Job Closed
This listing is no longer active.
STERIS is a highly reputable organization that focuses on Quality and Safety, with: $5 billion global organization that has grown organically and through acquisition. Approximately 17,000 associates worldwide, including over 4,000 customer-facing field-based professionals. Opportunities for career advancement within the US and globally.
Cybersecurity Compliance Analyst
Location
EST (UTC-5) + 1 moreAll locations: EST (UTC-5) | CST (UTC-6)
Posted
20 days ago
Salary
$79.7K - $93.8K / year
Seniority
Mid Level
Job Description
Cybersecurity Compliance Analyst
Steris Corporation
Role Description As the Cybersecurity Compliance Analyst you will support and strengthen the organization’s cybersecurity, governance, risk, and compliance initiatives. You will play a critical part in representing STERIS Digital Workflow Solutions systems, infrastructure, cloud environments, client data, and operational integrity while supporting compliance with frameworks such as NIST, SOC 2, FedRAMP, related security standards, and ensuring systems meet customer security and regulatory requirements. You will collaborate closely with the Legal, Compliance, Leadership, and all Development teams to: - Monitor security posture - Audit readiness - Manage risk-related activities - Coordinate compliance initiatives - Respond to Customer technical & security questionnaires The position requires a blend of technical understanding, analytical thinking, documentation management, and communication skills. This is a fully remote role with preference for qualified candidates living in Eastern and Central time zones. Qualifications - Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field - 2+ years experience in the following: - Networking basics (TCP/IP, DNS, firewalls) - Operating systems (Windows & Linux) - Basic scripting (Python, PowerShell, or Bash) - Threats & vulnerabilities - Risk management principles - Identity and access management (IAM) - Encryption basics - Experience with SIEM tools (e.g., Splunk, QRadar), Antivirus/endpoint protection, Vulnerability scanners (e.g., Nessus) - Preferred: - Hands-on labs (TryHackMe, Hack The Box) - Knowledge of cloud security (AWS/Azure basics) - Familiarity with compliance frameworks (NIST, ISO 27001) - CompTIA Security+ preferred Requirements - Maintain strong operational alignment with security and compliance frameworks including NIST, SOC 2, and FedRAMP - Ensure audit preparation activities, evidence collection, and compliance reporting are completed accurately and on schedule - Improve and maintain vendor risk management and third-party security review processes - Maintain accurate security documentation, procedures, questionnaires, and internal records - Support the company’s long-term cybersecurity maturity goals and compliance initiatives - Collect, organize, validate, and maintain evidence required for audits, assessments, and security reviews Benefits - Market Competitive Pay - Extensive Paid Time Off and (9) added Holidays - Excellent Healthcare, Dental and Vision Benefits - Long/Short Term Disability Coverage - 401(k) with a company match - Maternity and Paternity Leave - Additional add-on benefits/discounts for programs such as Pet Insurance - Tuition Reimbursement and continued education programs - Excellent opportunities for advancement in a stable long-term career - Pay range for this opportunity is $79,687.50 - $93,750 - This position is eligible for bonus participation
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Support cybersecurity engineering for the pilot, including cloud security, RMF/ATO support, compliance documentation, and continuous monitoring. • Secure AWS-based environments through identity and access management, encryption, logging, monitoring, network security, vulnerability management, and configuration hardening. • Configure, monitor, and support AWS security services such as AWS Network Firewall, Security Hub, GuardDuty, CloudWatch, CloudTrail, Inspector, and related capabilities. • Support security planning for an AWS Commercial Cloud environment with consideration for future migration to AWS GovCloud or another VA-approved hosting environment. • Assist with ATO planning, control implementation, evidence collection, compliance reporting, and approval workflows. • Work within eMASS, ServiceNow GRC, or similar risk management systems to support ATO artifacts, information assurance tasking, POA&M tracking, and security documentation. • Develop and maintain SSPs, POA&Ms, SOPs, risk assessments, control narratives, security diagrams, and remediation plans. • Support vulnerability assessments, DISA STIG hardening, configuration compliance reviews, remediation tracking, and audit readiness activities. • Integrate security requirements into architecture, sprint planning, CI/CD processes, testing, and deployment readiness. • Support security reviews for VIA platform capabilities, including data handling, access control, auditability, secure integration, and AI-enabled modernization workflows. • Collaborate with technical and non-technical stakeholders to translate security requirements into practical engineering, documentation, and compliance actions.
Cyber Security SME
9th Way InsigniaServing the federal government with courage, integrity, and excellence.
