| Title: | Risk and Compliance Analyst |
|---|---|
| ID: | 549 |
| Department: | Cybersecurity |
| Location: | Remote |
Excentium, Inc. is a Service-Disabled Veteran-Owned Small Business (SDVOSB) that provides Cybersecurity Consulting and Advisory, Assessment, and Cybersecurity Architecture and Engineering services to government and commercial organizations. Excentium is an accredited FedRAMP Independent Assessor (IAS), formerly known as a Third-Party Assessment Organization (3PAO).
We are building our team in support of a major U.S. Department of Veterans Affairs (VA) cybersecurity architecture and engineering program, and have an opportunity for a Risk and Compliance Analyst to support enterprise security architecture, engineering, and operations across VA's Office of Information Security (OIS).
|
MINIMUM CLEARANCE LEVEL: |
Public Trust — High Risk (Tier 4) Background Investigation |
|
CITIZENSHIP: |
US Citizenship required |
|
LOCATION: |
Remote / Contractor facility, with occasional coordination at VA Central Office (Washington, D.C.) and limited program-related travel as required |
Position Description:
The Risk and Compliance Analyst will lead risk management and compliance activities across the program, conducting internal reviews, supporting audits, and maintaining the documentation, policies, and continuous monitoring processes that keep VA systems in compliance with federal and VA-specific security requirements. This role partners with the architecture and engineering team to assess control effectiveness and translate compliance findings into practical, risk-informed recommendations for VA stakeholders.
Position Requirements:
- 7+ years of information security experience, including 5+ years focused on risk and compliance at a large company or federal agency of comparable scale. An advanced degree (e.g., Master's or PhD) in a related field may substitute for up to 2 years of the required experience.
- Experience conducting internal and external audits to assess compliance with regulatory requirements and organizational policy.
- Experience developing and implementing risk management programs, including risk assessments, mitigation strategies, and continuous monitoring.
- Experience with security policy development, documentation, and enforcement, and in handling and reporting compliance issues to regulatory bodies.
Educational Requirements/Qualifications:
- Bachelor's degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or a related field.
- A current certification satisfying DoD 8570/8140 workforce requirements at IAT Level III, IAM Level III, or IASAE Level III. IAT, IAM, and IASAE are qualification levels, not certifications in themselves — each level is satisfied by an approved certification such as CISSP, CASP+ CE, CISA, CISM, CCISO, GCIH, or CSSLP, depending on the level and category.
Desired Certifications:
- CISSP or CISA
- CRISC
- CMMC CCP or CCA
We take pride in building a workforce with a strong Veterans focus.
Excentium offers a competitive salary and comprehensive benefits package, including medical, dental, life, disability, 401k, and paid time off.
Excentium, Inc. is an equal opportunity employer.
