IT GRC Analyst Level II

Socket.dev

Town of Florida (NY)

On-site

USD 90,000 - 130,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Socket.dev is seeking an IT GRC Analyst (CMMC Control Specialist) to monitor, test, and analyze compliance of cybersecurity controls in hybrid IT environments. You will review logs, verify evidence, and author detailed SOPs to ensure adherence to NIST SP 800-171 and DFARS requirements.

Responsibilities include daily control monitoring, evidence analysis, POA&M execution, and audit support for SPRS and external assessments, collaborating with system administrators and IT operations.

Qualifications

  • Hands-on IT compliance monitoring and auditing in a DoD/DFARS environment.
  • Ability to author SOPs, system guides, and audit-ready logs.
  • Experience with NIST SP 800-171, CMMC Level 2, and DFARS 252.204-7012.

Responsibilities

  • Draft, review, and refine SOPs translating 800-171 controls into workflows.
  • Audit operations and update documentation as environments change.
  • Maintain SOP repository with version control and SSP alignment.
  • Convert POA&M remediation into repeatable SOPs to close gaps.
  • Monitor controls, collect artifacts, and verify evidence across hybrid/cloud environments.
  • Support SPRS updates and audits (DIBCAC/C3PAO).

Skills

IT compliance
Audit & testing
Documentation
NIST SP 800-171
DFARS

Education

Bachelor’s Degree in Cybersecurity

Tools

SIEM
Entra ID
Microsoft 365
GCC High
Firewalls

Job description

Description

Position Overview

The IT GRC Analyst (CMMC Control Specialist) is responsible for the daily monitoring, operational testing, and ongoing compliance analysis of the organization’s cybersecurity controls. Rather than developing high-level enterprise security policies, this operational role focuses on hands-on control execution, reviewing technical logs, verifying evidence, and authoring, maintaining, and updating granular Standard Operating Procedures (SOPs). This position ensures that hybrid IT environments, cloud enclaves, and technical infrastructure continuously satisfy CMMC Level 2 and NIST SP 800-171 requirements through standardized, repeatable processes.Key Responsibilities
Key Responsibilities

SOP Development, Maintenance & Operationalization:

  • Draft, review, and continuously refine detailed Standard Operating Procedures (SOPs) that translate complex NIST SP 800-171 controls into step-by-step technical workflows for IT staff.
  • Audit operational practices regularly to ensure procedural alignment with active SOPs, updating documentation whenever technical environments or baseline configurations evolve.
  • Maintain the centralized repository of GRC SOPs, work instructions, and execution templates, ensuring version control and strict alignment with the enterprise System Security Plan (SSP).
  • Partner with System Administrators and IT Operations to convert POA&M remediation outcomes into formalized, repeatable SOPs to prevent recurring compliance gaps.

Daily Control Monitoring & Evidence Analysis

  • Perform daily, weekly, and monthly operational reviews of technical controls across all 14 NIST SP 800-171 practice domains (e.g., auditing SIEM logs, validating MFA enforcement, and reviewing access requests) in accordance with established SOPs.
  • Collect, inspect, and archive technical artifacts and evidence (configuration baselines, backup logs, patch records) to maintain continuous audit readiness.
  • Identify, document, and report control drift or non-compliance issues across hybrid Active Directory, cloud environments (GCC High/Azure), and virtualization platforms.
  • Execute recurring internal control tests to verify that technical safeguards operate as documented in the SSP and procedural guidelines.

Risk Tracking & POA&M Execution

  • Track and validate the daily progress of remediation items listed on the active Plan of Action & Milestones (POA&M).
  • Collaborate directly with System Administrators and IT Operations to test and verify fixed items before closing out open POA&M entries.
  • Monitor daily CUI flow paths and enclave access logs to verify that Controlled Unclassified Information (CUI) boundary controls remain strictly enforced.
  • Conduct routine vendor risk checks, verifying that subcontractors maintain active compliance with DFARS 252.204-7012 / 7020 flow-down requirements.

Audit Support & Reporting

  • Analyze compliance data to support regular SPRS score updates and internal readiness reporting.
  • Serve as the primary hands-on evidence and procedural coordinator during internal compliance reviews, DIBCAC audits, and external C3PAO assessments.
  • Generate weekly operational risk metrics, process execution logs, and gap analysis reports for the IT Security Manager.

Qualifications & Requirements

  • Experience: 2–4+ years of hands-on experience performing IT compliance monitoring, internal auditing, procedural documentation, or security control testing in a DoD/DFARS environment.
  • Documentation & SOP Skills: Proven ability to author clear, step-by-step technical Standard Operating Procedures (SOPs), system administration guides, and audit-ready control execution logs.
  • Framework Knowledge: Direct experience monitoring and analyzing controls under NIST SP 800-171, CMMC Level 2, and DFARS 252.204-7012.
  • Technical Familiarity: Practical experience inspecting control evidence within Active Directory / Entra ID, Microsoft 365 / GCC High, firewalls, SIEM platforms, and hypervisors.
  • Education: Bachelor’s Degree in Cybersecurity, Information Systems, or equivalent practical technical experience.

Preferred Certifications

  • CMMC / Compliance: CCP (CMMC Certified Professional) or CISA.
  • General Security: Security+, Network+, or SSCP.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
GRC Analyst – CMMC Level 2 & SOP Expert
GRC Analyst – CMMC Level 2 & SOP Expert

Socket.dev • Town of Florida (NY)

On-site
USD 90,000 - 130,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 120,000 - 155,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Information Security Analyst - GRC & Operations
Information Security Analyst - GRC & Operations

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark Bank • Ridgeland (MS)

Hybrid
USD 60,000 - 80,000
Senior Security Compliance Specialist
Senior Security Compliance Specialist

FORTEM TECHNOLOGIES INC • Lindon (UT)

On-site
USD 110,000 - 160,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark • Ridgeland (MS)

Hybrid
USD 65,000 - 85,000