Governance, Risk, and Compliance (GRC) / Compliance Analyst
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The role maintains traceability among agency documentation, Rule 60GG-2, NIST CSF, approved procedures, factual findings, remediation actions, and deliverable acceptance criteria while protecting confidential and exempt information across a potentially broad multi-agency environment.
Responsibilities and Duties:
- Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
- Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
- Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
- Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and the applicable approved criteria.
- Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement.
- Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
- Validate that reports accurately state procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled.
- Conduct independent QA reviews of technical deliverables not authored solely by the reviewer and document sign-off.
- Lead technical briefings, workshops, job aids, and knowledge transfer so OCIG and OIG staff can understand and reuse procedures.
- Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed.
Requirements:
- A Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline.
- Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
- 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
- 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
- Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders.
- Working knowledge of professional auditing or assurance standards and evidence requirements.
Preferred Qualifications:
- Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains.
- Government incident-command experience.
- CISA, CIA, or other audit credential.
- Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at ArdentMC
Explore Top Companies in this Space
Optery
Technology / Information Services / Internet / Privacy & Security
Symphony Solutions
Information Technology / Cloud Services / Software Development
Antenna
Media / Technology / Information Services
Trace3
Information Technology & Services / Cybersecurity / Cloud Computing / AI & Data Solutions
ArdentMC
View Company ProfileArdentMC (operating at ardentmc.com) is a specialized technology firm focused on geospatial and IT solutions for the public sector. Founded in 2006 and headquartered in Vienna, Virginia, ArdentMC bridges critical gaps in government and defense operations by delivering high-end geospatial mobile and web-based applications. Unlike traditional IT providers, ArdentMC tailors its solutions to address complex challenges in national security, disaster response, and infrastructure management. Under the hood, the company leverages advanced geospatial information systems (GIS) and IT program management to create scalable, mission-critical platforms. This empowers federal, state, and local agencies to enhance situational awareness, streamline operations, and mitigate risks—whether combating cyber threats or natural disasters. With a revenue footprint of approximately $21 million, ArdentMC operates as a privately held subsidiary, focusing on delivering measurable impact rather than rapid growth.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
