Risk and Compliance Analyst

Boston Government Services LLC

$136K — $160K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent required.
  • Experience in federal cybersecurity compliance, audit readiness, and risk management.
  • Knowledge of NIST 800-53 Rev. 5 and associated frameworks.
  • Ability to translate technical data into actionable risk reports.
  • Strong writing and stakeholder management skills.
  • U.S. citizenship is mandatory.
  • Eligible for security clearance after drug screening.

Responsibilities

  • Develop and maintain comprehensive risk and compliance documentation.
  • Assist with cybersecurity audits and assessments.
  • Coordinate collection of evidence and stakeholder interactions.
  • Conduct risk analysis on system changes and vulnerabilities.
  • Prepare risk profiles and quarterly FISMA reports.
  • Track and manage waivers and their associated risks.
  • Identify compliance gaps and suggest mitigation strategies.

Benefits

  • Health, Dental, and Vision insurance.
  • Life insurance coverage.
  • Paid Vacation days.
  • 401K retirement plan.
  • Long and Short-Term Disability insurance.
Full Job Description
Responsibilities:

The Risk and Compliance Analyst supports client cybersecurity governance, risk management, compliance reporting, audit support, corrective action tracking, waiver management, and cybersecurity risk visibility. This role helps sustain a defensible risk posture through structured analysis, documentation, reporting, and stakeholder coordination.
  • Support development and maintenance of risk registers, POA&Ms, risk mitigation waiver records, corrective action plans, compliance dashboards, and security metrics.
  • Assist with internal, external, and third-party cybersecurity audits and assessments.
  • Coordinate artifact collection, stakeholder inputs, interview support, remediation tracking, and response documentation.
  • Support risk analysis for system changes, vulnerabilities, exceptions, third-party software, vendor documentation, SBOM inputs, and acquisition-related cybersecurity concerns.
  • Help prepare cybersecurity risk profiles, FISMA quarterly/annual inputs, information security reports, dashboards, and ad hoc risk analyses.
  • Track waiver justifications, risk levels, compensating controls, approval authorities, expiration dates, and annual reassessments.
  • Identify emerging compliance gaps and recommend practical mitigation actions.

Requirements:
  • Bachelor's degree or equivalent.
  • Experience supporting federal cybersecurity compliance, audit readiness, RMF, POA&M management, FISMA reporting, or risk management.
  • Working knowledge of NIST 800-53 Rev. 5, RMF, FISMA, federal-style reporting, CISA BODs, KEV tracking, and corrective action management.
  • Ability to analyze technical and compliance information and convert it into actionable risk reporting.
  • Strong writing, coordination, and stakeholder management skills.
  • Must be a U.S. citizen.
  • Successful drug screening.
  • Must be eligible to obtain and maintain a security or clearance badge.


Preferred Qualifications:
  • CISA, CISM, Security+, CISSP, CAP/CGRC, CRISC, or equivalent.


Location/Work Arrangement:
  • Schedule is full-time, Monday - Friday 40-hour week, 4/10's, or 9/80's and may require on call or overnight shifts depending on contract needs.
  • This position may be fully onsite or hybrid/remote depending on the needs of the specific contract.


Benefits:

BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability.

Starting compensation for this role typical salary ranges between $136,849 - $160,999 annually is commensurate with experience relative to the position and may vary based on candidate geographical location.

Similar Jobs

More Jobs at Boston Government Services LLC

More Education, Government & Non-Profit Jobs

Find similar Risk and Compliance Analyst jobs: