ArdentMC Logo

ArdentMC

Governance, Risk, and Compliance (GRC) Analyst

Posted 3 Days Ago
Remote
Hiring Remotely in USA
Expert/Leader
Remote
Hiring Remotely in USA
Expert/Leader
Leads GRC and compliance analysis, agency risk documentation, defensible cybersecurity testing strategies, evidence validation, audit-quality assurance, regulatory mapping, technical reporting, and stakeholder briefings across government environments. Supports incident-specific analysis and ensures deliverables meet authorization, evidence, confidentiality, and acceptance requirements.
The summary above was generated by AI

Ardent is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our team.  

This is a remote position with expected travel to Tallahassee, FL. 

Position Description:

Ardent is seeking a Governance, Risk, and Compliance (GRC) Analyst that integrates technical evidence with governance, risk, compliance, and internal-audit support requirements. The role maintains traceability among agency documentation, Rule 60GG-2, NIST CSF, approved procedures, factual findings, remediation actions, and deliverable acceptance criteria while protecting confidential and exempt information across a potentially broad multi-agency environment.

Responsibilities and Duties:

  • Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
  • Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
  • Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
  • Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and the applicable approved criteria.
  • Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement.
  • Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
  • Validate that reports accurately state procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled.
  • Conduct independent QA reviews of technical deliverables not authored solely by the reviewer and document sign-off.
  • Lead technical briefings, workshops, job aids, and knowledge transfer so OCIG and OIG staff can understand and reuse procedures.
  • Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed.

Requirements:

  • Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline.
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
  • 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
  • Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders.
  • Working knowledge of professional auditing or assurance standards and evidence requirements.

Preferred Qualifications:

  • Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains.
  • Government incident-command experience.
  • CISA, CIA, or other audit credential.
  • Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.

Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.

Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.

Similar Jobs

A Minute Ago
Remote or Hybrid
Chatsworth Lake Manor, CA, USA
37K-66K Hourly
Senior level
37K-66K Hourly
Senior level
Fintech • Financial Services
Build and manage relationships with affluent consumer and business customers, acquire and deepen a book of business, and provide integrated guidance across deposits, lending, investments, and banking products. Conduct discovery-based conversations, make referrals, support digital adoption, collaborate with Wealth, Home Lending, and Business Banking partners, coach branch colleagues, and maintain strong risk, documentation, licensing, and compliance standards.
2 Hours Ago
Remote or Hybrid
Virginia, USA
78K-117K Annually
Senior level
78K-117K Annually
Senior level
Digital Media • Information Technology • News + Entertainment
Drives measurement, attribution, data analytics, and business intelligence initiatives. Integrates large-scale data from multiple platforms, performs exploratory analysis and hypothesis testing, develops predictive models, evaluates advertising campaigns, and communicates insights to executives. Ensures data integrity, governance, privacy, and security while collaborating with business leaders and data partners.
Top Skills: AWSDatabricksHadoopLookerPythonSQLSQL ServerTeradata
5 Hours Ago
In-Office or Remote
129K-175K Annually
Mid level
129K-175K Annually
Mid level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Drive full-cycle field sales across Brooklyn by prospecting local businesses, conducting demos, closing deals, building partnerships, and growing Square’s merchant pipeline. Manage territory activity, seller relationships, referrals, onboarding coordination, Salesforce pipeline tracking, forecasting, and quota attainment. The role requires extensive in-person outreach, including 50–60 business visits weekly, and consultative selling across restaurants, retail, and service businesses.
Top Skills: Salesforce

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account