Thomson Reuters

Lead Governance & Compliance Analyst

Thomson Reuters$136K — $253K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cloud security, governance, risk, or compliance for federal workloads.
  • In-depth knowledge of FedRAMP, NIST RMF, and NIST SP 800-53 Rev. 5.
  • Experience with FedRAMP Continuous Monitoring and vulnerability management.
  • Proven track record in conducting risk assessments and incident responses.
  • Excellent communication skills to engage with federal agencies and auditors.
  • Ability to analyze security/compliance data and report findings clearly.
  • Bachelor's in cybersecurity or related field, or equivalent experience.

Responsibilities

  • Act as liaison with federal agencies for compliance activities.
  • Lead Continuous Monitoring and vulnerability reporting for FedRAMP.
  • Maintain System Security Plans and related documentation for audit readiness.
  • Oversee risk and incident response processes in line with FedRAMP requirements.
  • Support annual security assessments and related project closures.
  • Collaborate with teams to enhance compliance and security practices.
  • Educate stakeholders on FedRAMP security standards and compliance processes.

Benefits

  • Hybrid work model offering flexibility between office and remote work.
  • Supportive policies for work-life balance and personal responsibilities.
  • Focus on career development and continuous learning opportunities.
  • Comprehensive health benefits and flexible vacation policies.
  • Recognized company culture promoting inclusion and flexibility.
  • Opportunities for social impact through community engagement.
  • Recognition for making a global impact in justice and transparency efforts.
Full Job Description
Are you ready to help secure the trusted technology that powers mission-critical decisions across government and highly regulated industries?

At Thomson Reuters, our technology supports customers who depend on secure, reliable, and compliant platforms to deliver essential outcomes. We are seeking a Lead Governance & Compliance Analyst to join our Operations and Technology organization, supporting our federal government portfolio, including FedRAMP-authorized and in-process platforms for products such as Legal Research and Risk & Fraud.

This role is central to sustaining and evolving the FedRAMP compliance posture of Thomson Reuters' federal-facing products. As a senior technical and governance leader, you will help ensure our cloud environments remain continuously compliant, secure, audit-ready, and aligned with federal requirements. You will partner closely with engineering, product, operations, security, federal agencies, the FedRAMP PMO, and third-party assessment organizations to support authorization activities, strengthen security practices, and help maintain customer trust.

Please note: This position requires access to U.S. Federal Government systems and data under a federal government contract. In accordance with contractual requirements, applicants must be U.S. citizens. This requirement applies only to this role and is mandated by the applicable government contract; it is not a general company policy.

About the Role

In this opportunity as Lead Governance & Compliance Analyst, you will:
  • Serve as a primary liaison with federal agencies, the FedRAMP PMO, third-party assessment organizations, consultants, and internal stakeholders to support ongoing authorization and compliance activities.
  • Lead FedRAMP Continuous Monitoring activities, including POA&M management, vulnerability reporting, monthly deliverables, and recurring agency reporting requirements.
  • Maintain and update the System Security Plan, risk documentation, assessment artifacts, and other required FedRAMP documentation to ensure ongoing audit readiness.
  • Manage vulnerability, risk, and incident response processes in alignment with FedRAMP, NIST RMF, and NIST SP 800-53 Rev. 5 requirements.
  • Support annual security assessments, including planning, scope definition, SAP preparation, security testing coordination, SAR development, POA&M updates, and project closure.
  • Partner with engineering, product, operations, and security teams to drive risk mitigation, compliance improvements, and secure delivery of federal-facing cloud solutions.
  • Educate and guide internal stakeholders on FedRAMP security requirements, continuous monitoring expectations, significant change processes, and compliance best practices.


About You

You're a fit for the role of Lead Governance & Compliance Analyst if your background includes:
  • 5+ years of experience in cloud security architecture, security engineering, governance, risk, compliance, or related roles supporting federal or highly regulated workloads.
  • Demonstrated expertise with FedRAMP, NIST Risk Management Framework, and NIST SP 800-53 Rev. 5 security controls.
  • Experience supporting FedRAMP Continuous Monitoring, including vulnerability management, POA&M tracking, evidence collection, reporting, and control monitoring.
  • Experience conducting or supporting risk assessments, vulnerability scans, incident analysis, and remediation activities within a FedRAMP or regulated environment.
  • Strong communication skills with the ability to engage effectively with federal agencies, auditors, third-party assessors, technical teams, and senior stakeholders.
  • Ability to analyze security and compliance data, identify trends or risks, and produce clear reports for leadership, agencies, and audit partners.
  • Bachelor's degree in cybersecurity, information security, computer science, or a related discipline, or equivalent professional experience.


Preferred Qualifications
  • Experience with cloud environments such as AWS, Azure, or Google Cloud Platform.
  • Experience supporting the FedRAMP Authorization to Operate process.
  • Familiarity with state-level compliance programs such as StateRAMP, GovRAMP, or TX-RAMP.
  • Relevant security or compliance certifications such as CISSP, CISM, CISA, CCSP, Security+, or similar credentials.


#LI-LP2

What's in it For You?
  • Hybrid Work Model: We've adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.
  • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
  • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow's challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
  • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
  • Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
  • Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
  • Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.


In the United States, Thomson Reuters offers a comprehensive benefits package to our employees. Our benefit package includes market competitive health, dental, vision, disability, and life insurance programs, as well as a competitive 401k plan with company match. In addition, Thomson Reuters offers market leading work life benefits with competitive vacation, sick and safe paid time off, paid holidays (including two company mental health days off), parental leave, sabbatical leave. These benefits meet or exceeds the requirements of paid time off in accordance with any applicable state or municipal laws. Finally, Thomson Reuters offers the following additional benefits: optional hospital, accident and sickness insurance paid 100% by the employee; optional life and AD&D insurance paid 100% by the employee; Flexible Spending and Health Savings Accounts; fitness reimbursement; access to Employee Assistance Program; Group Legal Identity Theft Protection benefit paid 100% by employee; access to 529 Plan; commuter benefits; Adoption & Surrogacy Assistance; Tuition Reimbursement; and access to Employee Stock Purchase Plan.

Thomson Reuters complies with local laws that require upfront disclosure of the expected pay range for a position. The base compensation range varies across locations.Eligible office location(s) for this role include one or more of the following: New York City, San Francisco, Los Angeles, and/or Irvine, CA; McLean, VA; Washington, DC. The base compensation range for the role in any of those locations is $136,000 USD - $253,000 USD.Base pay is positioned within the range based on several factors including an individual's knowledge, skills and experience with consideration given to internal equity. Base pay is one part of a comprehensive Total Reward program which also includes flexible and supportive benefits and other wellbeing programs.This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance.

About Thomson Reuters

Thomson Reuters Corporation is a Canadian multinational media conglomerate. The company was founded in Toronto, Ontario, Canada, where it is headquartered at 333 Bay Street. Thomson Reuters provides professionals with the intelligence, technology, and human expertise they need to find trusted answers in the financial and risk, legal, tax and accounting, and media markets. The company is dual-listed on the New York Stock Exchange and the Toronto Stock Exchange. In 2019, the company reported revenues of $5.9 billion and net income of $1.3 billion.
Learn more about Thomson Reuters
Size
24,400 employees
Market Cap
$53.8 billion
Industry
Founded
2008
5 Year Trend
-10.7%
NASDAQ

Similar Jobs

More Jobs at Thomson Reuters

More Information Technology Jobs

Find similar Lead Governance & Compliance Analyst jobs: