Risk and Compliance Analyst
Triumph Enterprises
Triumph Enterprises is building the team for a Department of Veterans Affairs Office of Information and Technology / Office of Information Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply chain reporting spine of the program.Program: VA Cybersecurity Architecture and Engineering Services (COSE) Location: Washington, DC (Remote) | Full-Time, Exempt | Contingent upon contract awardThis role is measured against numbers, not activity. You will run a weekly risk analysis rhythm, stand up and operate a full Cyber Supply Chain Risk Management program, and report against specific data quality thresholds the program has committed to meeting.RESPONSIBILITIES- Produce the Security Risk Analysis Report every Friday, 52 per option year.
- Build and operate the annual Cyber Supply Chain Risk Management (C-SCRM) program, including the strategy and implementation plan, vendor risk assessment framework and scoring rubric, and quarterly briefing package.
- Own SBOM validation procedures and quarterly SBOM compliance reporting.
- Maintain the critical supplier inventory and risk prioritization, and implement banned vendor automation.
- Report FISMA and CISA compliance quarterly, and report performance metrics against committed data quality thresholds: at least 97 percent asset coverage, at least 98 percent data accuracy and completeness on a 30-day rolling average, and 97 percent tagging accuracy.
- Produce specialized security posture reports, remediation reports following audit activity, and requirements traceability matrices.
- Support cyber engineering modernization with risk analysis and continuous monitoring.REQUIRED QUALIFICATIONS- Minimum 7 years of information security experience, of which at least 5 years are risk and compliance experience at a large company or Government agency similar in size and scope to VA, DoD, GSA, or IRS.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, Business Administration, Business Management, or a related field. An advanced degree in a related field may substitute for up to 2 years of experience, to a floor of 6 years.
- Expertise in risk management, compliance, audit, or related roles within an organization.
- Expertise conducting internal and external audits to assess compliance with regulatory requirements and organizational policies.
- Expertise developing and implementing risk management programs, including risk assessments, risk mitigation strategies, and continuous monitoring.
- Expertise in policy development, documentation, and enforcement.
- Expertise handling and reporting compliance issues and coordinating with regulatory bodies.
- Demonstrated ability to sustain a weekly reporting cadence in a federal environment.CERTIFICATION (REQUIRED)One or more of the following: Information Assurance Technician (IAT) III, Information Assurance Management (IAM) III, or Information Assurance System Architect and Engineer (IASAE) III. Commonly satisfied by CISSP, CISM, or CASP+. Certification is verified against the current DoD 8140 qualification matrix before an offer is extended. The credentials named above are those most commonly held; any other credential on the current matrix at the required level also qualifies.SUITABILITYThis position requires a Tier 4 / High Risk Public Trust background investigation. A Tier 4 investigation is adjudicated for suitability and fitness and is not a security clearance. Candidates must be U.S. citizens and able to obtain and maintain the investigation, VA systems access, and PIV credentialing. No work may begin until an interim determination is received.PREFERRED- Continuous Diagnostics and Mitigation (CDM) program experience.
- Cyber supply chain risk management under EO 14028 or NSM-10.
- Familiarity with CISA binding operational directives.
- NIST Risk Management Framework and FISMA reporting at a federal agency.
- Prior VA program experience, particularly within OIT or OIS.ADDITIONAL INFORMATIONTravel is expected to be 0-10%. This position is contingent upon contract award.Triumph Enterprises, Inc. is an SBA-certified Service-Disabled Veteran-Owned Small Business and an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by law.Location:
- ...repeatable habit instead of a fire drill. If you're a compliance pro who thrives on building scalable, tech-enabled... ...” mentality — that's not us. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team, where you'll own...SuggestedFull timeWork experience placementWork at office
- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...SuggestedFull timeRemote work
- Governance, Risk & Compliance (GRC) Analyst Washington D.C. CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage domain dominance. The company's products are powered by Coherent Distributed Networks (CDN), empowering...SuggestedContract workFor subcontractorCasual workRelocation package
$121.5k - $188.5k
...4 days/week to be considered for this position.Compliance doesn't have to mean dusty binders and once-a-year... ..., and built to last. Nordstrom's Governance, Risk & Compliance (GRC) team is looking for a Compliance Analyst to help build out three of our most active programs...SuggestedFull timeWork at office- ...Job Description Job Description Job Title: Compliance Analyst (GRC/RMF Focused) Pay Type : SALARIED EXEMPT Location: Hybrid, Washington... ...Compliance Analyst (GRC/RMF Focused) supports governance, risk, and compliance (GRC) initiatives by developing, maintaining,...SuggestedFull timeMonday to Friday
$79.7k
...Budgeting (FPB) has an outstanding opportunity for a Senior Compliance Analyst to join their Office of Merchant Services (OMS) team. About... ...and apply expertise in payment security, PCI compliance, and risk management while navigating diverse technical infrastructures...Full timeTemporary workWork at officeShift work- ...Compliance Data Analyst ProSidian is a Management And Operations Consulting Services firm that focuses on providing value to clients through... ...practices. ProSidian provides enterprise services/solutions for Risk Management | Compliance | Business Process | IT...Contract workH1bWork at office
- SME SCRM Policy & Compliance AnalystThis Department of War enterprise data and analytics program... ...experienced SME SCRM Policy & Compliance Analyst to support the delivery, enhancement, and... ..., maintain, and govern Supply Chain Risk Management (SCRM) policies, Standard Operating...Contract work
