• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board Risk and Compliance Analyst

$98,135–115,000/yr 3d ago

Risk and Compliance Analyst

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

9th Way Insignia

US

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

The Risk and Compliance Analyst will perform comprehensive cybersecurity risk assessments and develop risk-mitigation strategies aligned with federal requirements. They will also coordinate internal and external audits, maintain compliance documentation, and support the Authority to Operate (ATO) process.

Job Description

9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions.  Our specialties include cybersecurity, cloud modernization, software development, data analytics, enterprise architecture, enterprise IT, analytics, process automation, and artificial intelligence.  Learn more about 9th Way Insignia at https://9thwayinsignia.com/.

Application password: Niner

Team (Project) Introduction

We are recruiting for a range of cybersecurity opportunities supporting federal customers, focused on strengthening enterprise security architecture, systems engineering, and the secure implementation of technologies across the environment.

The work involves applying established cybersecurity standards, guidelines, and frameworks to help translate organizational and business requirements into secure, scalable technical solutions. Team members may contribute to security architecture and engineering efforts, implementation guidance, technical analysis, and the development of repeatable approaches that support the consistent deployment and operation of secure technologies across complex enterprise environments.

Systems security engineering is an important component of this work, with an emphasis on incorporating security and stakeholder protection requirements throughout the system development life cycle, from concept and design through development, production, sustainment, and decommissioning. The team will apply established systems engineering and cybersecurity principles to help protect systems, applications, data, and supporting technologies.

Ultimately, this work supports the broader mission to strengthen its cybersecurity posture, reduce organizational risk, and protect critical systems and information from evolving cyber threats, including external adversaries and insider threats.

9th Way Insignia is looking for an Engineer, 3, Risk and Compliance Analyst to join this team.

Professional Level Information:
An Engineer, 3 typically plans and directs research or development work on complex projects, along with engaging various parties in design and development. Costs and recommendations of new components may also involve part of the job scope. Performs multiple engineering-related tasks in various assignments within the project and firm. An Engineer, 3 oversees the design, development, implementation, and analysis of technical products and systems.  An Engineer, 3 has broad knowledge of engineering procedures and assists in the resolution of complex problems.  An Engineer, 3 has strong technical skills and background, a knack for learning new technologies, and a blend of good problem-solving and innovation needed to resolve a wide variety of technical production challenges.

Responsibilities:  

  • Perform and support comprehensive cybersecurity risk assessments for information systems, applications, platforms, technologies, processes, and enterprise initiatives.
  • Identify, analyze, evaluate, document, and monitor cybersecurity risks, vulnerabilities, control gaps, compliance deficiencies, and residual risks.
  • Develop and implement risk-management processes and programs, including risk identification, assessment, prioritization, mitigation, monitoring, and reporting.
  • Develop risk-mitigation strategies and corrective-action recommendations that are technically feasible, actionable, and aligned with Government risk tolerance and mission requirements.
  • Monitor identified risks throughout the system and program lifecycle and track the status and effectiveness of approved mitigation actions.
  • Support continuous monitoring activities to provide ongoing visibility into cybersecurity risk, compliance posture, control implementation, and outstanding remediation requirements.
  • Perform compliance assessments against applicable Federal cybersecurity requirements, VA policies, organizational standards, and approved security baselines.
  • Assess systems and cybersecurity activities for compliance with applicable NIST standards, OMB mandates, VA cybersecurity requirements, and other Federal security frameworks identified within the program.
  • Support risk-management activities aligned with NIST SP 800-53 and the NIST Cybersecurity Framework.
  • Evaluate compliance findings and provide clear recommendations supporting risk-based decisions regarding system accreditation and authorization.
  • Conduct and support internal and external cybersecurity audits, assessments, inspections, and reviews.
  • Coordinate with auditors, assessors, Government representatives, cybersecurity SMEs, system owners, engineers, and other stakeholders throughout audit and assessment activities.
  • Collect, review, organize, and validate supporting evidence requested during audits and assessments, including policies, procedures, system documentation, security reports, configuration information, logs, diagrams, and other technical artifacts.
  • Evaluate audit findings and develop remediation strategies, corrective actions, responsible-party assignments, and resolution timelines.
  • Track audit and compliance findings through resolution and verify that corrective actions adequately address identified deficiencies.
  • Support annual FISMA/FICAM audit activities and assist in developing actionable remediation recommendations for identified findings.
  • Develop and maintain Remediation Reports documenting audit findings, recommended corrective actions, responsible parties, mitigation strategies, and planned resolution timelines.
  • Develop and maintain Security Risk Analysis Reports that identify, evaluate, monitor, and communicate system-security risks.
  • Support development of Specialized Security Posture Reports evaluating the risks associated with new and emerging technologies such as Artificial Intelligence, Cloud Security, Post-Quantum Cryptography, medical devices, and Internet-of-Things technologies.
  • Assess changes in technologies, systems, regulatory requirements, and Government mandates to determine potential risk and compliance impacts.
  • Perform security architecture and compliance gap analyses to identify differences between existing implementations and required VA or Federal security requirements.
  • Document compliance gaps and recommend mitigation strategies consistent with Government security policies and enterprise risk tolerance.
  • Review security configuration and baseline-assessment findings to determine compliance status, deviations, risk implications, and required remediation actions.
  • Support requirements traceability between security controls, architectural requirements, system implementation, evidence, and Authority to Operate (ATO) activities.
  • Develop and maintain Requirements Traceability Matrices (RTMs) supporting accreditation, authorization, and compliance activities.
  • Support Federal Assessment and Authorization (A&A), Risk Management Framework (RMF), and ATO processes as applicable to assigned systems and initiatives.
  • Assist system owners and technical teams with interpreting cybersecurity requirements and determining appropriate evidence needed to demonstrate compliance.
  • Develop, review, maintain, and support enforcement of cybersecurity policies, procedures, standards, guidelines, and governance documentation.
  • Evaluate existing policies and procedures to identify gaps, inconsistencies, or changes needed to maintain alignment with evolving regulatory and organizational requirements.
  • Monitor relevant regulatory, policy, and security-requirement changes and assess their potential impact on VA systems and cybersecurity programs.
  • Identify and report compliance issues, material deviations, and areas of increased risk to appropriate program and Government stakeholders.
  • Prepare risk and compliance information suitable for technical teams, program managers, Government leadership, auditors, and other non-technical stakeholders.
  • Develop reports, briefings, dashboards, risk summaries, compliance status updates, and other materials communicating cybersecurity posture and remediation progress.
  • Maintain accurate and auditable records of risk decisions, findings, mitigation plans, compliance evidence, corrective actions, and closure status.
  • Coordinate with appropriate Government and regulatory stakeholders regarding compliance issues, assessments, findings, and remediation actions.
  • Support Government audit and inspection activities by ensuring requested information and documentation are provided accurately and in a timely manner.
  • Monitor adherence to approved security policies and requirements and escalate significant compliance issues when necessary.
  • Support third-party and supplier risk-management activities where assigned, including evaluation of vendor cybersecurity risk and compliance posture.
  • Assist in developing risk-assessment criteria, scoring methodologies, and risk thresholds for evaluating third-party or supplier cybersecurity risk.
  • Support cybersecurity supply-chain risk-management activities involving vendor assessments, third-party risk, and regulatory compliance.
  • Collaborate with cybersecurity architects, security engineers, DevSecOps personnel, program managers, system owners, technical SMEs, and other stakeholders to integrate risk and compliance requirements throughout the technology lifecycle.
  • Participate in technical reviews, governance forums, risk meetings, audit meetings, engineering working groups, and other activities requiring cybersecurity risk or compliance expertise.
  • Promote a risk-based approach to cybersecurity decision-making, balancing security requirements, mission needs, operational constraints, and remediation priorities
  • May require occasional on-site visits

