Source Job

US

  • Maintain traceability from Federal Zero Trust guidance and VA objectives to assessment criteria, architecture patterns, and implementation priorities.
  • Support preparation and documentation for Architecture Review Boards, technical reviews, and executive governance forums.
  • Coordinate documentation needed to transition implementation outcomes into sustainable governance and RMF processes.

NIST SP 800-207 Analytical Writing Stakeholder Coordination

20 jobs similar to Governance Analyst

Jobs ranked by similarity.

US

  • Support design, configuration, integration, and validation of Zero Trust security capabilities.
  • Perform technical reviews of system changes and identify security control, interoperability, and implementation impacts.
  • Develop and validate test evidence, technical configuration records, and implementation artifacts.

True Zero Technologies is a veteran-owned small business that enables organizations through people and technology, focusing on quality outcomes. With a people-first culture, it has been recognized as a Best Place to Work in 2023 and 2025, and made the Inc. 5000 list of fastest-growing companies in 2022, 2023, and 2025.

US

  • Own and manage the end-to-end RMF lifecycle, including system categorization, control selection, and continuous monitoring.
  • Assess current-state RMF processes and design standardized target-state workflows aligned with NIST and federal requirements.
  • Serve as the primary functional subject matter expert for the new RMF solution, leading requirements gathering, testing, and training.

True Zero Technologies is a veteran-owned small business that enables people and technology to deliver top-tier cybersecurity services to customers. The company has been recognized as a Best Places to Work honoree and has appeared on the Inc. 5000 list of fastest-growing companies in America.

US

  • Support enterprise cybersecurity governance, compliance, and risk management programs.
  • Conduct security control assessments, audit readiness, and policy development.
  • Coordinate with technical teams and executive leadership to drive cybersecurity modernization.

ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.

US 3w PTO

  • Lead enterprise Zero Trust architecture patterns and use cases.
  • Provide technical advisory to architecture review boards.
  • Ensure alignment with Federal cybersecurity guidance.

True Zero Technologies is a veteran-owned small business that helps organizations achieve their outcomes by enabling people and technology. They have been named a Best Place to Work and are on the Inc. 5000 list, reflecting their people-first culture and growth.

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.

US

  • Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
  • Oversee preparation and execution of external compliance audits, including facilitating security assessments.
  • Support mapping of compliance requirements to security control implementation using agile development processes.

Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.

India

  • Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
  • Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
  • Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.

The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.

US 3w PTO

  • Coordinate execution across Zero Trust maturity assessments, enterprise architecture activities, and system implementation engagements.
  • Maintain integrated delivery schedules, track dependencies, and support resequencing when delays affect delivery.
  • Lead recurring contractor delivery reviews and prepare status, risk, and action reports for Government stakeholders.

True Zero Technologies is a veteran-owned small business that focuses on enabling people and technology to achieve quality outcomes. With a people-first culture, they have been recognized as a Best Places to Work honoree and have made the Inc. 5000 list of fastest-growing companies.

US

  • Support stakeholder readiness and adoption as Zero Trust capabilities are introduced across prioritized VA systems.
  • Assess stakeholder, process, and operational impacts, and develop change readiness and transition activities.
  • Coordinate with system owners to document transition needs and capture adoption lessons learned for future plans.

True Zero Technologies is a veteran-owned small business that focuses on enabling people and technology to deliver quality outcomes. With a people-first culture, it has been recognized as a Best Places to Work honoree in 2023 and 2025, and earned spots on the Inc. 5000 list of fastest-growing companies in 2022, 2023, and 2025.

$117,500–$166,250/yr
US

  • Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
  • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
  • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.

Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

US

  • Execute NIST SP 800-53 control mappings and implement security baselines.
  • Develop and maintain SSPs, POA&Ms, and authorization documentation.
  • Support continuous monitoring and gap assessments for ATO and FedRAMP.

This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.

$105,000–$155,000/yr
US

  • Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
  • Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
  • Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.

The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.

US

  • Design and implement cybersecurity architectures, controls, and technologies for secure government systems.
  • Manage Authority to Operate (ATO) activities, including security documentation, compliance tracking, and continuous monitoring.
  • Apply NIST SP 800 security controls and support Risk Management Framework (RMF) implementation.

The partner organization provides advanced cybersecurity solutions for critical government technology environments. They operate in a mission-driven, collaborative culture with a focus on protecting federal systems.

United States 3w PTO

  • Design and maintain automated workflows for Risk Management Framework and compliance operations.
  • Build integrations between GRC platforms, security tools, and reporting solutions.
  • Develop scripts, APIs, and dashboards to improve cybersecurity visibility and efficiency.

This is a partner company role managed by Jobgether, focusing on cybersecurity governance through automation. The company uses AI-powered matching to connect candidates with roles and emphasizes data privacy and fair hiring processes.

US Unlimited PTO

  • Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
  • Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
  • Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.

OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.

US

  • Develop executive briefings, stakeholder updates, and concise summaries of maturity and implementation progress.
  • Translate technical findings and risks into clear language for varied stakeholder audiences.
  • Coordinate inputs from technical leads and validate communications against approved source material.

True Zero Technologies, a veteran-owned small business, enables people and technology to improve organizational outcomes. It has been recognized as a Best Place to Work and an Inc. 5000 fastest-growing company, with a people-first culture and commitment to excellence.

$70,000–$77,000/yr
US

  • Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
  • Develop and execute security awareness programs including training and phishing simulations.
  • Support governance and control management by maintaining policies and control libraries.

Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.