- ...Regulatory Compliance Specialist ProSidian is a Management and Operations Consulting Services firm that delivers value to clients through... .... ProSidian provides enterprise services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering...Contract workFor contractorsWork at officeLocal areaRemote work
- ...The Global Trade & Customs (GTC) team is responsible for the compliance execution of global export controls, sanction laws, and regulations... ...Provide timely guidance and escalation support for high-risk, complex, or ambiguous compliance scenarios Independently prepare...Full timeTemporary workWork at officeMonday to FridayShift work
$90k - $200k
...Investigations Kroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is... ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters...Temporary workFlexible hours- ...markets. Under the general supervision of the Senior Market Compliance Analyst (Natural Gas, LNG, and Dry Bulk), this role supports the... ...commercial operations. Working closely with Trading, Commercial, Risk, Operations, Legal, senior management, Market Analysts, and...Full timeWork at officeLocal areaVisa sponsorshipWork visa
$62k - $141k
Cyber Compliance SpecialistThe Opportunity:Designs, implements, and manages policies and procedures to ensure database and software security... ...or Information Security policyExperience conducting cyber risk assessments, evidence reviews, and compliance checksExperience...Full timeContract workPart timeWork at officeLocal areaRemote work$83.2k - $145.5k
We're seeking a Compliance Specialist who will play a central role in ensuring product safety and regulatory compliance across Amazon's Store... ...cross-functional compliance initiatives, identify emerging risks, engage directly with regulators, and collaborate with business...Fixed term contractFlexible hours$166k - $224.4k
...provide customers with control and transparency and reduce privacy risk, while enabling partner teams to innovate with appropriate... ...moderation, privacy, accessibility, and trust.TPA is seeking a HIPAA Compliance Officer responsible for developing, maintaining, communicating,...Flexible hours- ...through tailored solutions grounded in industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering, Environmental, Sustainability, and Human Capital. We help forward-thinking...Full timeContract workTemporary workFor contractorsWork at officeLocal areaRemote workFlexible hours
- ...clients through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness, Energy & Sustainability, and Talent Management. We help forward thinking clients...Full timeContract workTemporary workFor contractorsFor subcontractorWork at officeRemote workFlexible hours
- ...solutions based on industry-leading practices. ProSidian services focus on the broad spectrum of Enterprise Solutions for Risk Management | Compliance | Business Process | IT Effectiveness | Energy & Sustainability | Human Capital. We help forward-thinking clients solve...Contract workFor contractorsWork at officeRemote work
$80.05k - $165k
About the Role:Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and maintenance of IT operating model and facilitating the development of technology policies and standards.Maintain governance documentation...Full timeWork at office$62k - $141k
...Cyber threats evolve constantly. In this role, you’ll turn complex risk into clear action by supporting Risk Management Framework (RMF)... ...+ years of experience within cyber risk management or security compliance functionsExperience applying NIST RMF across categorization,...Full timeContract workPart timeWork at officeLocal areaRemote work- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...Remote job
- Security Compliance Support Role Provides direct support to the Director Security Governance, Risk and Compliance and security shared service team by assuring information system processes and procedures meet or exceed our contractual security compliance requirements. Primary...
$112.7k - $193.2k
...Caring. Connecting. Growing together. This District of Columbia Compliance Officer will serve in a role providing direct support to... ...while ensuring that resources are used effectively to mitigate risks and achieve compliance. This position follows a hybrid schedule...Minimum wageFull timeWork experience placementWork at officeLocal areaRemote workFlexible hoursShift work- Title: IT Risk and Compliance Professional Location: Washington, DC Duration: 6+ Months Description The IT risk and compliance or IT audit professional will support Client's IT Risk & Compliance team in its efforts to establish an ongoing monitoring program over its information...
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- ...that holds a high bar for itself - keep reading. Overview Socure is seeking an Analyst, GRC - Public Sector to own the hands-on execution of the company's governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC -...Permanent employmentContract work
$95k - $105k
...Contingent Upon Contract Award Remote with occasional on-site support Connected Logistics is seeking a senior Risk and Compliance Analyst to support cybersecurity governance, enterprise risk management, compliance oversight, audit readiness, and continuous monitoring...Contract workRemote work- Security Risk Management Specialist In depth understanding and hand on experience with NIST 800-53, 800-36 and 800-66 frameworks. Significant... ...-functional deployments, processes creation and integrations. Nice to have: Privacy (HIPAA) and PCI Compliance experience. Samprasoft
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...Remote jobFull timeInternship
- A consulting firm seeks a Security & Compliance Analyst to support various client environments, concentrating on security operations, compliance preparedness, and risk management. This hands-on position involves collaboration with IT leadership to ensure effective maintenance...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Risk and Compliance Analyst. Be the first to apply!
- risk consultant Washington DC
- it risk analyst Washington DC
- operational risk specialist Washington DC
- risk analyst Washington DC
- third party risk analyst Washington DC
- risk officer Washington DC
- senior quantitative risk analyst Washington DC
- operational risk consultant Washington DC
- regulatory analyst Washington DC
- risk and compliance analyst Washington DC


