Award Remote with occasional on-site support Connected Logistics is seeking a senior Risk and Compliance Analyst to support cybersecurity governance, enterprise risk management, compliance oversight, audit readiness, and continuous monitoring... 
    Contract work
    Remote work

    Connected Logistics

    Springfield, VA
    3 days ago
  • Security Risk Management Specialist In depth understanding and hand on experience with NIST 800-53, 800-36 and 800-66 frameworks. Significant...  ...-functional deployments, processes creation and integrations. Nice to have: Privacy (HIPAA) and PCI Compliance experience. Samprasoft

    Samprasoft

    Washington DC
    6 days ago
  • Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship... 
    Remote job
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    2 days ago
  • A consulting firm seeks a Security & Compliance Analyst to support various client environments, concentrating on security operations, compliance preparedness, and risk management. This hands-on position involves collaboration with IT leadership to ensure effective maintenance... 
    Remote work

    Envision Consulting LLC

    Alexandria, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Risk and Compliance Analyst. Be the first to apply!