Security & Compliance Analyst

Nalley Consulting

$75K — $95K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, or related field, or 5+ years of relevant experience.
  • Expertise in DoD identity governance policies and cybersecurity best practices.
  • Strong knowledge of NIST 800-53 Rev. 5, FedRAMP, and Risk Management Framework guidelines.
  • Proficient in compliance tools such as Microsoft Purview, AWS Security Hub, Nessus, or Splunk Enterprise Security.
  • Experience with security assessments and documentation like SSPs and SARs.

Responsibilities

  • Ensure compliance with cybersecurity regulations and best practices.
  • Conduct security assessments to verify adherence to federal security mandates.
  • Maintain documentation to support Authority to Operate processes.
  • Oversee security controls in identity access management and data protection.
  • Produce comprehensive compliance and audit reports that document security findings.

Benefits

  • Excellent medical, dental, and vision benefits.
  • Paid time off (PTO) and 11 paid federal holidays.
  • Tuition assistance for continued education.
  • Paid military-reserve leave and parental leave for birth or adoption.
  • 401(k) matching up to 5% of salary and flexible work hours.
  • Company-paid short-term and long-term disability, and life insurance.
Full Job Description
Position: Security & Compliance Analyst
LCAT: Mid
Location: SOUTHCOM HQ, Doral, FL / On-site
Office: U.S. SOUTHERN Command J2

Required clearance: TS/SCI

Required education: Bachelor's degree in Cybersecurity, Information Assurance, or a related field, or five (5) years of equivalent experience in security compliance analysis.

Description:
  • Ensure compliance with DoD identity governance policies, regulatory frameworks, and cybersecurity best practices.
  • Conduct security assessments and audits to verify adherence to NIST 800-53 Rev. 5, FedRAMP, DoD IL-4/IL-5 security mandates, and Risk Management Framework (RMF) guidelines.
  • Maintain System Security Plan (SSP), Security Assessment Reports (SAR), and other documentation supporting the Authority to Operate (ATO) process.
  • Provide oversight of security controls related to IAM, data protection, and cloud security configurations.
  • Produce the Security Compliance & Audit Report, documenting compliance gaps, remediation actions, and assessment results.
Required Experience:
  • Possess the knowledge and capability to assess, implement, and monitor security compliance frameworks across cloud and hybrid environments, ensuring adherence to FedRAMP, NIST 800-53 Rev. 5, DoD RMF, and Zero Trust security principles.
  • Proficient in security risk assessment, compliance reporting, and vulnerability remediation strategies.
  • Demonstrated experience in conducting security assessments, preparing compliance documentation (SSPs, POA&Ms), and ensuring regulatory adherence for cloud and hybrid infrastructures. Proficiency with compliance tools such as Microsoft Purview, AWS Security Hub, Nessus, or Splunk Enterprise Security is required.
Desired Qualifications:
  • Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or CompTIA Security+.


Nalley Consulting fringe benefits include:
  • Excellent medical, dental, and vision benefits
  • PTO
  • 11 paid federal holidays
  • Tuition assistance
  • Paid military-reserve leave
  • Paid parental leave for birth or adoption
  • 401k matching up to 5 percent of the base salary
  • Flex time
  • Company-paid short-term disability, long-term disability, and life insurance.

Similar Jobs

More Jobs at Nalley Consulting

More Aerospace & Defense Jobs

Find similar Security & Compliance Analyst jobs: