Risk and Compliance Analyst
Boston Government Services, LLC (BGS) - Knoxville Metropolitan Area
Hiring: Risk and Compliance Analyst Company: Boston Government Services, LLC (BGS) Location: Knoxville Metropolitan Area Job Posted Time: 2026-09-11 13:24:44 Employment Type: Full-time / Remote Target Skills & Keywords : Program Management, Risk Management, SBOM, Stakeholder Management About the job Required Skills: •The Risk and Compliance Analyst supports client cybersecurity governance, risk management, compliance reporting, audit support, corrective action tracking, waiver management, and cybersecurity risk visibility. This role helps sustain a defensible risk posture through structured analysis, documentation, reporting, and stakeholder coordination. •Support development and maintenance of risk registers, POA&Ms, risk mitigation waiver records, corrective action plans, compliance dashboards, and security metrics. •Assist with internal, external, and third-party cybersecurity audits and assessments. •Coordinate artifact collection, stakeholder inputs, interview support, remediation tracking, and response documentation. •Support risk analysis for system changes, vulnerabilities, exceptions, third-party software, vendor documentation, SBOM inputs, and acquisition-related cybersecurity concerns. •Help prepare cybersecurity risk profiles, FISMA quarterly/annual inputs, information security reports, dashboards, and ad hoc risk analyses. •Track waiver justifications, risk levels, compensating controls, approval authorities, expiration dates, and annual reassessments. •Identify emerging compliance gaps and recommend practical mitigation actions. Qualifications: •Bachelor’s degree or equivalent. •Solid functional working knowledge of NIST 800-53 Rev. 5, RMF, FISMA, federal-style reporting, CISA BODs, KEV tracking, and corrective action management. •Demonstrated capacity to analyze technical and compliance information and convert it into actionable risk reporting. •Strong writing, coordination, and stakeholder management skills. •Must be a U.S. citizen. •Must be eligible to obtain and maintain a security or clearance badge. •CISA, CISM, Security+, CISSP, CAP/CGRC, CRISC, or equivalent. •Schedule is full-time, Monday – Friday 40-hour week, 4/10’s, or 9/80’s and may require on call or overnight shifts depending on contract needs. •This position may be fully onsite or hybrid/remote depending on the needs of the specific contract. Compensation: •$136,849 - $160,999 / year •Competitive benefits and rewards package Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!