Booz Allen Hamilton logo
Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

IT Audit, Controls, and Compliance Lead

Location

Virginia

Posted

19 days ago

Salary

$112.8K - $257K / year

Seniority

Lead

Bachelor Degree

Job Description

IT Audit, Controls, and Compliance Lead

Booz Allen Hamilton

Title: Federal IT Audit, Controls, and Compliance Lead Location: Arlington United States Full time Job Description: The Opportunity: The Department of War and Federal government operate some of the most consequential and heavily scrutinized IT environments in the world-and behind every Authorization to Operate (ATO), every clean SOC 1 opinion, and every successful Federal audit stands a hands-on compliance expert who designs controls that work, tests them with rigor, and proves their quality. That expert is you. This is a high-impact player-coach role for a strategic doer who also knows how to lead. You'll thrive owning the full audit lifecycle end-to-end-not directing it from a distance-while simultaneously building, mentoring, and elevating the delivery quality and impact of compliance professionals who follow your lead. You'll personally execute SOC audits with a sharp focus on IT General Controls (ITGC/GITC) and Business Process Controls (BPCs)-designing, testing, continuously improving and evidencing the operating effectiveness and quality of controls across access management, change management, computer operations, system development, cybersecurity and the business processes that depend on them. You'll align governance programs to FISMA, NIST 800-53, NIST 800-37, RMF, and the NIST Cybersecurity Framework, author and mature System Security Plans, build evidence packages, and serve as the authoritative voice with external auditors, Federal regulators, IG reviewers, and DoW client assessors. You'll set the bar for quality across every deliverable that leaves your team's hands-POA&Ms, control narratives, readiness assessments, and continuous monitoring (ConMon) artifacts-and drive a culture of continuous improvement grounded in proven quality frameworks. You'll move forward where others get stuck, coach team members through complex audits, partner directly with security engineering, legal, privacy, and risk teams to close gaps, and make sure compliance at this organization isn't just a checkbox-it's a competitive advantage and a measurable mark of quality. If you're a strategic operator who genuinely loves doing the work, leading by example, and protecting the quality of Federal mission systems, we're ready for you. Join us. The world can't wait. You Have: - 10+ years of experience in information security, audit, and compliance - 5+ years of experience executing formal Federal audit programs - Experience executing SOC 1 audits focused on IT General Controls (ITGCs) and Business Process Controls (BPCs), including design, testing and evidencing control quality across access management, change management, IT operations, system development, and business processes, such as financial reporting, transaction processing, segregation of duties, or management review - Experience with audits and control assessments aligned to FISMA, NIST 800-53, NIST 800-37 (RMF), NIST CSF, and DoD/Department of War requirements - Experience leading, mentoring, and developing audit and compliance teams, instilling a culture of quality and continuous improvement, and holding the team to Federal standards, and driving audit and compliance work forward independently and through a team, including tracking POA&Ms, findings, remediations, and running continuous control monitoring (ConMon) and quality improvement initiatives, such as CMMI or ISO 9001, conducting internal readiness assessments, and proving compliance to Federal authorizing officials - Experience maintaining and elevating the quality of security policies, control frameworks, System Security Plans (SSPs), and governance documentation - Knowledge of evaluating end-to-end business processes, identifying control points, and assessing both automated and manual controls for effectiveness and quality - Ability to effectively liaison for external auditors, Federal regulators, IG reviewers, and DoW/DoD client assessors, with executive-level communication - Secret clearance - Bachelor's degree Nice If You Have: - Experience at a Big 4 audit firm, such as Deloitte, EY, KPMG, or PwC, with SOC reporting, ITGC, and business process control quality testing rigor - Experience supporting Department of War (DoW), DoD, or Intelligence Community audit and compliance programs, including DoD RMF, eMASS, and Authorization to Operate (ATO) processes - Experience with FedRAMP, CMMC 2.0, and DFARS 252.204-7012 compliance programs, including quality and process maturity frameworks, such as CMMI Levels 3-5, and IT Service Management (ITSM) and Information Technology Infrastructure Library (ITIL) practices that support sustained audit readiness - Experience implementing or optimizing GRC and ITSM-integrated platforms, such as RSA Archer, ServiceNow GRC, including ITSM module integration, custom Audit Control Systems, Xacta, or eMASS to streamline Federal audit workflows, evidence collection, and continuous improvement of control quality - Experience testing business process controls in financial systems, such as ERP, billing, or procurement, or mission-critical workflows, including walkthroughs, control matrices, and risk-and-control matrices (RCMs) - Experience defining career paths, building training plans, or scaling a compliance team within a Federal contracting environment - Knowledge of cloud compliance in Federal environments, such as AWS GovCloud, Microsoft Azure Government, or Google Cloud for Government - Knowledge of AI governance and emerging Federal compliance standards, including NIST AI RMF and OMB AI guidance, such as M-24-10, as they apply to government systems - CPA License or Certified Internal Auditor Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $112,800.00 to $257,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Related Categories

Related Job Pages

More Compliance Jobs

Brown & Brown Insurance logo

Technology Risk and Compliance Analyst

Brown & Brown Insurance

As an Equal Opportunity Employer, we are committed to fostering an inclusive environment comprised of people from all backgrounds, with a variety of experiences and perspectives, guided by our Diversity, Inclusion & Belonging (DIB) motto, “The Power to Be Yourself”.

