Governance, Risk, and Compliance (GRC) / Compliance Analyst

New
A
ArdentCybersecurity / GRC
This is a remote position with expected travel to Tallahassee, FL.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
10 years of progressive cybersecurity experience; 5 years supporting or conducting audits
Required Skills
CybersecurityCompliance

Requirements

  • Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline.
  • Professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 10 years of progressive cybersecurity experience (e.g., security operations, incident response, vulnerability management, intrusion analysis).
  • 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or regulated environments.
  • Demonstrated ability to design defensible test procedures and evaluate control performance.
  • Ability to distinguish fact from opinion and communicate technical results to senior stakeholders.
  • Working knowledge of professional auditing or assurance standards and evidence requirements.
  • Willingness to undergo a government-issued background investigation process.

Responsibilities

  • Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
  • Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
  • Design Ground-Truth and Ad Hoc Testing Strategies, defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, and escalation paths.
  • Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and approved criteria.
  • Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
  • Validate that reports accurately state procedures performed and factual results; ensure advisory recommendations are distinctly labeled.
  • Conduct independent QA reviews of technical deliverables and document sign-off.
  • Lead technical briefings, workshops, and knowledge transfer initiatives.
  • Support urgent analysis of logs, timelines, after-action reports, and incident-specific control issues as directed.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now