PingWind Logo

PingWind

Risk & Compliance Analyst

Posted 3 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Conducts cybersecurity risk assessments, compliance reviews, audits, continuous monitoring, and remediation tracking for a federal government client. Develops security policies and compliance documentation, supports VA audit activities, coordinates corrective actions, analyzes findings, and provides prioritized risk mitigation recommendations. Collaborates with technical teams, program leaders, government stakeholders, and auditors to strengthen cybersecurity compliance and support risk-based decisions.
The summary above was generated by AI

Location: Remote; travel may be required in support of meetings, training, presentations, or briefings with project stakeholders
Required Clearance: Ability to obtain and maintain the required VA background investigation/suitability determination
Certifications: Certification in one or more of the following: IAT III, IAM III or IASAE III certifications. IAT III/ IAM III / IASAE III certifications may be substituted for a relevant Bachelor’s degree or 4 years of relevant experience
Required Education: Bachelor’s degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information identification Resource Management, or related fields.
Required Experience: Minimum of 7 years of Information Security Experience of which at least 5 years are of risk and compliance experience at a large company or Government agency similar in size/scope to GSA, IRS, DoD or VA. An advanced degree (e.g. Master’s or PhD) in related field may substitute for up to 2 years of the required experience. Expertise handling and reporting compliance issues and coordinating with regulatory bodies.

Description

PingWind is seeking a highly skilled and experienced Risk & Compliance Analyst to join our dynamic team supporting a large Federal Government client. Apply expertise in cybersecurity risk management, compliance, audit, and continuous monitoring to assess organizational risk and ensure alignment with Federal security requirements and policies. The Risk & Compliance Analyst will collaborate with technical teams, program leadership, Government stakeholders, and auditors to strengthen the client's cybersecurity and compliance posture and support effective risk-based decision-making.
 
Responsibilities

• Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
• Support internal and external audits against applicable Federal requirements and organizational policies.
• Perform risk, assessment, mitigation, tracking, and continuous monitoring activities.
• Develop and maintain cybersecurity policies, procedures, and compliance documentation.
• Track and report compliance issues and coordinate corrective actions with technical teams.
• Support VA audit planning, documentation collection, auditor inquiries, and required submissions.
• Analyze findings and develop prioritized remediation recommendations.

Requirements

• Ability to obtain and maintain required VA background investigation/suitability and system access.
• Experience conducting cybersecurity risk assessments, compliance reviews, and audits.
• Experience developing risk mitigation strategies and supporting continuous monitoring.

Preferred Qualifications

• VA/Federal cybersecurity compliance experience.
• RMF, FISMA, NIST, or ATO experience.
• Audit remediation or POA&M experience.

About PingWind
 
PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity, development, IT infrastructure, supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL.
www.PingWind.com
 
Our benefits include:
 
·       Eleven Federal Holidays
·       Paid Time Off accrued each pay period
·       Parental Leave
·       Three medical plan choices with generous employer contribution
·       Dental and Vision Insurance
·       Company paid Short-Term and Long-Term Disability
·       Company paid Life and AD&D Insurance
·       401k with competitive matching and vesting schedule 
·       Continuing education assistance
·       Short Term / Long Term Disability & Life Insurance
·       Medical, Dependent Care and Commuter Flexible Spending Accounts
·       Employee Assistance Program 
·       Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)
·       529 College Savings Plan
·       Legal Insurance 
·       Pet Insurance
 
Veterans are encouraged to apply

Salary Range

 77K - 107K 

The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities, education, certifications, experience, as well as internal equity mapping and alignment with market data, or other applicable laws.

 
PingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law

Similar Jobs

7 Days Ago
In-Office or Remote
Senior level
Senior level
Healthtech
Leads enterprise security governance, risk management, and compliance activities. Conducts security risk assessments, maintains the security risk register, supports HIPAA and PCI compliance, evaluates third-party vendors, develops security metrics, reports risk status to leadership, maintains security policies, and drives remediation strategies.
Top Skills: Cybersecurity Governance FrameworksHipaaIt AuditPci DssSecurity Risk ManagementVendor Risk Management
10 Days Ago
Remote
US
50K-73K Annually
Entry level
50K-73K Annually
Entry level
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
Support day-to-day GRC operations: assess third-party vendors, maintain vendor risk register, track remediation and control evidence, assist with internal control testing and audits (SOC 2, ISO 27001, PCI-DSS), maintain policies, prepare reporting, and contribute to process improvements.
Top Skills: Claude CodeGoogle WorkspaceIso 27001MS OfficeNistPci-DssSoc 2
21 Days Ago
Remote
United States
98K-115K Annually
Senior level
98K-115K Annually
Senior level
Artificial Intelligence • Cloud • Machine Learning • Software • Business Intelligence • Cybersecurity • Big Data Analytics
Performs cybersecurity risk assessments, compliance reviews, audits, and RMF/ATO support for federal systems. Identifies vulnerabilities, control gaps, and compliance deficiencies; develops mitigation strategies, remediation reports, risk analyses, and traceability matrices. Coordinates with government stakeholders, auditors, system owners, engineers, and vendors. Maintains cybersecurity policies, evidence, findings, dashboards, and risk records while monitoring remediation and evolving federal requirements. The role may include occasional onsite visits and support for third-party and supply-chain risk management.
Top Skills: Authority To Operate (Ato)Cloud SecurityCybersecurityDevsecopsFicamFismaInternet Of Things (Iot)Nist Cybersecurity FrameworkNist Sp 800-53Post-Quantum CryptographyRisk Management Framework (Rmf)

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account