Careers

Join our team of high performers seeking to change the status quo.

 
 
 
Job Listings
Share with friends or Subscribe!

Current job opportunities are posted here as they become available.

 
 
 

 

 
 
 
 
 
 
 

Risk and Compliance Analyst

Location:
Job ID: 176
Clearance Type: Public Trust - T4
Employee Type : Regular Full Time
Citizenship: US Citizen Only

Triumph Enterprises is building the team for a Department of Veterans Affairs Office of Information and Technology / Office of Information Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply chain reporting spine of the program.

Program: VA Cybersecurity Architecture and Engineering Services (COSE)
Location: Washington, DC (Remote) | Full-Time, Exempt | Contingent upon contract award

This role is measured against numbers, not activity. You will run a weekly risk analysis rhythm, stand up and operate a full Cyber Supply Chain Risk Management program, and report against specific data quality thresholds the program has committed to meeting.

RESPONSIBILITIES

- Produce the Security Risk Analysis Report every Friday, 52 per option year.
- Build and operate the annual Cyber Supply Chain Risk Management (C-SCRM) program, including the strategy and implementation plan, vendor risk assessment framework and scoring rubric, and quarterly briefing package.
- Own SBOM validation procedures and quarterly SBOM compliance reporting.
- Maintain the critical supplier inventory and risk prioritization, and implement banned vendor automation.
- Report FISMA and CISA compliance quarterly, and report performance metrics against committed data quality thresholds: at least 97 percent asset coverage, at least 98 percent data accuracy and completeness on a 30-day rolling average, and 97 percent tagging accuracy.
- Produce specialized security posture reports, remediation reports following audit activity, and requirements traceability matrices.
- Support cyber engineering modernization with risk analysis and continuous monitoring.

REQUIRED QUALIFICATIONS

- Minimum 7 years of information security experience, of which at least 5 years are risk and compliance experience at a large company or Government agency similar in size and scope to VA, DoD, GSA, or IRS.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, Business Administration, Business Management, or a related field. An advanced degree in a related field may substitute for up to 2 years of experience, to a floor of 6 years.
- Expertise in risk management, compliance, audit, or related roles within an organization.
- Expertise conducting internal and external audits to assess compliance with regulatory requirements and organizational policies.
- Expertise developing and implementing risk management programs, including risk assessments, risk mitigation strategies, and continuous monitoring.
- Expertise in policy development, documentation, and enforcement.
- Expertise handling and reporting compliance issues and coordinating with regulatory bodies.
- Demonstrated ability to sustain a weekly reporting cadence in a federal environment.

CERTIFICATION (REQUIRED)

One or more of the following: Information Assurance Technician (IAT) III, Information Assurance Management (IAM) III, or Information Assurance System Architect and Engineer (IASAE) III. Commonly satisfied by CISSP, CISM, or CASP+. Certification is verified before an offer is extended.

SUITABILITY

This position requires a Tier 4 / High Risk Public Trust background investigation. A Tier 4 investigation is adjudicated for suitability and fitness and is not a security clearance. Candidates must be U.S. citizens and able to obtain and maintain the investigation, VA systems access, and PIV credentialing. No work may begin until an interim determination is received.

PREFERRED

- Continuous Diagnostics and Mitigation (CDM) program experience.
- Cyber supply chain risk management under EO 14028 or NSM-10.
- Familiarity with CISA binding operational directives.
- NIST Risk Management Framework and FISMA reporting at a federal agency.
- Prior VA program experience, particularly within OIT or OIS.

ADDITIONAL INFORMATION

Travel is expected to be 0-10%. This position is contingent upon contract award.

Triumph Enterprises, Inc. is an SBA-certified Service-Disabled Veteran-Owned Small Business and an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by law.

 

 
 
 
 
 
 
 

 

 
 
 
 
 
 
 

Applicant Tracking System Powered by ClearCompany HRM Applicant Tracking System