Compliance20 days ago
Full TimeRemoteTeam 10,001+Since 1939H1B No Sponsor

• Identify, assess, and document technology risks across projects, products, and platforms within the Retail portfolio. • Facilitate the prioritization of technology risks based on business impact, regulatory exposure, and defined risk appetite. • Conduct risk assessments for new initiatives, including M&A integrations and platform implementations. • Partner with project managers and product teams to integrate risk mitigation into delivery plans and milestones. • Ensure risk mitigation strategies align to enterprise risk appetite and portfolio priorities. • Monitor risk exposure and ensure remediation activities are tracked through completion. • Ensure alignment with internal policies and external regulatory requirements (e.g., SOX, SOC controls, data privacy standards). • Support implementation and maintenance of IT governance, risk, and compliance (GRC) frameworks. • Evaluate and ensure technology policies, standards, and procedures are fit for purpose and aligned to regulatory and business requirements. • Maintain compliance documentation, control narratives, and evidence repositories. • Monitor and report adherence to policies, standards, and standard operating procedures across the portfolio. • Support internal and external audit activities, including evidence collection, walkthroughs, and remediation tracking. • Partner with internal and external Audit to support successful audit outcomes, including SOX compliance, evidence validation, and timely remediation of findings. • Assess effectiveness of IT controls and identify gaps across applications, infrastructure, and processes. • Partner with control owners to strengthen control design and execution. • Drive timely closure of audit findings and control deficiencies. • Partner with Vendor Management and enterprise third- and fourth-party risk teams to ensure technology-related vendor risks are identified and addressed. • Incorporate vendor-related risks into portfolio-level risk visibility and reporting. • Support tracking and remediation of vendor-related control gaps impacting Retail Technology delivery. • Prepare and deliver transparent, decision-ready reporting for governance forums, including Steering Committees and OCIO leadership. • Provide insights that enable leadership to evaluate risk exposure alongside investment, delivery progress, and business outcomes. • Highlight trade-offs, emerging risks, and areas requiring leadership attention or decision. • Track key risk indicators (KRIs), control effectiveness, and remediation progress. • Identify opportunities to streamline and improve GRC processes, tooling, and operating model effectiveness. • Contribute to the evolution of OCIO governance, risk, and control frameworks.

Florida
$85K - $105K / year

Compliance Specialist

Renaissance Life & Health Insurance Company of America

Renaissance Life & Health Insurance Company of America provides ancillary benefits solutions, including dental, vision, life, and disability insurance, to individuals and businesse

Compliance20 days ago

Role Description Renaissance Benefits is hiring for an experienced Compliance Specialist to join our growing team! The Compliance Specialist is responsible for supporting the execution, administration, and ongoing improvement of the Company’s Compliance Program. This role helps ensure regulatory requirements are tracked, implemented, documented, and monitored accurately and on time. The position requires strong attention to detail, sound judgment, analytical thinking, and the ability to manage multiple priorities in a fast-paced, highly regulated environment. - Support the day-to-day administration of the Compliance Program, including regulatory tracking, task management, metrics intake, incident tracking, and exam readiness activities. - Help ensure compliance-related activities are completed accurately, documented appropriately, and aligned with internal and regulatory deadlines. - Manage recurring compliance workflows that require strong organization, follow-through, and attention to detail. - Monitor applicable state and federal regulatory updates and assess operational impact across supported product lines. - Track regulatory requirements through intake, assignment, monitoring, and completion. - Review compliance data and performance metrics to identify risks, gaps, and opportunities for improvement. - Maintain compliance documentation, trackers, repositories, and audit files to support accuracy, consistency, and audit readiness. - Coordinate document review and implementation activities to support regulatory and contractual compliance. - Assist in the development, maintenance, and monitoring of internal compliance controls. - Coordinate compliance training schedules, tracking, and reporting activities. - Maintain accurate training records to support audit and reporting needs. - Support preparation for regulatory exams, audits, and inquiries by coordinating documentation and operational readiness activities. - Assist with compliance investigations through accurate documentation and workflow tracking. - Other duties as assigned by manager. Qualifications - Bachelor’s degree in business, compliance, risk management, healthcare administration, or a related field, or an equivalent combination of education, training, and experience. - Three to five years of experience in compliance, regulatory operations, auditing, risk management, or a related function. - Experience within the insurance industry is preferred, including exposure to dental, vision, life, disability, supplemental, or government-regulated products. - Strong organizational, communication, and collaboration skills with the ability to manage multiple priorities and deadlines with accuracy. Requirements - Willingness to learn and adopt new tools, technologies, and process improvements, including automation or AI-enabled solutions. - Knowledge of compliance, regulatory, audit, or risk management processes within a regulated industry environment. - Ability to interpret regulatory requirements, translate them into operational tasks, and monitor progress to completion. - Experience maintaining documentation, trackers, repositories, and records that support audit readiness and reporting accuracy. - Proficiency with Microsoft Office applications, particularly Excel, Word, and Outlook, with the ability to organize, analyze, and communicate information effectively. - Experience working with compliance-related data, metrics, reporting, or workflow tracking tools is preferred. Benefits - Salary Range: $70,000-80,000 Company Description The company will provide equal employment and advancement opportunity within the context of its unique business environment without regard to race, color, religion, gender, gender identity, gender expression, age, national origin, familial status, citizenship, genetic information, disability, sex, sexual orientation, marital status, pregnancy, height, weight, military status, or any other status protected under federal, state, or local law or ordinance.

