IT GRC Analyst Level II
Socket.dev
Description Position Overview The IT GRC Analyst (CMMC Control Specialist) is responsible for the daily monitoring, operational testing, and ongoing compliance analysis of the organization’s cybersecurity controls. Rather than developing high-level enterprise security policies, this operational role focuses on hands-on control execution, reviewing technical logs, verifying evidence, and authoring, maintaining, and updating granular Standard Operating Procedures (SOPs). This position ensures that hybrid IT environments, cloud enclaves, and technical infrastructure continuously satisfy CMMC Level 2 and NIST SP 800-171 requirements through standardized, repeatable processes.Key Responsibilities Key Responsibilities SOP Development, Maintenance & Operationalization: Draft, review, and continuously refine detailed Standard Operating Procedures (SOPs) that translate complex NIST SP 800-171 controls into step-by-step technical workflows for IT staff. Audit operational practices regularly to ensure procedural alignment with active SOPs, updating documentation whenever technical environments or baseline configurations evolve. Maintain the centralized repository of GRC SOPs, work instructions, and execution templates, ensuring version control and strict alignment with the enterprise System Security Plan (SSP). Partner with System Administrators and IT Operations to convert POA&M remediation outcomes into formalized, repeatable SOPs to prevent recurring compliance gaps. Daily Control Monitoring & Evidence Analysis Perform daily, weekly, and monthly operational reviews of technical controls across all 14 NIST SP 800-171 practice domains (e.g., auditing SIEM logs, validating MFA enforcement, and reviewing access requests) in accordance with established SOPs . Collect, inspect, and archive technical artifacts and evidence (configuration baselines, backup logs, patch records) to maintain continuous audit readiness. Identify, document, and report control drift or non-compliance issues across hybrid Active Directory, cloud environments (GCC High/Azure), and virtualization platforms. Execute recurring internal control tests to verify that technical safeguards operate as documented in the SSP and procedural guidelines. Risk Tracking & POA&M Execution Track and validate the daily progress of remediation items listed on the active Plan of Action & Milestones (POA&M). Collaborate directly with System Administrators and IT Operations to test and verify fixed items before closing out open POA&M entries. Monitor daily CUI flow paths and enclave access logs to verify that Controlled Unclassified Information (CUI) boundary controls remain strictly enforced. Conduct routine vendor risk checks, verifying that subcontractors maintain active compliance with DFARS View phone number on click.appcast.io / 7020 flow-down requirements. Audit Support & Reporting Analyze compliance data to support regular SPRS score updates and internal readiness reporting. Serve as the primary hands-on evidence and procedural coordinator during internal compliance reviews, DIBCAC audits, and external C3PAO assessments. Generate weekly operational risk metrics, process execution logs, and gap analysis reports for the IT Security Manager. Qualifications & Requirements Experience: 2–4+ years of hands-on experience performing IT compliance monitoring, internal auditing, procedural documentation, or security control testing in a DoD/DFARS environment. Documentation & SOP Skills: Proven ability to author clear, step-by-step technical Standard Operating Procedures (SOPs), system administration guides, and audit-ready control execution logs. Framework Knowledge: Direct experience monitoring and analyzing controls under NIST SP 800-171 , CMMC Level 2 , and DFARS View phone number on click.appcast.io . Technical Familiarity: Practical experience inspecting control evidence within Active Directory / Entra ID, Microsoft 365 / GCC High, firewalls, SIEM platforms, and hypervisors. Education: Bachelor’s Degree in Cybersecurity, Information Systems, or equivalent practical technical experience. Preferred Certifications CMMC / Compliance: CCP (CMMC Certified Professional) or CISA. General Security: Security+, Network+, or SSCP. #J-18808-Ljbffr Socket.dev
- ...seeking a Senior Cybersecurity Governance Analyst to support their Cybersecurity Strategy &... ...individual will partner with leaders across IT and the business to maintain, improve, and... .... This role is ideal for a senior-level professional who can operate independently...Suggested
