Job Closed
This listing is no longer active.
Powering and Empowering Government
Information Security Compliance Analyst
Location
United States
Posted
76 days ago
Salary
$61.7K - $87.6K / year
Seniority
Senior
Job Description
Information Security Compliance Analyst
CivicPlus
• Maintain and update information security policies, standards, and procedures in alignment with modern cybersecurity frameworks and regulatory requirements, including GovRAMP, FedRAMP, ISO 27001, PCI DSS, and SOC 2. • Maintain System Security Plans (SSPs) to ensure system boundaries, control implementations, and control inheritance accurately reflect the current state of production systems. • Coordinate and manage internal and external compliance assessment activities, including audit planning, audit fieldwork coordination, evidence collection and preservation, and support of audit responses. • Manage continuous monitoring activities, including tracking, updating, and reporting Plan of Actions and Milestones (POA&Ms) to support risk remediation and security posture communication. • Support risk assessments and control gap analyses by identifying security and compliance deficiencies and collaborating with stakeholders to define remediation approaches. • Define, track, and report key compliance metrics to measure program effectiveness and communicate compliance posture to leadership and governance committees. • Partner closely with engineering, operations, and production teams to ensure security requirements are documented, implemented consistently, and remain audit-ready across systems. • Develop and maintain audit-ready evidence repositories to support repeatable, efficient compliance assessments and reduce audit cycle time. • Provide guidance to system owners and control owners on compliance expectations, documentation standards, and control implementation requirements.
Job Requirements
- Bachelor’s degree in Cybersecurity, Information Security, Information Systems, or a related field (preferred), or equivalent professional experience.
- 3–5 years of experience in information security compliance, cybersecurity assurance, GRC, or a related field.
- Demonstrated experience managing System Security Plans (SSPs) and supporting documentation for enterprise systems.
- Experience supporting compliance audits and certifications, including NIST 800-53 (FedRAMP/GovRAMP), ISO 27001, PCI DSS, and/or SOC 2.
- Strong understanding of modern information security compliance frameworks and control-based security programs (e.g., NIST 800-53, ISO 27001, SOC 2).
- Ability to interpret regulatory and compliance requirements and translate them into clear, actionable documentation.
- Strong analytical, writing, and organizational skills with exceptional attention to detail.
- Ability to manage multiple compliance activities concurrently while meeting deadlines and quality expectations.
- Certifications Security+, GSEC, or equivalent certification preferred.
Benefits
- Comprehensive health insurance
- Dental insurance
- Vision insurance
- Flexible Time Off
- 401(k) plan
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Information Security Analyst – Engineer
DoiT InternationalDoiT develops the technology and expertise needed to solve both essential and complex cloud challenges.
• Monitor security alerts, incidents, and threats across DoiT's global infrastructure • Conduct security assessments and vulnerability scans for cloud environments and applications • Investigate and respond to security incidents, coordinating with relevant teams for remediation • Maintain and update security documentation, playbooks, and incident response procedures • Support compliance efforts including SOC2, ISO 27001, and customer security assessments • Assist with security awareness training and education initiatives across the organization • Implement and maintain security controls across AWS, Google Cloud, and Microsoft Azure environments • Configure and monitor cloud security tools including SIEM, CASB, and vulnerability scanners • Review cloud architecture designs and provide security recommendations • Support secure configuration management and infrastructure as code practices • Monitor cloud access patterns and investigate anomalous activities • Assist with security policy development and implementation • Support vendor security assessments and due diligence processes • Maintain security metrics and reporting for leadership and compliance requirements • Participate in security audits and provide evidence for compliance frameworks • Help develop and test business continuity and disaster recovery plans • Work closely with IT Operations team on security-related projects and initiatives • Provide security guidance to development and engineering teams • Support procurement processes by reviewing security requirements for new tools and services • Collaborate with external security consultants and penetration testing teams • Participate in cross-functional incident response and crisis management activities
Information Security Analyst, Engineer
DoiT InternationalDoiT develops the technology and expertise needed to solve both essential and complex cloud challenges.
• Monitor security alerts, incidents, and threats across DoiT's global infrastructure • Conduct security assessments and vulnerability scans for cloud environments and applications • Investigate and respond to security incidents, coordinating with relevant teams for remediation • Maintain and update security documentation, playbooks, and incident response procedures • Support compliance efforts including SOC2, ISO 27001, and customer security assessments • Assist with security awareness training and education initiatives across the organization • Implement and maintain security controls across AWS, Google Cloud, and Microsoft Azure environments • Configure and monitor cloud security tools including SIEM, CASB, and vulnerability scanners • Review cloud architecture designs and provide security recommendations • Support secure configuration management and infrastructure as code practices • Monitor cloud access patterns and investigate anomalous activities • Assist with security policy development and implementation • Support vendor security assessments and due diligence processes • Maintain security metrics and reporting for leadership and compliance requirements • Participate in security audits and provide evidence for compliance frameworks • Help develop and test business continuity and disaster recovery plans • Work closely with IT Operations team on security-related projects and initiatives • Provide security guidance to development and engineering teams • Support procurement processes by reviewing security requirements for new tools and services • Collaborate with external security consultants and penetration testing teams • Participate in cross-functional incident response and crisis management activities
• Partner with Security and Sales to double weekly fulfillment of customer security requests and improve enterprise deal cycle velocity. • Perform collection and organization of compliance evidence to support SOC 2 and other framework audits and help deliver an exception free audit. • Configure and maintain security and compliance monitoring systems, reducing false-positive alerts through improved tuning and alerting workflows. • Track and coordinate vulnerability remediation efforts to eliminate breached remediation SLAs and improve security program accountability. • Maintain and update security policies, procedures, and documentation required for regulatory frameworks and internal security standards. • Support cross functional security and compliance initiatives that improve Scribe’s overall security posture and enterprise readiness.
• Monitor, identify and analyze events from a range of sources to spot threats and respond to such incidents with a sense of urgency. • Collaborate with globally distributed teams to accomplish tasks. • Assist in the collection of metrics to measure the efficiency of Security Operations functions. • Audit the effectiveness of security measures to check if the systems meet the Security compliance norms. • Assist in implementation of security policies and procedures. • Fine-tune of the process and eventually update standard operating procedures for the team. • Participate in various stages of incident investigations and threat hunting engagements. • Work closely with internal company teams such as Product, Customer Success, etc.


