Security Analyst / ISSO

Lynk Global

Rural Grove (NY)

Hybrid

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-first, US-based role
Learning and certification budget
Competitive salary and equity

Job summary

Lynk Global seeks a Senior Cybersecurity Compliance professional to own the company’s GRC program across CMMC Level 2, NIST SP 800-171, DFARS 7012, SOC 2 Type II, and GDPR. You will serve as ISSO for CUI-scoped systems, author SSPs and POA&Ms, and drive evidence for audits in a hybrid setup based near Chevy Chase, MD.

Reporting to the CISO, you’ll mature existing controls and align tooling (SIEM/EDR/MDM/ITAM) to regulatory requirements while collaborating with legal, contracts, and business

Qualifications

  • 3–6 years in cybersecurity with a strong GRC or compliance focus; prior ISSO experience or equivalent accountability preferred.

Responsibilities

  • Own and maintain SSP and POA&M for all CUI-scoped systems; keep documentation audit-ready.

Skills

GRC/Compliance
NIST SP 800-171
SSP/POA&M
CMMC Level 2
SIEM
EDR
SOC 2/GDPR
Cloud security (AWS)
Communication

Tools

Wazuh
ThreatDown
Tenable
ManageEngine
AD GPOs
SnipeIT

Job description

Full-time · Chevy Chase, MD(Hybrid)· US-based · Senior level · Reports to CISO

US citizenship or Lawful Permanent Resident status required. This role involves access to Controlled Unclassified Information (CUI); no security clearance required.

ABOUT LYNK

Lynk is building the world’s first global satellite-to-cellular network, enabling direct device-to-device (D2D) connectivity from commercial low Earth orbit (LEO) satellites to standard mobile phones, no special hardware required. We operate in a market alongside other commercial LEO constellations, satellite-direct-to-cellular providers, and large-scale broadband satellite networks, competing for the same spectrum, orbits, and government contracts.

Our technology and network infrastructure are of significant interest to US government and defense customers. Protecting the integrity of that infrastructure and the Controlled Unclassified Information that flows through it is mission critical. That’s where you come in.

Role Overview:

Reporting directly to the CISO, you’ll own Lynk’s cybersecurity compliance program across CMMC Level 2 / NIST SP 800-171, DFARS 7012, SOC 2 Type II, and GDPR. You’ll be ISSO for CUI-scoped systems: authoring SSPs, maintaining POA&Ms, running control assessments, and leading C3PAO engagement. Lynk has a functioning security toolset in place including SIEM/log management, EDR, MDM, vulnerability management and IT asset management; your job is to mature and align that stack to CMMC requirements, not start from zero.

Responsibilities:
GRC & Compliance (primary)
  • Own and maintain the System Security Plan (SSP) and Plan of Action & Milestones (POA&M) for all CUI-scoped systems; always keep documentation audit-ready.

  • Assess all 110 NIST SP 800-171 practices for implementation and effectiveness; map existing controls (Wazuh, ThreatDown, Tenable, ManageEngine, AD GPOs, SnipeIT) to CMMC requirements, identify gaps, and drive remediation.

  • Maintain the organizational risk register; support ongoing Risk Management Framework (RMF) processes and report risk posture to the CISO.

  • Lead preparation for CMMC Level 2 assessments — build evidence packages, coordinate with the C3PAO, and manage assessor requests and findings.

  • Develop and maintain cybersecurity policies, procedures, and standards aligned to CMMC, DFARS, SOC 2, and GDPR; ensure version control and staff acknowledgment records are maintained.

  • Define, track, and report security metrics and KPIs to the CISO and non-technical stakeholders including legal, contracts, and business development teams.

  • Support contract teams with DFARS clause requirements, cybersecurity representations, and customer security questionnaires.

  • Conduct vendor and third-party risk assessments; maintain supplier risk documentation.

  • Manage the security awareness training program and phishing simulations; maintain completion records per CMMC requirements.

Security Operations (secondary)
  • Monitor SIEM for security events and alerts relevant to CUI systems; write and tune detection rules; triage and elevate incidents; produce post-incident reports with compliance impact assessment. Leverage audit log aggregation to satisfy CMMC AU (Audit & Accountability) control evidence requirements.

  • Monitor EDR alerts for CUI-scoped endpoints; investigate detections and coordinate response with IT.

  • Work with IT to ensure vulnerability findings are remediated within CMMC-required timeframes, track and report on remediation status.

  • Leverage MDM and Active Directory to enforce device compliance, GPO-based security baselines, and access control policies across CUI-scoped endpoints.

  • Use asset inventory as the authoritative hardware/software asset register for CMMC system boundary documentation; keep it current and audit ready.