Requirements:

  • Minimum of 7 years of Information Security Experience of which at least 5 years are of risk and compliance experience at a large company or Government agency similar in size/scope to GSA, IRS, DoD or VA. 
  • An advanced degree (e.g. Master’s or PhD) in related field may substitute for up to 2 years of the required experience. 
  • Expertise in risk management, compliance, audit, or related roles within an organization. 
  • Expertise conducting internal and external audits to assess compliance with regulatory requirements and organizational policies. 
  • Expertise developing and implementing risk management programs, including risk assessments, risk mitigation strategies, and continuous monitoring.
  • Expertise policy development, documentation, and enforcement.
  • Expertise handling and reporting compliance issues and coordinating with regulatory bodies. 
  • Up to two travel times per year

Preferred/Desired:

  • Bachelor’s degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or related fields. 
  • CASP+ (SecurityX), CCISO, CISA, CISM, CISSP, CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH, GSLC, CCNP Security

Salary Range$98,135.18—$115,000 USD

9th Way Insignia’s range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Clearance/Background Investigation
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

Benefits
Eligible employees will have access to our comprehensive benefits package which includes Medical, Dental, Vision, Voluntary Life Insurance, 401(k), Basic Life A&D, STD, LTD, PTO, Telehealth, paid holidays, FSA, HSA. Additional resources include our Employee Assistance Program (EAP) and Traveling Assistance.

Legal
We’re an equal employment opportunity employer that empowers our people to fearlessly drive change – no matter their race, color, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, age, marital status, sexual orientation, gender identity, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, or local law.

Equal Employment Opportunity Notice
Applicants have the right to be free from unlawful workplace discrimination. Please review the EEOC’s Know Your Rights: Workplace Discrimination is Illegal notice. Accessible formats and translations are also available from the EEOC.

Application Accommodations
If you require a reasonable accommodation to complete this application or participate in the hiring process, please contact [email protected]. Requests will be considered individually.

About the company

9th Way Insignia

9th Way Insignia is a service-disabled veteran-owned small business (SDVOSB) that provides results-oriented technical solutions to the federal government. Led by experienced industry leaders, we bring software development, enterprise architecture, cybersecurity, enterprise IT, and data analytics capabilities to our customer base within the Departments of Veterans Affairs, Health and Human Services, Transportation, Commerce, and State.

Founded

2018

Company size

51-200 employees

Industry

IT Services and IT Consulting

Org type

Privately Held

Headquarters

Ashburn, Virginia

Apply Now

About the company

9th Way Insignia

9th Way Insignia is a service-disabled veteran-owned small business (SDVOSB) that provides results-oriented technical solutions to the federal government. Led by experienced industry leaders, we bring software development, enterprise architecture, cybersecurity, enterprise IT, and data analytics capabilities to our customer base within the Departments of Veterans Affairs, Health and Human Services, Transportation, Commerce, and State.

Founded

2018

Company size

51-200 employees

Industry

IT Services and IT Consulting

Org type

Privately Held

Headquarters

Ashburn, Virginia

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.