$73.8k - $132.7k
Join to apply for the IT Portfolio Management Analyst II role at Centene Corporation You could be the one who changes everything for our 28 million... ...Analyzes project risk profile and balance at the portfolio level Contributes to capacity planning for initial and ongoing...SuggestedFull timePart timeWork at officeRemote workFlexible hours- Socket.dev is seeking an IT GRC Analyst (CMMC Control Specialist) to monitor, test, and analyze compliance of cybersecurity controls in hybrid IT environments. You will review logs, verify evidence, and author detailed SOPs to ensure adherence to NIST SP 800-171 and DFARS...Suggested
- ...collaborative environment. Join our Technology Team as an IT Risk and Compliance Analyst located in our Miramar office. We are seeking a professional... ...skills, with the ability to interact effectively at all levels of the organization from analyst level to C‑suite Explain...SuggestedWork experience placementWork at office
- ...Job Overview We’re looking for an entry‑level Financial Data Analyst who’s passionate about transforming financial numbers into clear insights that support budgeting, forecasting, and operational decision‑making. You’ll work closely with senior analysts, finance teams...SuggestedFull time
- Westinghouse Electric Company LLC is looking for a Business Analyst Level 2 for a 10-month contract. You will support the Business Management Portfolio Services Compliance team, ensuring compliance with contractual obligations and ISO standards. Your role includes monitoring...Contract work
- RK Infotech LLC in Florida is hiring a Business Analyst (Fresher / Entry-Level | 0-5 Years). The role is ideal for fresh graduates who want to learn how data drives business decisions, with opportunities to work on real business data from academic or internship projects...Internship
- ...Senior Cybersecurity Governance Analyst to support their Cybersecurity... ...partnering with leaders throughout IT and the business to maintain,... ...ideal opportunity for a senior-level cybersecurity governance... ...experience in Cybersecurity Governance, GRC, Cyber Risk, Security...
- A financial analytics firm is seeking an entry-level Financial Data Analyst to transform financial data into insights for decision-making. You will work with finance teams to collect and analyze datasets, build reports, and help identify trends. The ideal candidate has...
- ...or an alternative application process. Analyst, Helpdesk II Full Time IT Doral, FL, US 13 days ago... ...Title: Analyst, Helpdesk II Department: IT Position Summary: The Help Desk Analyst... ...at a more advanced or oversight level Monitoring help desk metrics and SLAs, and...Permanent employmentFull timeWork experience placementWork at officeRemote workShift work
- ...inputs for governance committees, ORM, senior management, and Board-level audiences Review executive and Board-level reporting materials... ...4–6 years of experience in cybersecurity risk, technology risk, GRC, risk analytics, metrics reporting, or data governance Strong analytical...
$16 - $17 per hour
A non-profit organization is looking for a Compliance Specialist to join their team. This fully remote entry-level position involves analyzing validation documents to determine eligibility for scholarships. Strong attention to detail and a great work ethic are essential...Hourly payContract workRemote work- ...inputs for governance committees, ORM, senior management, and Board-level audiences Review executive and Board-level reporting materials... ...4-6 years of experience in cybersecurity risk, technology risk, GRC, risk analytics, metrics reporting, or data governance Strong analytical...
- ...data quality, and governance reporting. You will maintain the metric inventory, ensure data lineage, and validate evidence for board-level audiences. The role emphasizes advanced analytics, KPI development, and cross-functional collaboration with risk owners to improve...
- Greenberg Traurig, LLP seeks an IT Risk and Compliance Analyst located in Miramar for a hybrid role. You will lead the third-party risk management program, performing assessments and collaborating across teams to enhance security protocols. The ideal candidate has a degree...
- ...: The Cybersecurity Governance Analyst III is a key member of the Cybersecurity... ..., and improve governance, GRC, security awareness, and... ...cybersecurity governance, GRC, IT governance, process improvement... ...scorecards, and leadership or executive‑level reporting. Preferred...
