Posted 3 weeks ago
Secret
Unspecified
Unspecified
(On-Site/Office)
About the Job
SecureStrux is searching for a dynamic Compliance Analyst - CMMC Certified Assessor (CCA) with experience providing Cybersecurity Maturity Model Certification (CMMC) consulting services, DIBCAC Assessments, and/or CMMC Assessments. As a Compliance Analyst, you will be responsible for compliance and risk across diverse client projects for Defense Industrial Base (DIB) Partners and Defense Agencies. TIER III/Secret Clearance required.
Job Details
The Work You'll Do
What You'll Bring
Preferred
Salary Range: $90,000+
Our Approach
At SecureStrux, we are committed to core values that guide the way we work with one another and our clients. As a team member, you will Create Team Synergy, Drive Continuous Innovation, Deliver with Integrity, and have the Freedom to Own it. Our thriving company culture supports our employees as they seek to grow with us!
What We Offer
Between our virtual environment where you can evaluate recent technologies and enhance your skills, and a generous annual professional development stipend, you will join a team that enjoys working on leading-edge technologies for world-class clients. We offer a robust total compensation package that includes comprehensive health benefits to support you and your family, flexible time off, continuing education allowance, a donation allowance for charitable causes, and a matched 401k.
Employment Types: Full-time
Work Arrangements: Hybrid
SecureStrux is searching for a dynamic Compliance Analyst - CMMC Certified Assessor (CCA) with experience providing Cybersecurity Maturity Model Certification (CMMC) consulting services, DIBCAC Assessments, and/or CMMC Assessments. As a Compliance Analyst, you will be responsible for compliance and risk across diverse client projects for Defense Industrial Base (DIB) Partners and Defense Agencies. TIER III/Secret Clearance required.
Job Details
- Full Time, Exempt, Salaried
- Remote home office with up to 20% travel to client sites
The Work You'll Do
- Possess a working knowledge of IT security and various frameworks (i.e., CMMC, FedRAMP, NIST 800-30, 800-53, 800-60, 800-171, PCI DSS, NYS DFS 500).
- Contribute to projects with a primary focus on CMMC, NIST 800-171, RMF (NIST 800-53), FISMA, and FedRAMP.
- Determine the assessment scope for CMMC Level 1 and 2 assessments, ensuring a comprehensive evaluation of all relevant security controls.
- Conduct security assessments, identify vulnerabilities, and formulate strategic plans to address gaps; recommend risk mitigation measures.
- Develop customized policies, procedures, controls, system security plans, incident response, disaster recovery plans, and technical documentation for applications, systems, and infrastructure.
- Assess security controls and provide risk-based recommendations for both technical and non-technical findings.
- Create detailed information security policies and procedures to ensure compliance with various standards, including NIST 800-171A, DFARS, CUI, CMMC, and ISO 27001/2.
- Develop a Plan of Action and Milestones (POA&M) for the remediation of organization-wide weaknesses, ensuring a systematic and prioritized approach.
- Implement cybersecurity action plans and remediation activities for information systems hosted both on-premises and in the cloud.
- Conduct ongoing monitoring tasks to verify continuous compliance with security controls according to client-specific criteria.
- Foster a collaborative and knowledge-sharing environment within the team.
- Perform other duties as assigned to contribute to the overall success of the cybersecurity team.
- Support other types of Compliance projects (CSF, CORA) as needed.
What You'll Bring
- Associate or bachelor's degree, or equivalent experience, and 8+ years' professional experience required.
- Active Secret Clearance required to start.
- Active CMMC Certified Professional (CCP) Certification required to start.
- Active CMMC Certified Assessor (CCA) Certification preferred, or ability to quickly obtain CCA.
- CISSP or IAM III equivalent required to start.
- 8 years of Cybersecurity experience.
- 5 years of assessment or audit experience.
- Knowledge of and hands-on experience with CMMC, FedRAMP, and NIST 800-53/NIST 800-171 audits and attestations.
- Deep familiarity with, or experience performing security compliance assessments supporting a C3PAO or 3PAO to meet CMMC Certification or FedRAMP requirements.
- Knowledge of security architecture, infrastructure, network, and systems design.
- Practical and working knowledge of common IT and security concepts including Cloud (Microsoft, Google or AWS), firewall management, server management, SIEM, IDS/IPS, web proxies, access control, and authentication, with advanced knowledge in at least one of these areas.
- Experience in securing operating systems.
- Experience in managing policy exceptions, including working directly with the teams to document exceptions, identifying compensating controls, and remediation action plans.
Preferred
- Familiarity with, or experience supporting security assessments of cloud service providers, preferred.
- Familiarity with, or experience developing, updating, and maintaining ATO packages for platforms, systems, and applications to meet NIST 800-53 standards, preferred.
- Experience as a Security control Assessor DoD or Federal Agencies is a plus.
- Experience implementing various security policy frameworks and control design is a plus.
Salary Range: $90,000+
Our Approach
At SecureStrux, we are committed to core values that guide the way we work with one another and our clients. As a team member, you will Create Team Synergy, Drive Continuous Innovation, Deliver with Integrity, and have the Freedom to Own it. Our thriving company culture supports our employees as they seek to grow with us!
What We Offer
Between our virtual environment where you can evaluate recent technologies and enhance your skills, and a generous annual professional development stipend, you will join a team that enjoys working on leading-edge technologies for world-class clients. We offer a robust total compensation package that includes comprehensive health benefits to support you and your family, flexible time off, continuing education allowance, a donation allowance for charitable causes, and a matched 401k.
Employment Types: Full-time
Work Arrangements: Hybrid
group id: 91082047
N