
Governance, Risk, and Compliance Analyst
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in Florida.
• Oversee the ingestion and analysis of agency documentation, which encompasses risk assessments, remediation plans, previous findings, corrective actions, inventories, and strategic plans.
• Lead the creation of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and their effects on testing priorities.
• Develop the Ground-Truth and Ad Hoc Testing Strategies and authorize detailed procedures that include objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
• Align procedures and findings with NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and relevant approved criteria.
• Ensure testing adheres to written OCIG authorization, prevents duplication of operational testing, and complies with agency-specific Rules of Engagement.
• Assess evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
• Validate reports for accurate representations of procedures executed and factual outcomes without an audit opinion; ensure advisory recommendations are clearly marked.
• Perform independent QA reviews of technical deliverables and manage document sign-off.
• Facilitate technical briefings, workshops, job aids, and knowledge transfer sessions for OCIG and OIG staff.
• Provide urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when required.
• A Bachelor’s degree in cybersecurity, information assurance, auditing, information systems, or a related field.
• Evidence of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other pertinent certifications.
• A minimum of 10 years in progressive cybersecurity roles, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
• At least 5 years of experience in supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
• Proven capability to design robust test procedures, assess control performance, differentiate fact from opinion, and convey technical results to senior stakeholders.
• Familiarity with professional auditing or assurance standards and evidence requirements.
• Willingness to undergo the government-issued background investigation process.
• Preferred: Experience in purple-team or adversary-emulation leadership utilizing MITRE ATT&CK and threat-informed kill chains.
• Preferred: Experience in government incident command.
• Preferred: CISA, CIA, or other auditing credentials.
• Preferred: Proficiency with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.
• Equal opportunity employment and nondiscrimination protections.
• Flexibility to work remotely.
• Expected travel to Tallahassee, Florida.
• Government-issued background investigation process for candidates under consideration.
Consertus
Cartpanda
Syneos Health
Syneos Health
Get handpicked remote jobs straight to your inbox weekly.