Logo for Ardent

Governance, Risk, and Compliance (GRC) / Compliance Analyst

Role overview

Qualifications

  • Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications
  • 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support
  • 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments

Responsibilities

  • Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans
  • Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities
  • Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths
  • Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement

Key facts

Hard skills

Other skills

  • Governance
  • Communication
  • Problem Solving
  • Teamwork
  • Analytical Thinking

About the company

Ardent logo

Ardent

IT Services & IT Consulting

For over 15 years, Ardent has served this country by delivering award-winning security and defense technology solutions. Our clients'​ missions range from medical evacuation in overseas theaters to border protection to port security. They trust Ardent to guarantee quality, reliability, and responsiveness. The Ardent Team is the underpinning of our success. Our IT professionals specialize in large-scale situational awareness, geographic visualization, cloud, and information sharing technologies. Ardent inspires its employees to love their jobs. We can help you grow your career by connecting you with our top-notch professionals on challenging projects. We actively mentor and equip our employees to be thought leaders in their fields, and we offer competitive salaries and benefits, including financial rewards for excellence. If you like a fast-paced environment where insights are valued and innovations encouraged, then we want to meet you. Please visit our Career Portal [url: http://www.ardentmc.com/careers] to discover opportunities at Ardent.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Ardent is seeking a Governance, Risk, and Compliance (GRC) / Compliance Analyst to join our team.  

This is a remote position with expected travel to Tallahassee, FL. 

Position Description:

Ardent is seeking a Governance, Risk, and Compliance (GRC) / Compliance Analyst that integrates technical evidence with governance, risk, compliance, and internal-audit support requirements. The role maintains traceability among agency documentation, Rule 60GG-2, NIST CSF, approved procedures, factual findings, remediation actions, and deliverable acceptance criteria while protecting confidential and exempt information across a potentially broad multi-agency environment.

Responsibilities and Duties:

  • Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
  • Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
  • Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
  • Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and the applicable approved criteria.
  • Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement.
  • Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
  • Validate that reports accurately state procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled.
  • Conduct independent QA reviews of technical deliverables not authored solely by the reviewer and document sign-off.
  • Lead technical briefings, workshops, job aids, and knowledge transfer so OCIG and OIG staff can understand and reuse procedures.
  • Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed.

Requirements:

  • Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline.
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
  • 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
  • Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders.
  • Working knowledge of professional auditing or assurance standards and evidence requirements.

Preferred Qualifications:

  • Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains.
  • Government incident-command experience.
  • CISA, CIA, or other audit credential.
  • Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.

Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.

Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk and Compliance Analyst Related jobs

Other jobs at Ardent

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.