Remote Governance Risk And Compliance Jobs
Remote Governance Risk And Compliance jobs are in strong demand across the U.S., with remote-first firms and distributed teams actively hiring for compliance, risk management, and regulatory oversight roles in finance, healthcare, technology, and professional services. Employers hiring remotely right now include Vestis, Onebrief, and Owner. See the openings below and apply to the ones that match your experience.
Find JobsOverview
Showing 5 of 11+ Remote Governance Risk And Compliance jobs











Company Overview
Position Summary
Responsibilities:
- Review, update, and maintain Comtech cybersecurity policies, standards, and procedures.
- Ensure documentation aligns with DFARS, CMMC, NIST SP 800171, NIST CSF, and internal compliance objectives.
- Assist in drafting new policies and procedures to address regulatory gaps and audit findings.
- Collect and maintain evidence for NIST SP 800171 controls across all families.
- Perform internal control testing; validate control operation through screenshots, configurations, and interviews with system owners.
- Support readiness activities for external CMMC assessments and DIBCAC audits.
- Document compliance gaps and work with stakeholders to track remediation plans.
- Support enterprise risk assessments and risk tracking activities.
- Document identified risks, evaluate severity, and develop mitigation recommendations.
- Conduct reviews of privileged access, separation of duties, and user lifecycle management.
- Assist in documenting CUI data flow, system boundaries, network diagrams, and CUI storage/transmission locations.
- Validate enforcement of CUI access controls, session lock/termination parameters, and security notices.
- Support ongoing reviews of systems handling CUI to maintain administrative and technical compliance.
- Perform and document role based access reviews, privileged account audits, and separation of duties analysis.
- Coordinate with business unit system owners (e.g., M2K, ERP, AD administrators) to compile lists of authorized users, devices, and system accounts.
- Validate configurations related to failed logon thresholds, session timeouts, security banners, and role permissions.
- Work with internal audit teams and external partners (e.g., RISC Point) to prepare audit packages and evidence submissions.
- Maintain organized repositories of assessment artifacts, reports, and compliance documents.
- Support quarterly and annual control reviews.
- Assist in maintaining and updating IR, DR, and BCP documentation.
- Collect evidence and support after action reviews, helping to improve response plans and procedures.
- Resolve compliance related tickets requiring documentation, evidence updates, or access verification.
- Ensure timely response and remediation for aging compliance tasks.
Skills:
- Prior experience supporting compliance within a DoD contractor environment.
- Prior experience supporting NIST 800-171 requirements
- Familiarity with CUI identification and marking requirements.
- Experience with system administration basics (e.g., Active Directory roles/permissions review).
- Certifications: Security+, CGRC, CAP, CMMC-RP, CCP, CISA, or similar governance/compliance credentials.
Requirements:
- Strong understanding of NIST SP 800171 (R2/R3), DFARS, CMMC Level 2, and federal cybersecurity compliance.
- Experience performing access reviews, control evidence collection, and audit preparation.
- Ability to read and interpret technical configurations, logs, and administrative settings.
- Excellent writing skills for policy review, control documentation, and evidence narratives.
- Strong analytical capabilities with attention to detail and accuracy.
- Ability to work cross functionally with IT, security, engineering, and external assessors.
- Proficiency with Microsoft 365, SharePoint, and compliance documentation management.
Education and Experience:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Business IT, or related field.
- 2–5 years of experience in GRC, IT audit, cybersecurity compliance, or risk management.
About:
This position requires compliance with Comtech’s Drug-Free Workplace Program. Candidates must successfully complete a pre-employment drug screening as a condition of hire. Employees may be subject to random, reasonable suspicion, and post-incident testing. Illegal drug use — including marijuana, regardless of state law — is disqualifying under federal adjudicative guidelines and DoD DFARS requirements.
The pay range reflects the expected base salary for this position. Final compensation will be based on role, level, skills, experience, and geographic location.
