Risk and Compliance Analyst

Description
Risk and Compliance Analyst
Department of Veterans Affairs Office of Information Security COSE Support
Position: Full-Time / Remote from Contractor Facility
Primary Work Location: Contractor facility within the United States; occasional coordinated support at VA Central Office, 811 Vermont Street NW, Washington, D.C.
JOIN OUR TEAM!
Caladwich is seeking a highly motivated, detail-oriented Risk and Compliance Analyst to support the Department of Veterans Affairs Office of Information Security Cybersecurity Operations and Security Engineering (COSE) program. The selected professional will support enterprise cybersecurity risk, compliance, audit, and continuous-monitoring activities for VA. This role evaluates control effectiveness, documents and communicates risk, and tracks remediation against Federal and VA requirements.
This position offers the opportunity to contribute directly to a consistent, evidence-based view of cybersecurity risk and regulatory compliance across VA technology services. The analyst helps leaders prioritize corrective actions while ensuring findings, exceptions, and decisions remain traceable and audit-ready.
WHO WE ARE:
Caladwich is a U.S.-based Service-Disabled Veteran-Owned Small Business (SDVOSB) and SBA 8(a) certified company providing professional services and mission support solutions to federal agencies worldwide. Our capabilities include Acquisition Support, Program Management, Logistics Support Services, Process Improvement, Asset Management, and Operational Support Services for DoD, DHS, VA, and GSA customers.
As a Veteran-owned company, our mission remains steadfast: Integrity. Solutions. Results.
Core Responsibilities
· Conduct enterprise and system-level cybersecurity risk assessments, control gap analyses, compliance reviews, and audit-support activities.
· Develop and implement risk management processes, risk registers, mitigation strategies, treatment plans, and continuous-monitoring practices.
· Evaluate compliance with NIST, FISMA, FedRAMP, CIS Controls, HIPAA, VA policies, approved architectures, and other applicable requirements.
· Conduct or support internal and external audits and document findings, evidence, root causes, corrective actions, residual risk, and closure status.
· Develop, review, and maintain cybersecurity policies, standards, procedures, control documentation, and enforcement mechanisms.
· Identify and assess risks introduced by emerging technologies, modernization initiatives, cloud services, AI, and changes to enterprise systems.
· Analyze security metrics, vulnerabilities, exceptions, assessment results, and threat information to identify trends and priorities.
· Prepare risk and compliance reports and brief technical and non-technical stakeholders on exposure, options, and recommended actions.
Operational Support
· Coordinate with VA stakeholders, technical teams, system owners, and other contractors to resolve issues and keep work aligned with VA priorities.
· Develop, maintain, and submit accurate technical documentation, status information, and contract deliverables within required timeframes.
· Apply VA security, privacy, accessibility, records-management, and configuration-management requirements to all work products.
· Support risk, issue, dependency, schedule, and quality management activities, including corrective actions and continuous improvement.
· Protect VA information and systems, use approved collaboration and remote-access methods, and promptly report security or privacy concerns.
· Participate in meetings, reviews, briefings, and occasional travel as directed and approved under the task order.
· Coordinate compliance issues, evidence requests, and remediation activities with system owners, auditors, assessors, and regulatory stakeholders.
· Track findings and corrective actions through validation and closure and maintain complete, accurate, auditable records.
Requirements
Required Qualifications
· Minimum seven years of Information Security experience, including at least five years of risk and compliance experience at a large company or Government agency similar in size and scope to GSA, IRS, DoD, or VA.
· Expertise in risk management, compliance, audit, internal and external assessments, risk mitigation, continuous monitoring, policy development, documentation, enforcement, and reporting of compliance issues.
· Experience coordinating with regulatory bodies and organizational stakeholders to assess and resolve compliance matters.
· Bachelor's degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or a related field.
· Certification in one or more of the following: IAT III, IAM III, or IASAE III.
· PWS substitution: an advanced degree in a related field may substitute for up to two years of required experience. IAT III, IAM III, or IASAE III certification may substitute for a relevant Bachelor's degree or four years of relevant experience.
Other Requirements
· Must be able to read, write, speak, and understand the English language.
· Must successfully complete and maintain the VA personnel vetting and background investigation requirements applicable to assigned work; PWS Tasks 5.1 through 5.9 are designated Tier 4 / High Risk.
· Must complete required fingerprinting, personnel security forms, security and privacy training, and Rules of Behavior acknowledgments within Government-established timelines.
· Must qualify for and properly safeguard any required VA Personal Identity Verification (PIV) credential and Government-furnished equipment.
· Must be available and responsive during core hours of 8:00 a.m. to 5:00 p.m. Eastern Time on normal Federal Government workdays.
· Must be able to work from a Contractor-provided facility and travel occasionally to VA Central Office in Washington, D.C., or other approved locations when coordinated in advance.
· Remote access to VA systems must occur only through VA-approved methods and from locations permitted by VA policy.
You'll be redirected to
the company's application page