  • Conduct periodic access control audits; enforce least-privilege across AD, SSO, and SaaS tooling handling CUI.

Required Skills and Experience:
  • 3–6 years in cybersecurity with a strong GRC or compliance focus; prior ISSO experience or equivalent accountability preferred.

  • Deep, working knowledge of NIST SP 800-171 and DFARS 7012. Able to assess, gap-analyze, and evidence all 110 controls independently.

  • Demonstrated experience authoring SSPs and POA&Ms for government-facing or regulated environments.

  • Familiarity with the CMMC Level 2 assessment process and C3PAO engagement.

  • Hands-on SIEM experience: writing detection rules, querying logs, and generating compliance-grade audit evidence.

  • Hands-on experience with EDR and vulnerability scanning tools in a compliance context. Mapping tool outputs to NIST controls and generating assessor evidence.

  • Working knowledge of SOC 2 Type II and GDPR compliance requirements.

  • Some cloud security fundamentals (AWS preferred). IAM, CloudTrail, GuardDuty, access policies.

  • Clear, structured communicator. Equally comfortable writing formal policy documentation and briefing non-technical executives.

  • US citizenship or Lawful Permanent Resident status.

Nice to Have:
  • CMMC Registered Practitioner (RP) or Professional (CCP)

  • CISSP / CISM / Security+

  • RMF / ATO experience

  • FedRAMP familiarity

  • Space / satellite industry background

  • Telecom or critical infrastructure security

  • Prior C3PAO assessment experience

  • GRC platform experience (Vanta, Drata, Archer, ServiceNow)

  • Scripting in Python or Bash for evidence collection automation

  • Zero-trust architecture

What Lynk Offers:
  • Competitive salary and equity in a company building genuinely novel global infrastructure.

  • Remote-first, US-based role.

  • Direct line to the CISO; your work defines Lynk’s compliance posture at a critical growth stage.

  • A functioning security toolset already in place. Your focus is maturing and aligning it, not standing it up from scratch.

  • Learning and certification budget.

ITAR Requirements

To comply with U.S. Government export control regulations (ITAR), applicants must be one of the following: (i) a U.S. citizen or national, (ii) a lawful permanent resident (green card holder), (iii) a refugee under 8 U.S.C. § 1157, or (iv) an asylee under 8 U.S.C. § 1158. Individuals who do not meet these criteria must be eligible to obtain the necessary authorizations from the U.S. Department of State. For more information, please refer to the ITAR guidelines.

Learn about ITAR here.

Lynk is an equal opportunity employer. This position requires US citizenship or Lawful Permanent Resident status due to access to Controlled Unclassified Information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst – ISSO
Security Analyst – ISSO

Lynk • United States

Remote
USD 90,000 - 120,000
Competitive salary
Equity in the company
Learning and certification budget
Network System Administrator
Network System Administrator

Lynk Global • Rural Grove (NY)

Hybrid
USD 90,000 - 130,000
Network System Administrator
Network System Administrator

One Way Ventures • Chevy Chase (MD)

Hybrid
USD 110,000 - 170,000
Ground Systems Software Engineer
Ground Systems Software Engineer

One Way Ventures • Chantilly (VA)

On-site
USD 120,000 - 180,000
Security and Compliance Lead
Security and Compliance Lead

aalyria-careers • United States

Hybrid
USD 120,000 - 140,000
Competitive salary
Comprehensive benefits
Flexible working arrangements
GNC Engineer, ADCS
GNC Engineer, ADCS

One Way Ventures • Chantilly (VA)

On-site
USD 100,000 - 130,000
IT Support Engineer
IT Support Engineer

Elveo • Chantilly (VA)

Hybrid
USD 60,000 - 90,000
PowerShell scripting
AWS familiarity
Startup experience
Senior ISSO & CMMC/GRC Lead - Remote (US)
Senior ISSO & CMMC/GRC Lead - Remote (US)

Lynk • United States

Remote
USD 90,000 - 120,000
Competitive salary
Equity in the company
Learning and certification budget
Senior Security GRC Analyst – CMMC/NIST Focus, Remote
Senior Security GRC Analyst – CMMC/NIST Focus, Remote

Lynk Global • Rural Grove (NY)

Hybrid
USD 140,000 - 190,000
Remote-first, US-based role
Learning and certification budget
Competitive salary and equity
Cybersecurity Engineer II
Cybersecurity Engineer II

Accelint Holdings LLC • San Diego (CA)

On-site
USD 110,000 - 130,000
Paid Time Off
Medical, Dental & Vision Insurance
401k Matching
+1