RVC
JobsFor Employers
  1. Jobs
  2. /
  3. Middle Information Security Compliance Analyst

Middle Information Security Compliance Analyst

drc | Education and assessment services
1h 11m ago
On-site
Full Time
IC
United States of America

Title: Information Security Compliance Analyst

Location: Maple Grove, MN, USA

Information Security Compliance Analyst

Data Recognition Corporation - Minnesota

Please No Agencies

Company cannot provide sponsorship for this position          

Summary:

This position is part of the Data Recognition Corporation (DRC) Information Security Team that has an important role in the defining and enabling the secure operation of the DRC environment. This position has responsibility for managing and leading various risk and compliance activities, including internal and external security reviews that are key to validation of our security program. 

This position also assists with other aspects of the security practice, including maintaining DRC’s security policies, standard and procedures; increasing the organizations security awareness; performing risk assessment and risk management activities; and promoting business continuity and resiliency efforts. 

Responsibilities:

This position will manage/lead a wide range of compliance and risk functions, with the focus being on maintaining and enhancing our compliance maturity.  Key responsibilities include:

Obtain and maintain GovRAMP compliance

Support Authority to Operate (ATO) approvals for government contracts by adherence to NIST Risk Management Framework (RMF)

Support cybersecurity efforts to include the development and management of System Security Plan (SSP) documentation, Plans of Action and Milestones (POAMs), assessing and auditing systems security controls, and continuous monitoring activities

Manage internal and external annual audits (third party and customer)

GovRAMP

ISO 27000 series

SOC II

Type 2

Various customer audits

Maintain and drive remediation on Plan of Action and Milestones (POAM) items

Policy and standard development and review

Mature security risk management practices

Manage and enhance Business Continuity/Disaster Recovery processes

Update and maintain security and compliance metrics

Essential Qualifications

3+ years of Information Security, GRC, audit, or compliance experience

Working knowledge in NIST 800-53 Rev 5 framework and how to implement and audit against the framework

General knowledge of the following:  Risk Management Framework (RMF), compliance with security technical implementation guides (STIGs), and documenting Plan of Action and Milestones (POA&M)

Experience managing SOC 2 Type II compliance audits

Possesses a high level of personal integrity and the ability to discreetly handle sensitive, personal, and classified information.

Must have excellent communication skills and the ability to work well in a team and across the organization, in addition to independently driving initiatives.

Preferred Qualifications

Four-year college degree in IT, Computer Science, Cybersecurity, or related fields

Internal or External Audit experience

Experience with GovRAMP or FedRAMP certifications

Experience with Federal Information Security Management Act (FISMA) leveraging National Institute of Standards and Technology (NIST) security controls (NIST 800-53, rev 5).

Security certification such as Certified Information Security Auditor (CISA) and/or Certified in Risk and Information Security Controls (CRISC)

Experience with ISO 27001 certification

Experience supporting and participating in third party vendor security assessments and audits, reviewing audit findings as well as responses to security findings and remediation plans.

Ability to manage cross-functional projects and initiatives as required. 

 Reporting to this position:  No direct reports

 The Employer retains the right to change or assign other duties to this position

Company cannot provide sponsorship for this position

Please, no agencies

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

 

Required Skills

nistsoc_2iso_27001

Required Languages

🇬🇧 English

Related searches

  • Jobs in USA
  • Mid-Level Jobs
1 jobs
Sort by
1h 11m ago

Middle Information Security Compliance Analyst

drc·Education and assessment services
nistsoc_2iso_27001
🏢On-site
|United States of America
General InfoSec
No similar jobs match these filters. Try changing or clearing a filter.
Popular job searches ▸
Roles
Python JobsJava JobsReact JobsTypeScript JobsGo JobsDevOps JobsNode.js JobsRemote C# and .NET JobsData Science JobsProduct Manager JobsDesign Jobs
Countries
United StatesUnited KingdomCanadaUS & EMEAGermanyPolandSpainNetherlandsPortugal
Experience
Senior JobsMid-Level JobsJunior Jobs
R© 2026 RVC Globalbuild 417e4888
AboutJobs in Claude & ChatGPTPricingContactPrivacyCookiesRefundsTerms & ConditionsFor Employers