- BNY is seeking a Specialist, Market/Client Risk Management II to join the Depositary Receipts team in Lake Mary, FL. The role focuses on routine corporate action events with support for moderately complex transactions. The ideal candidate holds a finance-related bachelor...Work experience placement
- ...Fraud Investigator II – Accounting & Finance, Vaco Overview We are seeking a Fraud Investigator II to join our Corporate Fraud Investigations... ..., or CFCS; previous banking experience. Job Details Seniority level: Mid-Senior level Employment type: Full-time Job function:...Full time
- ...building secure IoT firmware and ensuring the SDLC meets EU cybersecurity requirements while supporting OTA updates. You will bridge low-level development, security architecture, and compliance with a team, driving secure-by-design practices, vulnerability handling, and...
$65.15k
...54 Agency: Department of Transportation Working Title: CONTRACT ANALYST II - 55012005 Pay Plan: SES Position Number: 55012005 Salary: $65,1... ..., and manage updates and addenda through the Vendor Bid System. It supports the Turnpike Enterprise’s contract program by preparing...Full timeContract workFor contractorsWork at office- Summary The position is responsible for performing confidential research and investigations of money laundering and other financial crimes. ESSENTIAL DUTIES AND RESPONSIBILITIES Monitor all aspects of client relationships and conduct customer due diligence and enhanced...
- ...site at our Sunrise offices, you will work side-by-side with our analysts and leadership to solve the problem of "information overload,"... ..., business intelligence, or information design.* Expert-level proficiency in leading BI tools (e.g., Tableau, Amazon QuickSight...Full timeWork at officeRemote workFlexible hoursNight shift
- ...during a subsequent face‑to‑face encounter. Review the encounter level patient medical record and provider selected ICD-10-CM diagnosis... ...confidentiality and adhering to ethical coding standards. Level II (in addition to minimum qualifications) Minimum of two (2) years...
- BankUnited in the United States seeks an AML/BSA analyst to review account activity, analyze suspicious activity, and prepare regulatory reports to ensure compliance with the Bank Secrecy Act. The role involves using the Actimize AML monitoring system and coordinating with...
$75k - $110k
...and verbal) Discretion when handling confidential information Seniority Level Entry level Employment Type Part‑time Job Function General Business and Analyst Industries Accounting Lake Mary, FL $75,000.00 - $110,000.00 | 6...Part timeWork at officeRemote work$99.2k - $138.88k
Blue Origin LLC is seeking a Structural Analyst II in the Town of Florida, NY, to support the Lunar Permanence business unit by developing safety and reliability protocols for spacecraft cargo delivery systems. This role involves solving structural problems, performing...- ...experience with Microsoft Server and an interest in Healthcare IT? Do you have strong skills in customer service,... ...clients and the patients they serve. POSITION SUMMARY The Analyst position is an entry level position to learn and increase skills around the ITIL and...Work experience placementWork at office
- ...understanding of global regulations relevant to medical devices, Class II and/or Class III devices Solid knowledge and understanding of... ...Ability to interact professionally with all organizational levels Ability to manage competing priorities in a fast paced environment...Work at office
- Mosaic Health, LLC. is seeking a Compliance Auditor II to execute audit procedures, review documents, test controls, and draft findings. This professional will support audit planning, maintain thorough work papers, and monitor corrective actions under supervision. Qualification...Work at office
- ...and/or the banking industry to ensure firm policies and procedures are designed and operating as intended and commensurate with the level of risk being mitigated. Oversees a team of testers performing large or multiple testing projects with significant scope and impact...Temporary workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT GRC Analyst Level II. Be the first to apply!
- entry level computer information technology Florida, NY
- it risk analyst Florida, NY
- IT delivery manager Florida, NY
- IT lead Florida, NY
- information technology consultant Florida, NY
- senior director it Florida, NY
- it operations coordinator Florida, NY
- IT network Florida, NY
- information technology graduate Florida, NY
- IT coordinator Florida, NY

