Compliance & Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteTeam 5,001-10,000

Location

United States

Posted

5 days ago

Salary

Not specified

NIST SP 800 171CMMC 2.0System Security PlansPlan OF Action AND MilestonesIncident ResponseDisaster RecoveryFIPS 140 2FIPS 140 3Network ArchitectureLog AnalysisSOC2ISO 27001HIPAAGDPRTechnical WritingCCPCISASecurity+Access ControlMFABoundary Protection

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

  • Architects and authors System Security Plans (SSPs), the "source of truth" for the client's security posture, detailing exactly how each NIST 800-171 control is implemented.
  • Develops and manages the Plan of Action and Milestones (POAM), tracking every deficiency and guiding the client’s IT team through remediation.
  • Drafts all formal security policies, ensuring they are not just "templates" but functional, defensible documents that reflect the client’s real-world operations.
  • Designs and facilitates annual Incident Response (IR) and Disaster Recovery (DR) tabletop drills.
  • Leads the Evidence Collection phase, verifying that the client’s logs and configurations meet the rigorous sufficiency standards of a C3PAO auditor.
  • Demonstrates and actively promotes an understanding and commitment to the mission of Logicalis through performing behaviors consistent with the organization's values.
  • Maintains a working knowledge of applicable Federal, State, and Local laws and regulations as well as policies and procedures of Logicalis in order to ensure adherence in a manner that reflects honest, ethical and professional behaviors.
  • Supports and conducts self in a manner consistent with customer service expectations.

Qualifications

  • Bachelor’s degree in a related field.
  • Compliance Enclaves: Advising on how to segment CUI to limit audit scope and cost.
  • FIPS 140-2/3 Validation: Verifying that encryption modules (VPNs, Wi-Fi, Storage) meet federal standards.
  • Network Architecture: Interpreting network diagrams and identifying gaps in boundary protection and data flow. Previous Network Engineer or Administrator experience is valued.
  • Log Logic: Knowing exactly what a "passing" audit log looks like for MFA, access control, and system monitoring.
  • Framework Expert: Mastery of CMMC 2.0 (Level 2) and NIST SP 800-171.
  • Technical Writing: Superior ability to write clear, audit-proof documentation (SSPs, SOPs, and Policies).
  • Knowledge of SOC2, ISO 27001, HIPAA, or GDPR.
  • Certifications: CCP (CMMC Certified Professional), CISA, Security +

Requirements

  • Ability to work with C-Suite Executives and across client technical teams throughout the consulting process.
  • Portfolio Management: Proven ability to manage ~10 concurrent clients/projects without sacrificing quality or missing milestones.
  • Ability to manage through high level of ambiguity and multiple requests from variety of sources.
  • Ability to work on multiple projects simultaneously and translate business data into digestible information that improves corporate processes.
  • Outstanding technical/business communication skills.

Physical Demands

The physical demands described here are representative of those that should be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • While performing the duties of this Job, the employee is constantly required to sit, talk, see, hear, and use hands and arms.
  • The employee is frequently required to stand; move about, climb steps or balance and stoop, kneel, crouch, or crawl.
  • The employee may occasionally lift and/or move up to 10 pounds.

Salary Compensation Range

$90,321 - $121,934

Job Requirements

  • Bachelor’s degree in a related field.
  • Compliance Enclaves: Advising on how to segment CUI to limit audit scope and cost.
  • FIPS 140-2/3 Validation: Verifying that encryption modules (VPNs, Wi-Fi, Storage) meet federal standards.
  • Network Architecture: Interpreting network diagrams and identifying gaps in boundary protection and data flow. Previous Network Engineer or Administrator experience is valued.
  • Log Logic: Knowing exactly what a "passing" audit log looks like for MFA, access control, and system monitoring.
  • Framework Expert: Mastery of CMMC 2.0 (Level 2) and NIST SP 800-171.
  • Technical Writing: Superior ability to write clear, audit-proof documentation (SSPs, SOPs, and Policies).
  • Knowledge of SOC2, ISO 27001, HIPAA, or GDPR.
  • Certifications: CCP (CMMC Certified Professional), CISA, Security +
  • Ability to work with C-Suite Executives and across client technical teams throughout the consulting process.
  • Portfolio Management: Proven ability to manage ~10 concurrent clients/projects without sacrificing quality or missing milestones.
  • Ability to manage through high level of ambiguity and multiple requests from variety of sources.
  • Ability to work on multiple projects simultaneously and translate business data into digestible information that improves corporate processes.
  • Outstanding technical/business communication skills.
  • Physical Demands
  • The physical demands described here are representative of those that should be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
  • While performing the duties of this Job, the employee is constantly required to sit, talk, see, hear, and use hands and arms.
  • The employee is frequently required to stand; move about, climb steps or balance and stoop, kneel, crouch, or crawl.
  • The employee may occasionally lift and/or move up to 10 pounds.
  • Salary Compensation Range
  • $90,321 - $121,934

Related Job Pages

More Security Analyst Jobs

SAP Security Specialist

CACI International

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Security Analyst5 days ago
Full TimeRemoteTeam 10,001

The specialist will translate functional specifications into SAP role designs, manage technical roles, user authorizations, and handle Segregation of Duties conflict remediation projects. They will also provide subject matter expertise and technical direction to clients while ensuring system reliability through day-to-day sustainment support.

SAP SecuritySAP GRCSegregation of DutiesSODSAP AuthorizationBW4HANAS4HANAR3 ECC
United States
$90.3K - $189K / year

Security Analyst II

Garner Health

A better way to get your employees to high-quality doctors.

Security Analyst5 days ago
Full TimeRemoteTeam 51-200H1B No Sponsor

Security Analyst II maintaining data integrity for Garner's healthcare technology

New York
$117K - $130K / year
Full TimeRemoteTeam 312Since 2010

This role involves conducting tactical threat monitoring and detection activities using internal tools to assess and communicate risks to customers through tactical-level reports. Analysts will produce high-quality tactical assessments, manage customer alerting profiles, and synthesize data to identify information credibility and relevance.

Threat IntelligenceData AnalysisPattern RecognitionCybersecurityRisk AssessmentTactical Monitoring
United States
Security Analyst5 days ago
Full TimeRemoteTeam 51-200Since 2021H1B No Sponsor

AGE Solutions is looking for a Security Control Assessor, Mid to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD in...

STIGRMFNIST 800-37NIST 800-53CNSSI 1253eMASSSTIG ViewerNessusACASSCAPHBSSWindowsUNIXCloudDatabasesPOA&M
United States