Security Compliance Analyst

ShorePoint

Herndon, Northern (VA, KY)

Hybrid

USD 90,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

PTO 144 hours
11 holidays
Insurance premium coverage 85%
401(k)
Continuing education
Certification maintenance & reimburse-

Job summary

ShorePoint is seeking a Security Compliance Analyst to support federal cybersecurity compliance activities, including FISMA-driven A&A, risk management, and audit readiness. You will coordinate documentation across ICAM, work with ISOs/ISSOs, and help maintain ongoing compliance in a fast-growing cybersecurity firm.

Remote role based in the United States (Herndon, VA area). The position requires collaboration with program leadership and government stakeholders, along with strong communication

Qualifications

  • Bachelor’s degree in Cybersecurity or related field, or equivalent professional experience.
  • 2+ years of federal information security compliance, IT security, or related field.
  • Experience with GRC tools such as Xacta, CSAM, RSA Archer.
  • Demonstrated experience supporting FISMA compliance activities and/or federal security audits.
  • Experience collaborating with ISOs/ISSOs on system security documentation and A&A activities.
  • Strong written and verbal communication skills for government stakeholders.

Responsibilities

  • Support the SIAM in executing the program’s information assurance and cybersecurity compliance strategy.
  • Coordinate with ISOs and ISSOs to maintain system security documentation and support ATO/cATO activities.
  • Support FISMA compliance activities, including self-assessments and audits.
  • Develop, review and maintain SSPs, SARs, POA&Ms and RARs.
  • Support RMF activities, including control selection and continuous monitoring.
  • Track POA&M remediation and ensure timely closure.
  • Prepare materials for internal reviews, external audits and inspections.
  • Maintain audit-ready documentation and communicate status to leadership.

Skills

GRC tools
Xacta
CSAM
RSA Archer
Audit readiness
Federal compliance

Education

Bachelor’s degree in Cybersecurity

Tools

Xacta
CSAM
RSA Archer

Job description

Who we are:

ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.

The Perks:

As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers. Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.

Who we’re looking for:

We are seeking a Security Compliance Analyst to support federal cybersecurity compliance activities, including Federal Information Security Modernization Act (FISMA)-driven assessment and authorization (A&A), ongoing risk management and audit readiness. This role supports the Security Information Assurance Manager (SIAM) by coordinating security documentation, control implementation, continuous monitoring and compliance activities across Identity, Credential, and Access Management (ICAM) systems. The Security Compliance Analyst position works with Information System Owners (ISOs), Information System Security Officers (ISSOs), program leadership and other stakeholders to maintain security compliance and support federal requirements. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.

What you’ll be doing:
  • Support the SIAM in executing the program’s information assurance and cybersecurity compliance strategy.
  • Coordinate with ISOs and ISSOs to maintain system security documentation, track control implementation and support Authorization to Operate (ATO) and continuous ATO (cATO) activities.
  • Support FISMA compliance activities, including annual self-assessments, security control assessments and preparation for Inspector General (IG) and Office of Management and Budget (OMB)-driven audits.
  • Develop, review and maintain security artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms) and Risk Assessment Reports (RARs).
  • Support Risk Management Framework (RMF) activities, including control selection, implementation tracking, assessment and continuous monitoring.
  • Track POA&M remediation activities to ensure findings from audits, assessments and vulnerability scans are documented, assigned and closed within required timelines.
  • Assist with the preparation of materials and evidence packages for internal reviews, external audits and compliance inspections (e.g., FISMA, OIG, GAO, or agency-specific audits).
  • Support the security compliance posture of ICAM systems and track security policy, procedure and control updates to maintain alignment with evolving federal requirements.
  • Maintain continuous monitoring documentation and support monthly and quarterly compliance reporting to program leadership and government stakeholders.
  • Participate in security control assessments, walkthroughs and stakeholder interviews to validate control implementation.
  • Maintain organized documentation repositories and audit trails to support inspection readiness.
  • Communicate compliance status, risks and action items to the SIAM and program leadership.
What you need to know:
  • Federal information security compliance and audit practices, including FISMA and A&A activities.
  • NIST RMF, NIST Special Publication (SP) 800-53 security controls and common security compliance artifacts, including SSPs, SARs, POA&Ms, RARs and continuous monitoring reporting.
  • Security documentation, control implementation, continuous monitoring and audit readiness practices.
Must have’s:
  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field, or equivalent professional experience.
  • 2+ years of experience in federal information security compliance, IT security, or a related field.
  • Experience with Governance, Risk, and Compliance (GRC) tools such as Xacta, CSAM, RSA Archer or similar.
  • Demonstrated experience supporting FISMA compliance activities and/or federal security audits.
  • Experience collaborating with ISOs and/or ISSOs on system security documentation and A&A activities.
  • Strong written and verbal communication skills, with the ability to translate technical compliance findings into clear, actionable reporting for government stakeholders.
  • Strong organizational skills and attention to detail, particularly around documentation control and audit readiness.
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Applicants must be a U.S. citizen and eligible to obtain and maintain a Public Trust security clearance, in compliance with federal contract requirements.
Beneficial to have:
  • Experience supporting an ICAM program or similar identity governance initiative.
  • Familiarity with Federal Identity, Credential, and Access Management (FICAM) architecture, NIST SP 800-63 digital identity guidelines or OMB M-19-17 or successor ICAM policy.
  • Relevant certifications such as CompTIA Security+, Certified Authorization Professional (CAP), Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA).
  • Experience supporting continuous monitoring programs or cATO initiatives.
  • Prior experience in a federal contracting environment supporting a civilian or defense agency.
Where it’s done:
  • Remote (Herndon, VA).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Compliance Analyst
Cybersecurity Compliance Analyst

Reston Consulting Group, Inc. • Suitland (MD)

Hybrid
USD 115,000 - 125,000
Cybersecurity Specialist
Cybersecurity Specialist

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Remote RMF & CSAM Security Analyst
Remote RMF & CSAM Security Analyst

PingWind • United States

On-site
USD 75,000 - 104,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+7
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 80,000 - 90,000
Sr. Security & Compliance Specialist - TS Clearance
Sr. Security & Compliance Specialist - TS Clearance

SVD Solutions • Washington

Hybrid
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+2
Information System Security Officer
Information System Security Officer

Conviso Inc. • Washington

On-site
USD 150,000 - 190,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

ShorePoint, LLC • Albuquerque (NM)

On-site
USD 120,000 - 180,000
PTO 144 hours
11 holidays
Insurance premium coverage 85%
+2
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

Hybrid
USD 140,000 - 220,000
Paid holidays
PTO
Group medical plan
+4
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 150,000 - 210,000
11 paid holidays
3 weeks PTO (min)
Medical plan
+4