Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Ardent

Governance, Risk, and Compliance Analyst

Ardent

. Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans .

Posted 9/17/2026full-timeRemote • Florida • United StatesSeniorLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity, risk assessment, and audit processes, with a strong focus on developing and validating test procedures and compliance with regulatory standards. Proficient in leading technical briefings and conducting independent assessments in government or regulated environments.

Highest-signal resume keywords
Cybersecurity ExperienceRisk AssessmentAudit SupportCISSP CertificationIncident Response

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability ManagementIntrusion AnalysisTechnical AssessmentTest Procedure DesignControl Performance Evaluation
Soft Skills
Communication to Senior StakeholdersLeadership in Technical Briefings
Tools & Technologies
Active DirectoryCloud PlatformsAPIsWeb ApplicationsSIEM/EDR
Certifications & Qualifications
CISSPCISAPMPCEH
Industry Keywords
NIST CSFGovernment ComplianceAudit StandardsEvidence RequirementsMITRE ATT&CK

Tech Stack

Tools & technologies
CloudCyber SecurityPMP

About the role

Key responsibilities & impact
  • Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans
  • Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities
  • Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures covering objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths
  • Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and applicable approved criteria
  • Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement
  • Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility
  • Validate reports for accurate statements of procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled
  • Conduct independent QA reviews of technical deliverables and document sign-off
  • Lead technical briefings, workshops, job aids, and knowledge transfer for OCIG and OIG staff
  • Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed

Requirements

What you’ll need
  • Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications
  • 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support
  • 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments
  • Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders
  • Working knowledge of professional auditing or assurance standards and evidence requirements
  • Willingness to undergo the government-issued background investigation process
  • Preferred: Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains
  • Preferred: Government incident-command experience
  • Preferred: CISA, CIA, or other audit credential
  • Preferred: Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories

Benefits

Comp & perks
  • Equal opportunity employment and nondiscrimination protections
  • Opportunity to work remotely
  • Expected travel to Tallahassee, Florida
  • Government-issued background investigation process for candidates in consideration