Cybersecurity Compliance Analyst

Decision Point Security, Inc.

Northern (KY)

Hybrid

USD 80,000 - 110,000

Full time

19 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Company Paid Health Insurance
Company Paid Dental Insurance
Company Paid Vision Insurance
Company Paid Life Insurance
Paid Training
Home Office Stipend
Paid Time Off

Job summary

Decision Point Security, Inc. is seeking a mid-level Cybersecurity Compliance Analyst to bridge engineering and RMF compliance. You will conduct NIST 800-53 control reviews and SRG/STIG assessments on DoW cloud architectures, delivering actionable recommendations to engineers for secure-by-design deployments.

This role integrates into engineering teams, requires strong written and oral communication, and offers remote work with travel within the United States.

Qualifications

  • 3–5+ years in DoD/DoW or DIB cybersecurity/RMF
  • DoD IAM/IAT Level II/III cert (e.g., Security+, CISSP)
  • Hands-on RMF artifacts management in eMASS
  • Experience with NIST SP 800-53, DISA STIGs, and vulnerability tools
  • Active DoD Secret clearance

Responsibilities

  • Assist the Security Control Assessor in RMF processes—write SARs, draft authorization memos, review SRCs, and conduct briefs.
  • Manage RMF documentation in eMASS, validate artifacts, coordinate plans, maintain compliance across RMF families.
  • Conduct security control assessments on complex defense cloud environments per NIST SP 800-37/800-53.
  • Ensure compliance with DoD SRG/ DISA STIGs, FISMA, and cloud SRG across system lifecycles.
  • Run vulnerability scans with ACAS/Nessus/SCAP; translate findings to engineering safeguards.
  • Review architectures, networks, and data flows to identify vulnerabilities and craft safeguards.
  • Perform continuous monitoring to maintain accurate system records and authorization status.

Skills

Communication skills

Education

DoD IAM/IAT Level II/III certification

Tools

eMASS
ACAS
Nessus
SCAP

Job description

Decision Point Security, Inc Cybersecurity Compliance Analyst Remote·Full time Company website

We are looking for a driven, mid-level professional who brings a strong technical background to our dynamic team. This role bridges the gap between technical engineering and Risk Management Framework (RMF) compliance by conducting in-depth NIST 800-53 control reviews and SRG/STIG assessments on Department of War (DoW) cloud architectures. Unlike traditional compliance roles, this position is deeply integrated into the technical lifecycle. You will participate directly in engineering working groups, providing actionable recommendations to systems and software engineers to ensure our deployments are secure by design. If you possess strong written and oral communication skills, in-depth technical aptitude, and the ability to solve complex challenges in a fast-paced environment, we want you on our team!

About Decision Point Security, Inc

Decision Point team has over 150 years combined experience delivering solutions based on sound research principals and critical thinking. Members of the team have been trusted with hardening and assessment of some of our nation’s critical defense infrastructure and weapon systems.We understand that achieving and maintaining adequate security requires thorough understanding of people, processes, and systems.Challenges associated with each of these areas are dynamic and can be costly. Let our team work with you to deliver practical, cost effective solutions.

Description
Responsibilities
  • Aid the Security Control Assessor (SCA) in the RMF process by performing Security Assessments, writing Security Assessment Reports (SAR), drafting authorization memorandums, reviewing Security Relevant Change (SRC) requests, and conducting determination briefs.
  • Manage RMF documentation within eMASS, validating artifacts, coordinating plans, and maintaining compliance across all RMF control families.
  • Conduct comprehensive security control assessments (SCA) on complex defense cloud environments in accordance with NIST SP 800-37 and NIST SP 800-53.
  • Ensure compliance with DISA STIGs/SRGs, FISMA requirements, and the DoD Cloud Computing SRG across system lifecycles.
  • Execute and review vulnerability scans utilizing tools such as ACAS/Tenable Security Center and SCAP Compliance Checker (SCC).
  • Review system architectures, network diagrams, and data flows to identify vulnerabilities and translate compliance requirements into actionable technical safeguards for engineering teams.
  • Perform continuous monitoring tasks required to maintain accurate system records and ensure ongoing authorization.
Required Qualifications
  • 3-5+ years of experience in cybersecurity, information assurance, or RMF compliance within the Department of Defense (DoD) / Department of War (DoW) or Defense Industrial Base (DIB).
  • DoDD 8570/8140 IAM or IAT Level II/III professional certification (e.g., Security+, CISSP, SecurityX).
  • Deep, hands-on experience utilizing eMASS for RMF artifact management, POA&M tracking, ATO package development, reviewing control compliance, or reviewing POA&M updates.
  • Strong proficiency with NIST SP 800-53, DISA STIGs, and vulnerability assessment tools (ACAS/Nessus, SCAP).
  • Experience assessing cloud architectures (AWS, Azure, GCP, etc) and understanding the DoD Cloud Computing SRG.
  • Exceptional ability to articulate complex security risks and deliver practical recommendations to both technical engineers and non-technical leadership.
  • Active DoD Secret (or higher) security clearance.
Preferred Qualifications
  • Previous experience as an Information Systems Security Officer (ISSO), Security Control Assessor (SCA), or RMF Information System Security Manager (ISSM).
  • Familiarity with container orchestration (Kubernetes/docker) and securing CI/CD pipelines.
  • Understanding of security engineering principles applied to Artificial Intelligence (AI) threat modeling and data pipeline security.
  • Experience supporting secure system development by reviewing A&A artifacts such as Ports, Protocols, and Services (PPS) and Hardware/Software inventories.
  • Generous 401(k) contribution, matching not required
  • Company Paid Health Insurance
  • Company Paid Dental insurance
  • Company Paid Vision Insurance
  • Company Paid Life Insurance
  • Paid Training
  • Home Office Stipend
  • Paid Time Off
Location
  • Remote within the United States with 10-20% travel
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote RMF Compliance Analyst – DoD Cloud Security
Remote RMF Compliance Analyst – DoD Cloud Security

Decision Point Security, Inc. • Northern (KY)

Hybrid
USD 80,000 - 110,000
Company Paid Health Insurance
Company Paid Dental Insurance
Company Paid Vision Insurance
+4
Security & Compliance Analyst
Security & Compliance Analyst

Endurion • Tampa (FL)

On-site
USD 95,000 - 140,000
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 80,000 - 90,000
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Senior Information Security Analyst
Senior Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 105,000 - 115,000
Cybersecurity Analyst Expert
Cybersecurity Analyst Expert

Pueo Business Solutions LLC • Virginia (IL), Northern (KY)

Hybrid
USD 110,000 - 150,000
Program Manager
Program Manager

Decision Point Security, Inc. • Northern (KY)

Hybrid
USD 120,000 - 160,000
401(k) contribution
Health insurance
Dental insurance
+5
Cyber Security Engineer
Cyber Security Engineer

Systems Planning & Analysis • Huntsville (AL)

On-site
USD 80,000 - 110,000
Competitive compensation
Industry-leading 401k contribution
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Technomics, Inc. • Arlington (VA)

On-site
USD 100,000 - 130,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 120,000 - 155,000