Skip to main content
Back to jobs

Lead Governance & Compliance Analyst

External
Thomson Reuters logoThomson Reuters · Washington, DC
ContractHybrid6d ago
AWSAzureCloud SecurityComplianceDocumentationIncident Response
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

In this opportunity as Lead Governance & Compliance Analyst , you will: Serve as a primary liaison with federal agencies, the FedRAMP PMO, third-party assessment organizations, consultants, and internal stakeholders to support ongoing authorization and compliance activities. Lead FedRAMP Continuous Monitoring activities, including POA&M management, vulnerability reporting, monthly deliverables, and recurring agency reporting requirements. Maintain and update the System Security Plan, risk documentation, assessment artifacts, and other required FedRAMP documentation to ensure ongoing audit readiness. Manage vulnerability, risk, and incident response processes in alignment with FedRAMP, NIST RMF, and NIST SP 800-53 Rev. 5 requirements. Support annual security assessments, including planning, scope definition, SAP preparation, security testing coordination, SAR development, POA&M updates, and project closure. Partner with engineering, product, operations, and security teams to drive risk mitigation, compliance improvements, and secure delivery of federal-facing cloud solutions. Educate and guide internal stakeholders on FedRAMP security requirements, continuous monitoring expectations, significant change processes, and compliance best practices. About You You're a fit for the role of Lead Governance & Compliance Analyst if your background includes: 5+ years of experience in cloud security architecture, security engineering, governance, risk, compliance, or related roles supporting federal or highly regulated workloads. Demonstrated expertise with FedRAMP, NIST Risk Management Framework, and NIST SP 800-53 Rev. 5 security controls. Experience supporting FedRAMP Continuous Monitoring, including vulnerability management, POA&M tracking, evidence collection, reporting, and control monitoring. Experience conducting or supporting risk assessments, vulnerability scans, incident analysis, and remediation activities within a FedRAMP or regulated environment. Strong communication skills with the ability to engage effectively with federal agencies, auditors, third-party assessors, technical teams, and senior stakeholders. Ability to analyze security and compliance data, identify trends or risks, and produce clear reports for leadership, agencies, and audit partners. Bachelor's degree in cybersecurity, information security, computer science, or a related discipline, or equivalent professional experience.

Requirements

  • Experience with cloud environments such as AWS, Azure, or Google Cloud Platform.
  • Experience supporting the FedRAMP Authorization to Operate process.
  • Familiarity with state-level compliance programs such as StateRAMP, GovRAMP, or TX-RAMP.
  • Relevant security or compliance certifications such as CISSP, CISM, CISA, CCSP, Security+, or similar credentials.
  • #LI-LP2
  • What's in it For You?
  • Hybrid Work Model: We've adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.

Benefits

Flexible schedule

Additional Information

Are you ready to help secure the trusted technology that powers mission-critical decisions across government and highly regulated industries? At Thomson Reuters, our technology supports customers who depend on secure, reliable, and compliant platforms to deliver essential outcomes. We are seeking a Lead Governance & Compliance Analyst to join our Operations and Technology organization, supporting our federal government portfolio , including FedRAMP-authorized and in-process platforms for products such as Legal Research and Risk & Fraud . This role is central to sustaining and evolving the FedRAMP compliance posture of Thomson Reuters' federal-facing products. As a senior technical and governance leader, you will help ensure our cloud environments remain continuously compliant, secure, audit-ready, and aligned with federal requirements. You will partner closely with engineering, product, operations, security, federal agencies, the FedRAMP PMO, and third-party assessment organizations to support authorization activities, strengthen security practices, and help maintain customer trust. Please note: This position requires access to U.S. Federal Government systems and data under a federal government contract. In accordance with contractual requirements, applicants must be U.S. citizens . This requirement applies only to this role and is mandated by the applicable government contract; it is not a general company policy. Thomson Reuters is an equal opportunity employer.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at Thomson Reuters? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect