The #1 field service management app for contractors.
Security & Compliance Analyst
Location
United States
Posted
11 days ago
Salary
$110K - $125K / year
Seniority
Senior
Job Description
Security & Compliance Analyst
CompanyCam
• Administer CompanyCam's Vanta Professional instance • Own NIST CSF 2.0 and SOC 2 Type II framework alignment • Identify and route compliance gaps • Maintain evidence libraries and audit trails • Prepare risk reporting for the Enterprise Risk Committee • Own the risk register • Conduct vendor security assessments • Own the intake and response process for security questionnaires • Support security awareness initiatives
Job Requirements
- 3 to 5 years of experience in GRC, security compliance, or information security
- Hands-on experience with Vanta (or a comparable platform)
- Direct experience with a SOC 2 Type II audit lifecycle
- Working knowledge of NIST CSF 2.0
- Strong analytical skills
- Continuous growth-mindset
- Creativity and innovation skills
Benefits
- meaningful equity
- paid time off
- flexible work arrangements
- professional development
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead the strategic direction, growth plan, and day-to-day operations of the security practice, including service development, go-to-market priorities, and revenue attainment. • Partner with sales teams to qualify opportunities, develop account strategies, support discovery sessions, and help position security solutions that address customer business and risk objectives. • Provide technical and business leadership across email security, SASE, endpoint protection, vulnerability management, SOC/MDR, and secure gateway solutions, ensuring offerings remain current, competitive, and aligned to client demand. • Oversee delivery quality, resource planning, utilization, and customer satisfaction across security engagements, including assessments, implementations, managed services, and recurring advisory services. • Build strategic relationships with key security vendors and partners, including Arctic Wolf, Pondurance, Zscaler, Cloudflare, and other relevant platform providers to support joint selling, enablement, and service delivery excellence. • Work with internal iT1 personnel attached to Security Vendors to collaborate on business plans and strategy. • Recruit, mentor, and develop security consultants, engineers, and practice resources by establishing career paths, training plans, delivery standards, and technical enablement programs. • Own practice-level financial performance, including forecasting, pipeline health, gross margin, service pricing input, and contribution to annual business planning. • Contribute to proposals, statements of work, service descriptions, presentations, and executive briefings, translating technical capabilities into clear business value and delivery outcomes. • Establish and track key performance indicators for the practice, including bookings, revenue, utilization, customer satisfaction, service quality, and partner performance, and drive continuous improvement based on results.
• Execute user access provisioning and deprovisioning requests (joiner, mover, leaver) • Validate access requests for completeness and proper authorization • Assist in maintaining role-based access models (RBAC) • Support management of Active Directory, Entra ID (Azure AD), or similar directories • Support day-to-day operations of IAM platforms (e.g., Okta, SailPoint, Saviynt, Entra ID) • Assist with onboarding applications into IAM systems • Help troubleshoot user access issues and authentication failures • Maintain documentation of IAM processes and procedures • Help enforce basic least privilege and access policies • Work with IT, HR, and business units to fulfill access requests • Communicate clearly with end users regarding access issues • Participate in team meetings and knowledge-sharing activities • Participate in compliance audits and support IAM audits and reporting. • Identify risks and recommend solutions to ensure compliance with IAM standards. • Work with the IAM team to resolve identity and access management problems. • Maintaining up-to-date knowledge of identity and access management best practices. • Documenting IAM processes and procedures.
Information Security Officer
R&C Request GmbHR&C Request GmbH Matching people since the last decade. Now with a new vision for 2025.
• Vollverantwortliche Implementierung und kontinuierliche Steuerung der DORA-Anforderungen (Digital Operational Resilience Act) • Prüfung der IT-Landschaft auf Konformität • Sicherstellung einer verhältnismäßigen und effizienten Umsetzung von Sicherheitsmaßnahmen • Beratung der Geschäftsführung zu strategischen Risiken und aktives Stakeholder-Management zur Abwehr unbegründeter Anforderungen
• Enhances CISO team accomplishments and competencies by planning the delivery of resilient cyber solutions and answering technical questions. • Plans, research, and designs RMF, CSF and Zero Trust architectures for our federal clients. • Updates job knowledge by tracking and understanding emerging executive orders (EO14028), security practices and standards, participating in federal opportunities, reading professional publications, and participating in professional organizations. • Develop relationships and pursue opportunities for Alpha Omega’s growth and inclusion on technically transformative efforts for US federal agencies. • Formulate partnerships with key technology and services providers to pursue related opportunities. • Participate in the proposal development, innovative technical content development and color reviews. • Attend industry/community events to increase awareness of Alpha Omega’s capabilities especially Cybersecurity COE services. • Develop and deliver proof of concept, customer demos, presentations, and white papers • Coordinate with various teams and stakeholders as required. • Lead technical teams to develop innovative mission cybersecurity solutions across multiple environments – on-prem, cloud and mobile. • Act as Cyber Security Liaison for leadership team, Client Services, Partners and Customers • Maintain acute awareness of government Cybersecurity standards, laws, guidance from key US federal agencies. • Help with sales support • Work with Cybersecurity Tools • Support the Cybersecurity Capabilities Unit