Indiana
$70K - $80K / year
Job Closed
Bureau Veritas logo

Concrete Inspector

Bureau Veritas

At Bureau Veritas, we are driven by our values of Trusted, Responsible, Ambitious & Humble, and Open & Inclusive. If this resonates with you, we’d love to hear from you.

Compliance20 days ago
Full TimeRemoteTeam 10,001

Role Description The Pre-Stressed Concrete Inspector is responsible for oversight of the fabrication facility's quality assurance on behalf of Bureau Veritas's client. The client's for these assignments are typically state Departments of Transportation or construction contractors. The inspector must have significant knowledge of Precast/Prestressed Concrete and demonstrable experience in a similar position. The skills required for this position include: - Communicating with the Project Manager to determine the specific requirements of a given work order, including the scope of work, deliverables, schedule, and budget for a particular assignment. - Communication with the Project Manager, fabrication shops, contractors, and other third parties to resolve schedule issues. - Ensure that the services provided are performed in accordance with the project requirements and contract with the client. - Generate and process timesheets, billing reports, and inspection reports in an expeditious and thorough manner, complying with all applicable deadlines. - All reports must be submitted typewritten using Microsoft Word/Adobe Acrobat and must be electronically transmitted to the Project Manager. - Communicate information from the fabrication facility regarding upcoming assignments and potential work that Bureau Veritas could perform. - Maintain a positive relationship between Bureau Veritas, the fabrication facility, and the client. - Ability to work remotely from the established Bureau Veritas offices. - Client oriented approach with emphasis on understanding and fulfilling the needs of the client. - Detail oriented with a dedication to the quality control and quality assurance process; ability to understand and read complex design and fabrication plans and specifications. - Excellent communication and documentation skills, with ability to communicate technical issues to the Project Manager, clients, and the fabrication facility. - Expertise in Microsoft Office (Word, Excel) required; knowledge of Adobe Acrobat and Lotus Notes preferred. - Proficient use of modern communication and computer equipment including cell phones, laptop computers and digital cameras. - Ability to multi-task and properly execute multiple simultaneous assignments without sacrificing efficiency or quality of the work. - Team player willing to work with clients, field staff, other Bureau Veritas offices, and the worldwide Bureau Veritas organization. Qualifications - Three years minimum in concrete construction including one year minimum in precast or prestressed construction. - ACI Level I Field Technician Certification (REQUIRED) - PCI Level II certification (REQUIRED) - High school Graduate or GED - Read and interpret blueprints and shop drawings - Prepare reports both in hard copy (written) and on a PC. - High degree of computer literacy with the ability to competently operate a PC and use Microsoft products including MS Word and MS Excel. - Ability to take and transfer digital photographs to Word Documents or MS Excel Report cells. Requirements - Location: Work from home in US with Travel Required to Various Sites (100% Travel) - Compensation: $30-$45 per hour Company Description Bureau Veritas is an Equal Opportunity Employer, and as such we recruit, hire, train, and promote persons in all job classifications without regard to race, color, religion, sex, national origin, disability, age, marital status, citizen status, sexual orientation, gender identity, genetics, status as a protected veteran, or any other non-job-related characteristics. If you are an individual with a disability and you would like us to assist you with searching the Careers Page site for employment opportunities and/or assistance with completing your profile and application, please contact us at 1-888-357-7020 or email us with your request to NorthAmericaTA@bureauveritas.com. We are happy to assist you and encourage you to consider Bureau Veritas for your next great career opportunity! If you would like additional information regarding Bureau Veritas' federal obligations in regards to equal employment opportunity, please click the link below: Federal Obligations in Regards to Equal Employment Opportunity

