Governance, Risk, and Compliance (GRC) / Compliance Analyst
New
A
ArdentCybersecurity / GRC
This is a remote position with expected travel to Tallahassee, FL.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 10 years of progressive cybersecurity experience; 5 years supporting or conducting audits
- Required Skills
- CybersecurityCompliance
Requirements
- Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline.
- Professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
- 10 years of progressive cybersecurity experience (e.g., security operations, incident response, vulnerability management, intrusion analysis).
- 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or regulated environments.
- Demonstrated ability to design defensible test procedures and evaluate control performance.
- Ability to distinguish fact from opinion and communicate technical results to senior stakeholders.
- Working knowledge of professional auditing or assurance standards and evidence requirements.
- Willingness to undergo a government-issued background investigation process.
Responsibilities
- Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
- Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
- Design Ground-Truth and Ad Hoc Testing Strategies, defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, and escalation paths.
- Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and approved criteria.
- Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
- Validate that reports accurately state procedures performed and factual results; ensure advisory recommendations are distinctly labeled.
- Conduct independent QA reviews of technical deliverables and document sign-off.
- Lead technical briefings, workshops, and knowledge transfer initiatives.
- Support urgent analysis of logs, timelines, after-action reports, and incident-specific control issues as directed.
View Full Description & ApplyYou'll be redirected to the employer's site