Risk and Compliance Analyst

Boston Government Services, LLCOak Ridge, TN
$136,849 - $160,999Hybrid

About The Position

Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Risk and Compliance Analyst to support our clients in various locations across the US. BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction. Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability—where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees’ well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection. If you align with BGS’ company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below!

Requirements

  • Bachelor’s degree or equivalent.
  • Experience supporting federal cybersecurity compliance, audit readiness, RMF, POA&M management, FISMA reporting, or risk management.
  • Working knowledge of NIST 800-53 Rev. 5, RMF, FISMA, federal-style reporting, CISA BODs, KEV tracking, and corrective action management.
  • Ability to analyze technical and compliance information and convert it into actionable risk reporting.
  • Strong writing, coordination, and stakeholder management skills.
  • Must be a U.S. citizen.
  • Successful drug screening.
  • Must be eligible to obtain and maintain a security or clearance badge.

Nice To Haves

  • CISA, CISM, Security+, CISSP, CAP/CGRC, CRISC, or equivalent.

Responsibilities

  • Supports client cybersecurity governance, risk management, compliance reporting, audit support, corrective action tracking, waiver management, and cybersecurity risk visibility.
  • Helps sustain a defensible risk posture through structured analysis, documentation, reporting, and stakeholder coordination.
  • Support development and maintenance of risk registers, POA&Ms, risk mitigation waiver records, corrective action plans, compliance dashboards, and security metrics.
  • Assist with internal, external, and third-party cybersecurity audits and assessments.
  • Coordinate artifact collection, stakeholder inputs, interview support, remediation tracking, and response documentation.
  • Support risk analysis for system changes, vulnerabilities, exceptions, third-party software, vendor documentation, SBOM inputs, and acquisition-related cybersecurity concerns.
  • Help prepare cybersecurity risk profiles, FISMA quarterly/annual inputs, information security reports, dashboards, and ad hoc risk analyses.
  • Track waiver justifications, risk levels, compensating controls, approval authorities, expiration dates, and annual reassessments.
  • Identify emerging compliance gaps and recommend practical mitigation actions.

Benefits

  • Health
  • Dental
  • Vision
  • Life Insurance
  • Paid Vacation
  • 401K
  • Long and Short-Term Disability
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service