Full-time

GRC Analyst

Posted on 24 September 26 by Noah Stratman

  • Mesa, AZ or Richmond, VA
  • $ - $
Logo

Powered by Tracker

Job Description

RESPONSIBILITIES
Compliance program operation

  • Track all 110 NIST SP 800-171 requirements across the 14 control families; keep the SPRS score current and defensible.
  • Maintain the SSP, POA&M, and supporting documents: policies, procedures, data flow diagrams, asset inventories.
  • Run internal 800-171A and gap assessments; propose remediation owners and dates; track findings to closure.
  • Verify controls technically: run 800-171A objectives as tests against the systems (MFA enforcement, session lock, audit retention, encryption), not as document review.
  • Keep an audit-ready evidence repository mapped to controls that an assessor can follow without coaching; build repeatable collection with scripts, saved queries, and scheduled exports.
  • Prepare the annual Affirming Official affirmation package; support DFARS 7012, DIBCAC, and CMMC Level 2 assessments.

Risk management

  • Maintain the security risk register; translate technical findings into likelihood, impact, and options leadership can act on.
  • Fold CISA and DoD threat advisories into the risk picture.
  • Flag boundary changes (new CUI contract, new system, enclave change); draft risk acceptances for sign-off.

Legal and contract liaison

  • Review contracts and flowdowns for CUI, ITAR, NNPI, and cybersecurity obligations; define the controls and evidence needed.
  • Act as point of contact for Legal and Contracts: answer can we truthfully attest to this? with control status and evidence.
  • Coordinate supplier security reviews where CUI or export-controlled data flows down; track flowdown compliance.
  • Escalate any gap that creates legal or contractual exposure to the Cybersecurity Manager and Legal, in writing.
  • Support voluntary disclosure and incident reporting with timeline reconstruction, evidence collection, and documentation.

Policy, training, monitoring, and reporting

  • Write and maintain policies, SOPs, and control narratives in SRC house style; update on DoD, DFARS, or NIST changes and record why.
  • Deliver security awareness and role-based training; track completion across the workforce.
  • Triage SIEM alerts for the CUI enclave, tune noisy rules, compare deployed configurations to CIS or STIG baselines, and open remediation items.
  • Administer the vulnerability scanner, SIEM rule content, and the GRC and evidence tooling.
  • Support incident response evidence and timelines, including DFARS 7012 reporting to DoD when CUI is involved.
  • Report control status, open risks, and remediation progress on a set cadence; produce readiness summaries on request.

QUALIFICATIONS
Required

  • 3 to 5 years in cybersecurity, with a background in systems administration, security operations, or security engineering before or alongside compliance work.
  • Working knowledge of NIST SP 800-171 and DFARS 252.204-7012.
  • Built or maintained an SSP and POA&M; maps controls to evidence.
  • Can pull the configuration, log, or report that proves a control is implemented in Entra ID, Intune, Windows, and firewalls, and explain what it shows.
  • Basic PowerShell or Python for exporting evidence (MFA status, patch compliance, account inventories) rather than assembling screenshots by hand.
  • Working knowledge of Windows and Microsoft 365 administration, Active Directory and Entra ID, and network fundamentals: VLANs, firewall rules, remote access.
  • Strong policy writing; explains controls to non-technical owners.
  • Bachelor's in cybersecurity or IT, or equivalent experience.
  • U.S. Person status under ITAR (22 CFR 120.62), given access to export-controlled technical data. Preferred
  • Prior help desk, systems administration, or SOC time.
  • Azure Government or GCC High administration; Palo Alto or equivalent firewall exposure; STIG or CIS benchmark work.
  • Exposure to CMMC Level 2 readiness, SPRS scoring, or a prior C3PAO or DIBCAC assessment.
  • Experience with Legal or Contracts on clause interpretation, flowdown, or disclosure obligations.
  • Experience with a manufacturing environment and operational technology (OT).
  • Familiarity with ITAR and NNPI handling requirements.
  • Hands-on time with a GRC or compliance tracking tool, and with Jira or Jira Service Management.
  • Security+, CySA+, SC-200, AZ-500 or SC-300, CISSP.

Job Information

Rate / Salary

$ - $

Sector

Not Specified

Category

Not Specified

Skills / Experience

Not Specified

Benefits

Not Specified

Our Reference

JOB-19463

Job Location