United States
$30 - $45 / hour
Full TimeRemoteTeam 51-200

Role Description Reporting to the Director of Grants Management, the Grants Compliance Manager (GCM) is responsible for overseeing grant compliance across AFT’s diverse portfolio of grants. The GCM ensures that all grant activities adhere to applicable regulations, funder requirements, and organizational policies; develops and maintains internal systems, tools, and standard operating procedures; and serves as a key resource for staff on grant management and compliance matters. This role requires a high degree of collaboration with the Programs, Project Management, Legal, and Development teams, and the ability to clearly communicate grant regulations and financial concepts to a variety of audiences. Duties & Responsibilities - Interpret and apply grant agreements, terms, and conditions to ensure compliance with funding guidelines, reporting deadlines, and allowable costs across awards issued by federal, state, corporate, foundation, and other institutional funding sources. - Monitor and stay current on U.S. Government (USG) grant management policies, federal regulations (including 2 CFR 200), and funder-specific requirements; update internal guidance and advise staff accordingly. - Develop, maintain, and refine organizational grant award tracking and filing systems, including SharePoint platform management, to ensure records are current, accurate, and complete. - Review new grant agreements and solicitations to identify compliance requirements, risks, and operational considerations. - Oversee subaward compliance, including development and review of subaward agreements for consistency with prime award requirements. - Provide training, guidance, and mentorship to grant team members and project/program managers to build organizational capacity and ensure compliance with applicable requirements. - Develop, update, and implement standard operating procedures (SOPs) for key grant management functions, to include procurement, subawards, consultant contracting, and budget and financial management. - Support the annual organizational work planning and budgeting process as it relates to grant compliance requirements. Qualifications - Demonstrated knowledge of federal grant regulations, including 2 CFR 200 (Uniform Guidance), and experience applying these regulations in a grant management or compliance role. - Experience in grant compliance and/or grants management within the nonprofit sector, government agencies, or a similar environment. - Familiarity with grant agreement structures, subaward management, and fiscal management of federal funds. - Strong analytical, organizational, and problem-solving skills with keen attention to detail. - Excellent verbal and written communication skills, with the ability to translate complex regulatory requirements for non-specialist audiences across all levels of an organization. - Experience developing or managing grants-related systems, trackers, or filing structures. Preferred - Experience with large federal awards, including familiarity with USDA regulations, USDA General Terms and Conditions (GT&C), and NRCS Grant Agreement and Development Budget Expense Tables (GADBET). - Experience with foundation grant management. - Demonstrated commitment to the mission of AFT. Education & Experience - A bachelor’s degree in Public Administration, Business Administration, Finance, or a related field. - A minimum of 7–10 years of relevant experience in grants management or grant compliance, with a strong background in federal grants and/or nonprofit administration. - Certification in grants management (e.g., Certified Grants Management Specialist – CGMS) or federal or commercial contracting is a plus. Working Conditions/Travel - This is a remote-based position. Occasional work in the evenings or on weekends may be required to meet deadlines. - This position does not require travel. Degree of Supervision Received The incumbent will operate under the general supervision of the Director of Grants Management. Degree of Supervision Given The incumbent may be expected to supervise one staff member, the Grants Administration Coordinator (or similar position). Compensation - American Farmland Trust offers excellent vacation, medical, retirement and other benefits. The salary range for this position is from $100,000 to $110,000 based upon experience. - Insurance coverage begins the 1st of the month following the date of hire. - Medical & Prescription Coverage - Dental Coverage - Vision Coverage - Company Paid Life Insurance & Long-Term Disability (LTD) - Voluntary Life Insurance - Flexible Spending Account (FSA) – Healthcare & Dependent Care - Health Savings Account (HSA) - 401k Plan - Sick Leave: Regular full-time employees accrue 13 “sick days” per year. - Vacation Leave: Accrue 15 days during the first year increasing by one day per year to 20 days per year maximum. - Holidays: AFT observes twelve fixed holidays and a week between Christmas and New Years off during the year (all offices closed) plus a choice of up to three (depending on hiring month) floating holidays. Why you should apply - Be a part of a purpose-driven, committed, knowledgeable, high-performing, experienced and fun team. - A diverse and inclusive work environment. - A cause and mission you can be proud of. - Competitive compensation & benefits. - Remote work opportunity. Timeline To be considered applicants must submit a resume, a cover letter explaining what they are a right fit for both AFT and this role. Applications will be reviewed on a rolling basis. Directly Apply Here: Grants Compliance Manager.

United States
$100K - $110K / year
Job Closed