• Provide expert cybersecurity guidance across enterprise systems, cloud environments, applications, networks, and mission platforms. • Lead the development and implementation of innovative cyber defense strategies that improve detection, prevention, response, and recovery capabilities. • Assess current cyber defense posture and recommend practical, scalable improvements aligned with mission, business, and regulatory requirements. • Design and support implementation of layered defense models, including Zero Trust, endpoint protection, identity-based security, network segmentation, encryption, threat monitoring, and secure cloud controls. • Evaluate emerging cybersecurity technologies, tools, and methodologies to determine applicability, maturity, risk, and operational value. • Support development of cybersecurity roadmaps, implementation plans, maturity models, and modernization strategies. • Advise leadership on cyber risk, threat trends, security gaps, mitigation strategies, and investment priorities. • Collaborate with technical teams, program managers, architects, engineers, system owners, and business stakeholders to integrate security into planning, development, operations, and sustainment activities. • Support security assessments, risk assessments, authorization activities, audits, and compliance reviews. • Provide expertise in federal cybersecurity frameworks and standards, including NIST, RMF, FISMA, FedRAMP, CMMC, CIS Controls, and Zero Trust guidance. • Recommend automation, analytics, artificial intelligence, machine learning, and security orchestration approaches to improve cyber defense effectiveness. • Support incident response planning, tabletop exercises, root cause analysis, and lessons-learned activities. • Develop cybersecurity policies, procedures, playbooks, technical guidance, briefings, and executive-level decision materials. • Mentor junior and mid-level cybersecurity staff and promote knowledge sharing across technical teams. • Identify opportunities to reduce risk, improve efficiency, strengthen resilience, and advance the organization’s cyber maturity. • This position may perform other duties as assigned. The responsibilities listed above are representative and not intended to be all-inclusive.
Cybersecurity Engineer – AI Risk and Governance
Vantage Data CentersExperience | Scalability | Efficiency By Design
• Perform technical security testing and reviews of AI‑enabled applications, agents, and workflows • Implement approved security architecture patterns for AI, ML, and LLM systems across cloud, hybrid, on‑prem, and OT‑adjacent environments • Engineer secure inference paths, APIs, service identities, authentication flows, and segmentation boundaries aligned with least privilege and zero trust principles • Implement technical safeguards to mitigate prompt injection, unauthorized context expansion, data leakage, hallucination risk, and unsafe output handling • Configure and maintain controls for limiting, monitoring, logging, and managing AI usage across platforms, models, and agents • Implement and validate technical controls supporting model explainability, traceability, and output validation where AI impacts operational, workforce, safety, or compliance decisions • Review and validate LLM usage patterns, including prompt design, retrieval‑augmented generation (RAG), context window constraints, and output handling mechanisms • Implement controls preventing unauthorized external model training, reuse, or retention of enterprise data by third‑party AI platforms • Validate encryption, access logging, retention, and deletion controls for data ingested, processed, or generated by AI systems • Execute AI‑specific threat modeling activities and contribute findings to enterprise and OT cybersecurity risk assessments • Ensure AI systems produce security telemetry, logs, and audit trails sufficient to detect misuse, drift, policy violations, or anomalous behavior • Integrate AI security signals into SOC, SIEM, and incident response tooling and workflows • Support investigation and response to AI‑related incidents, including data exposure, model failure, unsafe outputs, or control breakdowns • Conduct technical security reviews of vendor‑provided and embedded AI capabilities, assessing model behavior, data handling, and control alignment • Enforce approved security requirements for AI vendors and prevent activation of AI features without required security validation and governance approval • Drive alignment with ISO 42001 and related AI governance standards across applicable teams
• Triage, investigate, and respond to alerts across the SOC queue, hitting SLAs and following playbooks • Lead incident investigations, gather evidence, correlate events, and coordinate containment and recovery • Build and tune AI-assisted and agentic workflows across SIEM, SOAR, and EDR, including Claude via API • Engineer detection content: rules, queries, and alert tuning mapped to MITRE ATT&CK • Write and maintain SOAR playbooks and automation scripts that cut manual toil and accelerate response • Hunt for threats proactively, forming and testing hypotheses against current adversary TTPs • Maintain the SOC technology stack: integrations, health, and content engineering across all platforms • Keep SOX and SOC 2 Type 2 audit-ready evidence: logging coverage, incident records, and procedures • Partner with IT, Cloud, Risk, and Compliance to embed telemetry and surface findings clearly



