Governance, Risk, and Compliance Analyst
Vant4ge
Job description
Job Overview
Vant4ge is seeking a Governance, Risk, and Compliance (GRC) Analyst to help maintain and advance the security and compliance programs supporting our corrections and justice SaaS environment.
As a member of the Technical Operations team, you will manage day-to-day compliance activities, coordinate directly with external auditors and assessors, maintain controls and supporting evidence, and drive assigned compliance projects from planning through completion. You will help translate complex requirements into practical actions, identify gaps, and work with technical and business teams to track remediation through verified closure.
The role supports existing compliance commitments and new initiatives involving GovRAMP Moderate Authorized requirements, SOC 2 Type 2 examinations, the CJIS Security Policy, NIST SP 800-53, and applicable regulatory and customer obligations. Priorities will vary based on program scope and business needs.
You will work closely with cybersecurity, cloud engineering, IT operations, and other business stakeholders. This role offers meaningful ownership of compliance work, with priorities, risk decisions, and escalation support provided by the Technical Operations Manager.
Key Responsibilities
Compliance Program Maintenance
-
Coordinate recurring compliance activities, including control reviews, evidence collection, policy updates, and continuous monitoring deliverables.
-
Maintain a compliance calendar covering assessment milestones, reporting obligations, review cycles, and remediation deadlines.
-
Keep control descriptions, procedures, ownership records, and supporting documentation accurate as systems and business processes change.
-
Track changes to applicable frameworks and customer requirements, assess their impact, and coordinate necessary updates with stakeholders.
Audit and Assessment Coordination
-
Serve as a day-to-day coordination point for external auditors and assessors, including third-party assessment organizations (3PAOs), as applicable.
-
Organize audit preparation, manage evidence requests, schedule stakeholder interviews, and track questions and findings through resolution.
-
Review evidence for relevance, completeness, accuracy, and coverage of the required assessment period before submission.
-
Help control owners prepare for assessments and clearly explain how their processes meet applicable requirements.
Compliance Projects and Readiness
-
Support new compliance initiatives and drive assigned work-streams from initial gap assessment through readiness and assessment support.
-
Translate requirements into actionable tasks with defined owners, deliverables, dependencies, and deadlines.
-
Maintain project trackers, communicate progress, and escalate blockers or competing priorities.
-
Help prepare and maintain assessment documentation, including system security plans, control narratives, and plans of action and milestones (POA&Ms), where applicable.
Control Validation and Remediation
-
Perform documented control reviews and readiness checks to identify missing evidence, process weaknesses, and compliance gaps.
-
Work with cybersecurity, cloud engineering, and IT operations to clarify findings and develop practical corrective actions.
-
Track remediation commitments, obtain supporting evidence, and verify completion against agreed requirements.
-
Document unresolved issues and exceptions, and escalate matters requiring prioritization or risk acceptance to the appropriate decision-makers.
Documentation and Collaboration
-
Maintain organized, access-controlled evidence repositories and reliable records of compliance activities.
-
Map shared controls across frameworks to reduce duplicate work and improve consistency.
-
Support customer security questionnaires and compliance requests using accurate, approved information.
-
Provide clear reporting on audit readiness, open findings, overdue activities, and upcoming obligations.
-
Improve templates, workflows, and GRC tooling to make compliance activities more consistent and efficient.
Required Qualifications
-
Typically 2โ4 years of relevant experience in GRC, information security compliance, IT audit, technology risk, or a related field. Candidates with equivalent practical experience are encouraged to apply.
-
Hands-on experience supporting at least one security compliance framework or assessment program, such as SOC 2, NIST SP 800-53, GovRAMP, or CJIS-related requirements.
-
Experience collecting and reviewing audit evidence, maintaining compliance documentation, and tracking findings or corrective actions.
-
Ability to interpret control requirements and work with technical teams to identify appropriate evidence and implementation practices.
-
Working knowledge of core security concepts, including access management, vulnerability management, logging and monitoring, change management, incident response, and business continuity.
-
Strong writing skills, including the ability to produce clear policies, procedures, control narratives, and status updates.
-
Strong organizational skills and the ability to manage recurring obligations alongside project deadlines.
-
Ability to communicate professionally with auditors, technical teams, and business stakeholders, and to handle sensitive information with discretion.
Preferred Qualifications
-
Experience with GovRAMP or FedRAMP Moderate readiness, assessments, authorization support, or continuous monitoring.
-
Familiarity with NIST SP 800-53 control baselines, system security plans, POA&Ms, and assessment documentation.
-
Experience supporting SOC 2 Type 2 examinations and evidence collection across an audit period.
-
Familiarity with the CJIS Security Policy and agency-specific contractual or security requirements.
-
Experience in SaaS, cloud services, government technology, corrections, criminal justice, or another regulated environment.
-
Familiarity with cloud shared-responsibility models and the distinction between inherited and organization-managed controls.
-
Experience using GRC platforms, ticketing systems, document repositories, or evidence collection tools.
-
Relevant education, training, or certifications such as Security+, CGRC, CISA, or comparable credentials. Certifications are valued but are not required.
Core Competencies
-
Ownership and follow-through: Keeps commitments visible, follows up consistently, and closes the loop on outstanding work.
-
Attention to detail: Recognizes incomplete evidence, inconsistent documentation, and gaps between written procedures and actual practices.
-
Practical judgment: Considers risk, operational constraints, and business priorities when recommending next steps.
-
Clear communication: Makes requirements understandable and provides concise, actionable updates.
-
Collaborative problem-solving: Builds productive relationships and helps teams resolve issues without relying on formal authority.
-
Integrity: Represents compliance status accurately and raises concerns promptly.
-
Continuous improvement: Looks for ways to simplify recurring work while maintaining reliable documentation and evidence.
What Success Looks Like
During the first three months, you will learn the environment, understand program scope and control ownership, become familiar with existing evidence and open findings, and take responsibility for assigned recurring activities.
Within six months, you will independently coordinate assigned audit requests and compliance work-streams, maintain reliable documentation and tracking, and give stakeholders clear visibility into deadlines, gaps, and remediation progress.
Over time, your work will help Vant4ge maintain consistent audit readiness, complete compliance projects predictably, and demonstrate that documented controls are supported by current evidence and operational practices.
Pay: $85,000.00 - $105,000.00 per year
Benefits:
-
401(k)
-
401(k) matching
-
Dental insurance
-
Employee assistance program
-
Employee discount
-
Flexible spending account
-
Health insurance
-
Health savings account
-
Life insurance
-
Paid time off
-
Parental leave
-
Professional development assistance
-
Vision insurance
Work Location: Remote