Comtech Telecommunications Corp. is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability protected veteran status or other characteristics protected by law.
See All 11 Remote Governance Risk And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Governance Risk And Compliance Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Healthcare & Medical Services
- Insurance
What Employers Look For
The qualifications that appear most often in remote governance risk and compliance jobs.
- Bachelor's degree in finance, accounting, law, business, or a related field
- Certifications such as CISA, CRISC, CIA, CGRC, or CISM
- Experience conducting internal audits, risk assessments, or compliance reviews
- Knowledge of regulatory frameworks including SOX, COSO, NIST, or ISO 31000
- Proficiency with GRC platforms such as Archer, ServiceNow GRC, or MetricStream
- Strong written communication skills for policy documentation and audit reporting
Tips for Your Remote Governance Risk And Compliance Job Search
Apply early to remote roles that fit
Migrate Mate lists remote governance risk and compliance openings from across the U.S. in one place, so you can find roles that match your background and apply directly without sorting through unrelated listings.
Show your GRC tools fluency upfront
Remote employers want to know you can operate independently inside platforms like Archer, ServiceNow GRC, Vanta, or OneTrust from day one. Name the specific tools you've used and what you accomplished with them in your resume and cover letter.
Prove you can communicate compliance findings in writing
Remote GRC roles live or die on written communication. Prepare writing samples, such as risk memos, policy drafts, or audit summaries, that demonstrate you can convey complex regulatory findings clearly to stakeholders who aren't in the same room.
Target distributed teams with existing compliance programs
Companies that already have a remote compliance function are far more likely to onboard a remote GRC professional successfully. Look for job postings that mention remote-first culture, async workflows, or existing GRC tooling, because those teams know how to integrate you without requiring in-person oversight.
Remote Governance Risk And Compliance Jobs: Frequently Asked Questions
How do I get a remote governance risk and compliance job?
Target companies that already run distributed compliance teams, such as fintech platforms, SaaS businesses, and digital-first financial institutions, because they've built the infrastructure for remote GRC work. Remote employers screen for strong written communication, the ability to interpret and document regulatory requirements independently, and familiarity with GRC platforms like Archer, ServiceNow, or Vanta. Demonstrating that you can manage audits, track controls, and escalate findings without in-person check-ins gives you a clear edge.
Which companies hire remote governance risk and compliances?
Remote governance risk and compliance roles are posted by Vestis, Onebrief, and Owner and others right now, based on current remote listings on Migrate Mate as of August 2026. Remote-first fintechs, cloud-native healthcare organizations, insurance carriers with distributed operations, and large technology firms with global regulatory obligations are among the most consistent hirers of remote governance risk and compliance professionals.
Can you get a remote governance risk and compliance job with no experience?
Yes, but remote entry-level GRC roles are competitive because employers expect you to work independently from day one without on-site mentorship. Your best path in is through smaller compliance-light companies, startups building their first GRC function, or junior risk analyst roles at consulting firms with remote teams. Showing self-directed learning through GRC certifications like CompTIA Security+, CISA, or CRISC, along with any hands-on policy writing or audit support, signals you can handle the autonomy remote work demands.
Do you need a degree for remote governance risk and compliance jobs?
Not always. Many remote employers weight demonstrated GRC skills, relevant certifications, and a history of managing compliance frameworks over a specific degree. Credentials like CISA, CISM, CRISC, or a Certified Compliance and Ethics Professional designation carry real weight, especially at remote-first companies that evaluate candidates on output rather than credentials alone. A portfolio of policy documents, risk assessments, or audit reports you've produced strengthens your case significantly.
Which industries hire the most remote governance risk and compliances?
Most remote governance risk and compliance openings sit in Technology & Software, Healthcare & Medical Services, and Insurance, per current remote listings on Migrate Mate as of August 2026. These sectors hire governance risk and compliance professionals remotely because their compliance obligations are documentation-heavy and technology-driven, making the work well suited to distributed teams operating across multiple jurisdictions.
See All 11 Remote Governance Risk And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs