
Risk and Compliance Analyst
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Generate the Security Risk Analysis Report every Friday, 52 times per option year.
• Establish and manage the annual Cyber Supply Chain Risk Management program.
• Formulate the C-SCRM strategy and implementation plan, vendor risk assessment framework, scoring rubric, and quarterly briefing package.
• Oversee SBOM validation procedures and quarterly SBOM compliance reporting.
• Sustain the critical supplier inventory and prioritize risk management.
• Enforce automation for banned vendor processes.
• Provide quarterly updates on FISMA and CISA compliance.
• Deliver performance metrics against established data quality thresholds: a minimum of 97% asset coverage, at least 98% data accuracy and completeness on a 30-day rolling average, and 97% tagging accuracy.
• Create specialized security posture reports, remediation documents following audit activities, and requirements traceability matrices.
• Assist in the modernization of cyber engineering through risk analysis and continuous monitoring.
• U.S. citizenship is mandatory.
• A minimum of 7 years of experience in information security is required.
• At least 5 years of risk and compliance experience in a large organization or government agency comparable to VA, DoD, GSA, or IRS.
• A bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, Business Administration, Business Management, or a related discipline is necessary.
• An advanced degree in a relevant field may replace up to 2 years of experience, ensuring a minimum of 6 years.
• Proficiency in risk management, compliance, audit, or similar organizational functions.
• Experience in conducting both internal and external audits for compliance with regulations and organizational policies.
• Ability to develop and implement risk management programs, including risk assessments, risk mitigation strategies, and continuous monitoring.
• Skilled in policy development, documentation, and enforcement.
• Experienced in managing and reporting compliance issues while coordinating with regulatory entities.
• Proven capability to maintain a weekly reporting schedule in a federal context.
• One or more required certifications: IAT III, IAM III, or IASAE III, typically satisfied by CISSP, CISM, or CASP+.
• Certification must be validated prior to extending an offer.
• Must be eligible to obtain and sustain a Tier 4 / High Risk Public Trust background investigation, access to VA systems, and PIV credentialing.
• Work may not commence until an interim determination is issued.
• Preferred: Experience with the CDM program.
• Preferred: Knowledge of cyber supply chain risk management per EO 14028 or NSM-10.
• Preferred: Familiarity with CISA binding operational directives.
• Preferred: Experience with the NIST Risk Management Framework and FISMA reporting at a federal agency.
• Preferred: Previous experience with VA programs, particularly within OIT or OIS.
• Regular full-time, exempt employment.
• Remote work opportunities available.
• Travel requirements of 0–10% expected.
• Commitment to equal opportunity employment.
Sprinto
IRIUM
Centene Corporation
Get handpicked remote jobs straight to your inbox weekly.