Information Security Compliance Analyst
Quick Summary
The Information Security Compliance Analyst is responsible for maintaining the organization’s information security compliance posture by managing security documentation, supporting audits, and ensuring consistent implementation of security controls…
Bachelor’s degree in Cybersecurity, Information Security, Information Systems, or a related field (preferred), or equivalent professional experience.
The Information Security Compliance Analyst is responsible for maintaining the organization’s information security compliance posture by managing security documentation, supporting audits, and ensuring consistent implementation of security controls across production information systems. This role partners closely with technical and operational stakeholders to ensure security requirements are accurately documented, auditable, and aligned with regulatory and organizational expectations, while supporting risk management and continuous monitoring activities.
Nice to Have
~1 min readAt CivicPlus, we strive to bring our company vision to life through innovation and collaboration. Supported by approachable leadership and transparent communication, we're empowered to make an impact on local government and the residents they serve. Grow your career alongside great people, where authenticity is welcome, successes are celebrated, and potential is nurtured.
Responsibilities
~1 min readAs an Information Security Compliance Analyst, you will:
- →Maintain and update information security policies, standards, and procedures in alignment with modern cybersecurity frameworks and regulatory requirements, including GovRAMP, FedRAMP, ISO 27001, PCI DSS, and SOC 2.
- →Maintain System Security Plans (SSPs) to ensure system boundaries, control implementations, and control inheritance accurately reflect the current state of production systems.
- →Coordinate and manage internal and external compliance assessment activities, including audit planning, audit fieldwork coordination, evidence collection and preservation, and support of audit responses.
- →Manage continuous monitoring activities, including tracking, updating, and reporting Plan of Actions and Milestones (POA&Ms) to support risk remediation and security posture communication.
- →Support risk assessments and control gap analyses by identifying security and compliance deficiencies and collaborating with stakeholders to define remediation approaches.
- →Define, track, and report key compliance metrics to measure program effectiveness and communicate compliance posture to leadership and governance committees.
- →Partner closely with engineering, operations, and production teams to ensure security requirements are documented, implemented consistently, and remain audit-ready across systems.
- →Develop and maintain audit-ready evidence repositories to support repeatable, efficient compliance assessments and reduce audit cycle time.
- →Provide guidance to system owners and control owners on compliance expectations, documentation standards, and control implementation requirements.
- →Other duties as assigned by leadership.
We know that excellent candidates come from diverse backgrounds. Even if you don’t meet 100% of the listed requirements, we encourage you to apply!
Requirements
~1 min readThis role offers:
- Strengthen security at scale. Help shape and maintain compliance across FedRAMP, GovRAMP, ISO, PCI, and SOC 2 for a trusted GovTech platform.
- Work across teams with real influence. Partner with engineering and operations to ensure controls are implemented consistently and audit-ready.
- Drive measurable impact. Own SSPs, audits, and continuous monitoring that directly improve our security posture.
- Grow in a mission-driven culture. Build deep expertise while supporting technology that serves local governments and communities.
What We Offer
~1 min read- Introductory call with Talent Acquisition
- Interview with the Hiring Manager
- Interviews with Team Leadership (may include multiple conversations)
- Offer
Note: The process may vary slightly depending on the role.
- CivicPlus is currently unable to provide visa sponsorship for this position now or in the future. Applicants must be authorized to work in the US.
- We encourage you to apply as soon as possible, as applications will be reviewed on a rolling basis, and the posting may close earlier at the discretion of the Talent Acquisition team
CivicPlus is proud to be an Equal Employment Opportunity employer. We celebrate and support diversity for the benefit of our employees, products, clients, and communities. Reasonable accommodations are available during the interview process.
Location & Eligibility
Listing Details
- Posted
- February 16, 2026
- First seen
- May 7, 2026
- Last seen
- May 8, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 23%
- Scored at
- May 7, 2026
Signal breakdown
Please let civicplus know you found this job on Jobera.
4 other jobs at civicplus
View all →Explore open roles at civicplus.
Similar Information Security jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.