Information Security Compliance Analyst
Remotemid
OtherInformation Security
2 views0 saves0 applied
Quick Summary
Key Responsibilities
This position will manage/lead a wide range of compliance and risk functions, with the focus being on maintaining and enhancing our compliance maturity.
Requirements Summary
Risk Management Framework (RMF), compliance with security technical implementation guides (STIGs),
Technical Tools
OtherInformation Security
Information Security Compliance Analyst
Data Recognition Corporation - Minnesota
Please No Agencies
Company cannot provide sponsorship for this position
Summary:
This position is part of the Data Recognition Corporation (DRC) Information Security Team that has an important role in the defining and enabling the secure operation of the DRC environment. This position has responsibility for managing and leading various risk and compliance activities, including internal and external security reviews that are key to validation of our security program.
This position also assists with other aspects of the security practice, including maintaining DRC’s security policies, standard and procedures; increasing the organizations security awareness; performing risk assessment and risk management activities; and promoting business continuity and resiliency efforts.
Responsibilities:
This position will manage/lead a wide range of compliance and risk functions, with the focus being on maintaining and enhancing our compliance maturity. Key responsibilities include:
Obtain and maintain GovRAMP compliance
Support Authority to Operate (ATO) approvals for government contracts by adherence to NIST Risk Management Framework (RMF)
Support cybersecurity efforts to include the development and management of System Security Plan (SSP) documentation, Plans of Action and Milestones (POAMs), assessing and auditing systems security controls, and continuous monitoring activities
Manage internal and external annual audits (third party and customer)
GovRAMP
ISO 27000 series
SOC II Type 2
Various customer audits
Maintain and drive remediation on Plan of Action and Milestones (POAM) items
Policy and standard development and review
Mature security risk management practices
Manage and enhance Business Continuity/Disaster Recovery processes
Update and maintain security and compliance metrics
Essential Qualifications
3+ years of Information Security, GRC, audit, or compliance experience
Working knowledge in NIST 800-53 Rev 5 framework and how to implement and audit against the framework
General knowledge of the following: Risk Management Framework (RMF), compliance with security technical implementation guides (STIGs), and documenting Plan of Action and Milestones (POA&M)
Experience managing SOC 2 Type II compliance audits
Possesses a high level of personal integrity and the ability to discreetly handle sensitive, personal, and classified information.
Must have excellent communication skills and the ability to work well in a team and across the organization, in addition to independently driving initiatives.
Preferred Qualifications
Four-year college degree in IT, Computer Science, Cybersecurity, or related fields
Internal or External Audit experience
Experience with GovRAMP or FedRAMP certifications
Experience with Federal Information Security Management Act (FISMA) leveraging National Institute of Standards and Technology (NIST) security controls (NIST 800-53, rev 5).
Security certification such as Certified Information Security Auditor (CISA) and/or Certified in Risk and Information Security Controls (CRISC)
Experience with ISO 27001 certification
Experience supporting and participating in third party vendor security assessments and audits, reviewing audit findings as well as responses to security findings and remediation plans.
Ability to manage cross-functional projects and initiatives as required.
Reporting to this position: No direct reports
The Employer retains the right to change or assign other duties to this position
Company cannot provide sponsorship for this position
Please, no agencies
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Location & Eligibility
Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location
Listing Details
- Posted
- October 8, 2026
- First seen
- October 8, 2026
- Last seen
- October 8, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 63%
- Scored at
- October 8, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application
Similar Information Security jobs
View all →Browse Similar Jobs
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.