Lead Governance & Compliance Analyst

Thomson ReutersWashington, DC
$136,000 - $253,000Hybrid

About The Position

Are you ready to help secure the trusted technology that powers mission-critical decisions across government and highly regulated industries? At Thomson Reuters, our technology supports customers who depend on secure, reliable, and compliant platforms to deliver essential outcomes. We are seeking a Lead Governance & Compliance Analyst to join our Operations and Technology organization, supporting our federal government portfolio, including FedRAMP-authorized and in-process platforms for products such as Legal Research and Risk & Fraud. This role is central to sustaining and evolving the FedRAMP compliance posture of Thomson Reuters' federal-facing products. As a senior technical and governance leader, you will help ensure our cloud environments remain continuously compliant, secure, audit-ready, and aligned with federal requirements. You will partner closely with engineering, product, operations, security, federal agencies, the FedRAMP PMO, and third-party assessment organizations to support authorization activities, strengthen security practices, and help maintain customer trust. Please note: This position requires access to U.S. Federal Government systems and data under a federal government contract. In accordance with contractual requirements, applicants must be U.S. citizens. This requirement applies only to this role and is mandated by the applicable government contract; it is not a general company policy. Thomson Reuters is an equal opportunity employer.

Requirements

  • 5+ years of experience in cloud security architecture, security engineering, governance, risk, compliance, or related roles supporting federal or highly regulated workloads.
  • Demonstrated expertise with FedRAMP, NIST Risk Management Framework, and NIST SP 800-53 Rev. 5 security controls.
  • Experience supporting FedRAMP Continuous Monitoring, including vulnerability management, POA&M tracking, evidence collection, reporting, and control monitoring.
  • Experience conducting or supporting risk assessments, vulnerability scans, incident analysis, and remediation activities within a FedRAMP or regulated environment.
  • Strong communication skills with the ability to engage effectively with federal agencies, auditors, third-party assessors, technical teams, and senior stakeholders.
  • Ability to analyze security and compliance data, identify trends or risks, and produce clear reports for leadership, agencies, and audit partners.
  • Bachelor's degree in cybersecurity, information security, computer science, or a related discipline, or equivalent professional experience.

Nice To Haves

  • Experience with cloud environments such as AWS, Azure, or Google Cloud Platform.
  • Experience supporting the FedRAMP Authorization to Operate process.
  • Familiarity with state-level compliance programs such as StateRAMP, GovRAMP, or TX-RAMP.
  • Relevant security or compliance certifications such as CISSP, CISM, CISA, CCSP, Security+, or similar credentials.

Responsibilities

  • Serve as a primary liaison with federal agencies, the FedRAMP PMO, third-party assessment organizations, consultants, and internal stakeholders to support ongoing authorization and compliance activities.
  • Lead FedRAMP Continuous Monitoring activities, including POA&M management, vulnerability reporting, monthly deliverables, and recurring agency reporting requirements.
  • Maintain and update the System Security Plan, risk documentation, assessment artifacts, and other required FedRAMP documentation to ensure ongoing audit readiness.
  • Manage vulnerability, risk, and incident response processes in alignment with FedRAMP, NIST RMF, and NIST SP 800-53 Rev. 5 requirements.
  • Support annual security assessments, including planning, scope definition, SAP preparation, security testing coordination, SAR development, POA&M updates, and project closure.
  • Partner with engineering, product, operations, and security teams to drive risk mitigation, compliance improvements, and secure delivery of federal-facing cloud solutions.
  • Educate and guide internal stakeholders on FedRAMP security requirements, continuous monitoring expectations, significant change processes, and compliance best practices.

Benefits

  • Hybrid Work Model
  • Flexibility & Work-Life Balance
  • Work from anywhere for up to 8 weeks per year
  • Career Development and Growth
  • Industry Competitive Benefits
  • Flexible vacation
  • Two company-wide Mental Health Days off
  • Access to the Headspace app
  • Retirement savings
  • Tuition reimbursement
  • Employee incentive programs
  • Resources for mental, physical, and financial wellbeing
  • Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more.
  • Two paid volunteer days off annually
  • Opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
  • Market competitive health, dental, vision, disability, and life insurance programs
  • Competitive 401k plan with company match
  • Competitive vacation, sick and safe paid time off
  • Paid holidays (including two company mental health days off)
  • Parental leave
  • Sabbatical leave
  • Optional hospital, accident and sickness insurance paid 100% by the employee
  • Optional life and AD&D insurance paid 100% by the employee
  • Flexible Spending and Health Savings Accounts
  • Fitness reimbursement
  • Access to Employee Assistance Program
  • Group Legal Identity Theft Protection benefit paid 100% by employee
  • Access to 529 Plan
  • Commuter benefits
  • Adoption & Surrogacy Assistance
  • Access to Employee Stock Purchase Plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service