Job Closed
This listing is no longer active.
Enterprise cybersecurity for small and medium businesses | Specialize in defense and federal | Ask us about CMMC/DFARS
CMMC Compliance Analyst
Location
Virginia
Posted
135 days ago
Salary
$70K - $90K / year
Seniority
Mid Level
Job Description
CMMC Compliance Analyst
Sentinel Blue
• Receive, triage, and analyze compliance-related requests, documentation, and assessment findings, and work to resolve issues through research, evidence collection, and stakeholder coordination. • Support the development and maintenance of System Security Plans (SSPs), POA&Ms, policy sets, procedures, and control documentation across client environments. • Review client technical configurations (e.g., access controls, logging, encryption, segmentation, backup strategies) against NIST/CMMC compliance objectives and document gaps or remediation actions. • Communicate with clients through email, chat, meetings, and interviews to gather evidence, clarify processes, and maintain progress visibility on compliance deliverables. • Assist in the management, implementation, and validation of compliance controls across CMMC, NIST 800-171, and/or DFARS 7012. • Contribute to internal compliance documentation templates, client-facing guidance materials, and evidence repositories that streamline audit readiness. • Support the creation of compliance reports, risk assessments, briefs, and executive presentations that translate findings into clear business narrative.
Job Requirements
- U.S. citizenship - by nature of our work with the defense industry, all employees must be eligible for a Secret clearance.
- 2-5 years of experience in information security, IT compliance, cybersecurity auditing, GRC, or similar roles.
- Demonstrated ability to lead and make decisions on compliance-related matters, including interpreting control intent, assessing evidence, and determining whether control requirements have been met.
- Experience reviewing and developing policies, procedures, SSPs, POA&Ms, risk assessments, or similar compliance documentation.
- Working knowledge of technical environments such as IAM, endpoint protection, logging/monitoring, vulnerability management, segmentation, and backup/recovery strategies.
- Strong written and verbal communication skills, especially when translating technical information into actionable compliance guidance.
- Ability to work independently, manage multiple client tasks, and follow structured workflows to drive compliance activities to timely completion.
- CompTIA Security+ certification is required in the first 2 months of hire.
Benefits
- Fully paid individual healthcare, vision and dental insurance for the employee.
- Paid certification and training opportunities.
- Three weeks of paid vacation + 10 paid holidays.
- A supportive environment with a focus on keeping healthy work-life balance.
- Retirement benefit (401k) with company match.
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Senior Product Compliance Engineer
Agility RoboticsWe build robots made for work, engineered to work in nearly any environment, alongside people.
• Lead CE conformity assessments for machinery and robotic systems in accordance with EU regulations • Interpret and apply relevant directives and regulations, including but not limited to: Machinery Directive / Machinery Regulation (2006/42/EC / EU 2023/1230), Low Voltage Directive (LVD), EMC Directive, Radio Equipment Directive (RED), where applicable • Perform and review risk assessments in accordance with ISO 12100 • Ensure compliance with relevant harmonized standards (e.g., EN ISO 13849, EN IEC 62061, EN 60204-1, ISO 10218) • Support the creation and maintenance of Technical Files, including: Risk assessments, Schematics and drawings, Test reports, Declarations of Conformity, User manuals and safety instructions • Coordinate and support testing activities (EMC, electrical safety) • Interface with Notified Bodies, test laboratories, and regulatory authorities as required • Provide compliance guidance during product design reviews and change management • Monitor regulatory updates and assess impact on existing and future products • Support internal audits and continuous improvement of compliance processes
• Define and execute Tines' multi-year GRC strategy aligned with business objectives and market expansion goals • Own the compliance roadmap, prioritizing certifications and frameworks based on customer needs and revenue impact (FedRAMP, ISO 27001, SOC 2, GDPR, CCPA, etc.) • Serve as executive sponsor for all compliance programs, providing visibility and reporting to C-suite and Board of Directors • Build business cases for compliance investments, demonstrating ROI and competitive advantage • Monitor evolving compliance landscape, anticipating regulatory changes and translating requirements into actionable programs • Lead, mentor, and grow a team of GRC professionals, establishing career development paths and performance metrics • Drive Tines' FedRAMP authorization to successful completion, overseeing gap remediation, documentation, and 3PAO engagement • Maintain and optimize SOC 2 Type II compliance, ensuring efficient audit cycles and continuous control effectiveness • Own the information security policy framework, ensuring alignment with regulatory requirements and business needs • Own the customer security assurance experience, including questionnaire responses, audit coordination, and Trust Center management.
Director, Compliance
Connexus Credit UnionServing members across all 50 states, Connexus Credit Union is a member-focused cooperative that is proud to return profits to member-owners through high yields for checking accounts and deposit products, as well as competitive rates on our loans. We are a remote first employer with the majority of our employees residing in the upper Midwest. As an employer we foster collaboration and high performance to achieve excellence. We holistically care for and develop our employees to thrive personally and professionally. We are proud to share our success with our employees and those we serve.
• Develop, implement, and maintain detailed compliance management procedures consistent with applicable laws and regulations. • Oversee the CMS framework, including risk and control identification, reporting, monitoring, testing, change management, training, complaint management, governance, and regulatory relations. • Serve as the designated Director of Compliance, authorized to engage with all departments and effect corrective action as necessary. • Ensure compliance responsibilities are communicated and incorporated into business processes across the organization. • Lead the development and maintenance of risk assessments for various processes and programs to identify risks, create internal controls, and implement mitigation factors. • Review and update policies and procedures to ensure alignment with legal requirements and Connexus standards. • Coordinate and deliver comprehensive compliance training for all employees, tailored to job functions. • Oversee the process for receiving, recording, investigating, and resolving consumer complaints. • Conduct regular compliance quality assurance testing to evaluate adherence to laws, regulations, and internal policies. • Maintain proactive monitoring systems to identify procedural or training weaknesses.
Director, Healthcare Compliance
Mirum Pharmaceuticals, Inc.Creating transformative medicine for people with rare liver disease.
• Lead and manage all aspects of federal and state transparency (Sunshine Act/Open Payments and similar state requirements) and aggregate spend reporting requirements. • Monitor and analyze data for trends, anomalies and compliance gaps. • Manage ongoing development and execution of Mirum’s risk-based auditing and monitoring program to ensure compliance with applicable laws, regulations and company policies. • Work with third-party vendors and internal stakeholders to ensure compliance with state licensing, registration and renewal requirements. • Manage continual development and implementation of Mirum’s compliance policies. • Champion Company culture in which employees view compliance as aligned with core values and regard it as a key objective in business decisions and process development. • Partner with legal, regulatory, finance, quality and other departments to support compliance-related initiatives and resolve operational compliance issues. • Assist with ongoing management of training curriculum and healthcare compliance training as needed. • Assist with investigations regarding matters of observed, reported or suspected non-compliance and collaborate with functional heads as needed toward implementing necessary corrective actions. • Support Privacy initiatives for HIPAA and GDPR compliance as needed. • Represent Mirum in industry compliance forums. • Participate in ride-long monitoring activities as needed.




