Live opening · Posted 4 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Risk and Compliance Analyst
Location: Remote (preference to local Washington, DC area)
Clearance: Public Trust
Employment Type: Full-time
Position Summary
Revolutional is seeking Security Configuration and Compliance Engineers to support secure configuration, security control assessment, risk management, and continuous compliance activities across a large Department of Veterans Affairs enterprise environment.
Candidates will help translate federal cybersecurity requirements into actionable technical baselines, assess systems against those requirements, identify configuration and control gaps, and work with engineering teams to remediate findings. We are particularly interested in candidates who view compliance as an engineering problem that can be automated and continuously measured rather than a documentation-only activity.
Key Responsibilities
Develop, maintain, and assess enterprise security configuration baselines.
Evaluate operating systems, databases, cloud platforms, IoT/medical devices, and other technologies against approved security standards.
Perform security control, configuration, risk, and compliance assessments.
Identify configuration drift and develop actionable remediation recommendations.
Map technical requirements and configurations to NIST SP 800-53 and applicable federal/VA controls.
Support requirements traceability from cybersecurity controls through implementation and ATO.
Support FISMA and other audit/remediation activities.
Develop risk analyses, findings, remediation plans, and technical assessment reports.
Identify opportunities to automate configuration assessment and compliance validation.
Analyze security posture trends rather than relying solely on point-in-time assessments.
Required Experience
3+ years of experience in cybersecurity, security compliance, configuration management, vulnerability management, security engineering, or related work.
Working knowledge of NIST cybersecurity controls, RMF, security baselines, vulnerability management, or configuration compliance.
Experience assessing security controls, configurations, vulnerabilities, or compliance requirements and documenting findings and remediation recommendations.
Ability to work with technical teams to understand and resolve security findings.
Education
Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field preferred.
Relevant cybersecurity, engineering, military, or federal experience may be considered in lieu of a degree.
Preferred Experience
Federal cybersecurity experience involving NIST SP 800-53, FISMA, RMF, ATO, or continuous monitoring.
Experience with STIGs, CIS Benchmarks, SCAP, vulnerability scanners, or configuration-assessment technologies.
Experience developing or maintaining secure configuration baselines.
Experience automating compliance or configuration assessments.
Experience with POA&M remediation and security-control traceability.
Preferred Certifications
Security+, CySA+, CAP/CGRC, CISSP, CISA, CASP+/SecurityX, or similar.
Vendor or platform certifications relevant to security configuration or vulnerability management.
Work Authorization/Clearance: Must be authorized to work in the United States and able to pass the background investigation to obtain a Federal Government Public Trust clearance.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.