Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Thomson Reuters

Lead Governance and Compliance Analyst

Thomson Reuters

Lead Governance & Compliance Analyst managing security and compliance for federal government technology solutions. Partnering with various stakeholders to maintain FedRAMP compliance and educate on security requirements.

Posted 7/22/2026full-timeMcLean • District of Columbia, Virginia • 🇺🇸 United StatesSenior💰 $136,000 - $253,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in FedRAMP compliance, risk management, and security architecture, with a strong focus on continuous monitoring and vulnerability management. Capable of effectively communicating security requirements and compliance best practices to diverse stakeholders.

Highest-signal resume keywords
FedRAMP ComplianceNIST Risk Management FrameworkVulnerability ManagementRisk AssessmentSecurity Engineering

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cloud Security ArchitectureSecurity EngineeringGovernanceRisk ManagementComplianceVulnerability ReportingPOA&M ManagementSecurity Testing CoordinationIncident ResponseAudit Readiness
Soft Skills
Strong Communication SkillsStakeholder EngagementAnalytical Skills
Industry Keywords
FedRAMPNIST SP 800-53 Rev. 5Continuous MonitoringRegulated EnvironmentSecurity Assessments

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Serve as a primary liaison with federal agencies, the FedRAMP PMO, third-party assessment organizations, consultants, and internal stakeholders to support ongoing authorization and compliance activities.
  • Lead FedRAMP Continuous Monitoring activities, including POA&M management, vulnerability reporting, monthly deliverables, and recurring agency reporting requirements.
  • Maintain and update the System Security Plan, risk documentation, assessment artifacts, and other required FedRAMP documentation to ensure ongoing audit readiness.
  • Manage vulnerability, risk, and incident response processes in alignment with FedRAMP, NIST RMF, and NIST SP 800-53 Rev. 5 requirements.
  • Support annual security assessments, including planning, scope definition, SAP preparation, security testing coordination, SAR development, POA&M updates, and project closure.
  • Partner with engineering, product, operations, and security teams to drive risk mitigation, compliance improvements, and secure delivery of federal-facing cloud solutions.
  • Educate and guide internal stakeholders on FedRAMP security requirements, continuous monitoring expectations, significant change processes, and compliance best practices.

Requirements

What you’ll need
  • 5+ years of experience in cloud security architecture, security engineering, governance, risk, compliance, or related roles supporting federal or highly regulated workloads.
  • Demonstrated expertise with FedRAMP, NIST Risk Management Framework, and NIST SP 800-53 Rev. 5 security controls.
  • Experience supporting FedRAMP Continuous Monitoring, including vulnerability management, POA&M tracking, evidence collection, reporting, and control monitoring.
  • Experience conducting or supporting risk assessments, vulnerability scans, incident analysis, and remediation activities within a FedRAMP or regulated environment.
  • Strong communication skills with the ability to engage effectively with federal agencies, auditors, third-party assessors, technical teams, and senior stakeholders.
  • Ability to analyze security and compliance data, identify trends or risks, and produce clear reports for leadership, agencies, and audit partners.
  • Bachelor's degree in cybersecurity, information security, computer science, or a related discipline, or equivalent professional experience.

Benefits

Comp & perks
  • Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role).
  • Flex My Way: Policies designed to help manage personal and professional responsibilities.
  • Career Development and Growth: Fostering a culture of continuous learning and skill development.
  • Industry Competitive Benefits: Comprehensive benefits plans including flexible vacation, mental health days, retirement savings, and tuition reimbursement.
  • Culture: Globally recognized for inclusion, belonging, and work-life balance.
  • Social Impact: Two paid volunteer days off annually and opportunities to get involved with social initiatives.