Senior Cybersecurity GRC Analyst
AMRO Fabricating Corporation
Job Description
Job Description
Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies’ core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.
This role helps drive enterprise-wide cybersecurity governance, risk, compliance, and assurance activities that strengthen control quality, evidence readiness, and risk management across Karman. You will translate regulatory, contractual, and customer requirements into clear controls and reliable evidence; independently assess control effectiveness and risk; and partner with business and technology owners to embed sustainable practices that support audit, assessment, and operational readiness.
Responsibilities
- Interprets and operationalizes cybersecurity, regulatory, contractual, and customer requirements with business, legal, and technology stakeholders.
- Maintains cybersecurity governance artifacts including policies, standards, control documentation, mappings, ownership records, and assurance schedules.
- Evaluates control design, operating effectiveness, evidence sufficiency, exceptions, and residual risk and recommends corrective actions or escalation.
- Supports sustainable CMMC Level 2, NIST SP 800‑171, DFARS, and Controlled Unclassified Information (CUI) obligations through assessment, evidence validation, remediation, and monitoring.
- Maintains the Enterprise System Security Plan (SSP), Controlled Site Addenda, system boundaries, inventories, and supporting evidence across regulated environments.
- Coordinates contractual, regulatory, and CAGE-code traceability, ensuring accurate alignment among obligations, boundaries, sites, and assessment records.
- Supports Sarbanes‑Oxley (SOX) Information Technology General Controls (ITGC) through narrative development, testing coordination, evidence quality, exception identification, and remediation tracking.
- Governs cybersecurity risks, exceptions, remediation plans, compensating controls, and acceptance records and prepares leadership-ready materials that translate issues into decisions and business impact.
- Oversees identity, access, and vulnerability governance, including coverage, aging, remediation performance, exceptions, and validation of closure across responsible teams.
- Coordinates cybersecurity reviews for third-party services, Software-as-a-Service (SaaS), artificial intelligence (AI) tools, suppliers, and M &A activities, ensuring security, privacy, data-handling, and evidence requirements are met.
Required Qualifications
- Bachelor’s degree in cybersecurity, information technology, information systems, business, risk management, accounting, audit, or a related field; equivalent relevant experience may be considered.
- 5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.
- Experience assessing control design, operating effectiveness, and evidence sufficiency and translating findings into practical remediation and leadership reporting.
- Working knowledge of CMMC Level 2, NIST SP 800‑171, DFARS, CUI, SOX ITGC, or comparable regulated control environments.
- Experience maintaining cybersecurity policies, control narratives, SSPs or equivalent system documentation, evidence repositories, risk registers, Plans of Action and Milestones (POA &Ms), and remediation trackers.
- Ability to exercise independent judgment, challenge unsupported conclusions, organize complex requirements, and escalate material risk appropriately.
- Strong written, analytical, presentation, and stakeholder-management skills across technical teams, business owners, auditors, assessors, vendors, sites, and executives.
- Proficiency with Microsoft 365 tools, including Excel, PowerPoint, Word, Teams, SharePoint, and Outlook.
Preferred Qualifications
- Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
- Experience supporting CMMC Level 2 readiness, NIST SP 800‑171 assessments, DFARS compliance, CUI governance, Supplier Performance Risk System (SPRS) requirements, or defense‑contractor cybersecurity needs.
- Experience with SOX ITGC, internal or external audit, control testing, information technology risk, and remediation governance.
- Experience with SSPs, site-specific control documentation, specialized‑asset scoping, CUI flows, system boundaries, evidence validation, and POA &M management.
- Experience with supplier cyber risk, SaaS and AI governance, M &A due diligence, international operations, export controls, or cross-border access risk.
- Experience using Governance, Risk, and Compliance (GRC) or audit platforms such as ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, or Hyperproof.
- Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Governance, Risk and Compliance (CGRC), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Cybersecurity Maturity Model Certification Certified CMMC Professional (CMMC CCP), or comparable certification.
This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.
Benefits
- Medical, dental, and vision insurance
- 401(k) with company match
- Paid time off
- Health Savings Account (HSA) with company contribution
- Flexible Spending Accounts (FSA)
- Company‑paid life and AD &D insurance
- Short‑ and long‑term disability coverage
- Tuition reimbursement
Karman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.
$135k - $143k
...,000/year Work Location: Remote with occasional on-site work in Washington, DC, at least once per month. The Senior Cybersecurity Analyst leads in the proactive defense of the organization's information systems. This role provides expert-level guidance on cybersecurity...SeniorFull timeContract workCasual workRemote workFlexible hours- ...Senior Cybersecurity Analyst Trident Technologies and Consulting - Global, LLC (d.b.a. T2C-Global) is currently seeking motivated and talented individuals who can offer the knowledge, skills, and experience to support the United States Navy, NAVSEA HQ in administrating...SeniorContract workFor contractorsWork at officeFlexible hours
$130k
...Overview Senior Cybersecurity Analyst LOCATION: Washington DC - Navy Yard JOB STATUS: Full-time CLEARANCE: Secret CERTIFICATION: DoD 8140 IAT Level II TRAVEL: As Needed SALARY RANGE: Estimated $130,000+ USD Annually* *depending on experience...SeniorFull timeFlexible hours$105k - $200k
...clients across the Federal government, from senior level policy makers to program managers,... ...of a mix of junior and mid-level analysts who will look to you for technical acumen... ...& Responsibilities Provide cybersecurity expertise to surface combat system program...SeniorWork at office- ...Senior Cybersecurity Analyst TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection...SeniorFull timeWork experience placementShift work
- ...Senior Cybersecurity Analyst OCH Technologies is seeking a Senior Cybersecurity Analyst to execute independent risk assessments and vulnerability assessments at FAA facilities. Candidate should be based at one of three FAA hub locations (Oklahoma City, Atlantic City...SeniorTemporary workFor contractorsLocal area
$127k - $138k
Job Location: Washington D.C., DC 20376. Position Type: Full Time. Salary Range: $127,000.00 - $138,000.00. Title: Cybersecurity Analyst V (Senior). Clearance Type: Secret with the ability to obtain a Top Secret. Responsibilities Lead RMF lifecycle execution: Develop, manage...SeniorFull time$77.6k - $176k
Phase2 Technology is seeking a Cybersecurity Compliance Analyst to design and manage policies ensuring software and database security. The role requires extensive experience in compliance analysis and the ability to communicate cybersecurity posture effectively. Responsibilities...Senior- ...Job Description Job Description Description: RMC is seeking a Senior OT Cybersecurity Analyst for a full-time hybrid position in San Diego CA, Washington D.C. or Norfolk VA! Are you ready to embark on a fulfilling and impactful career journey with Risk Mitigation...SeniorFull timeContract workTemporary workWork at officeLocal areaFlexible hours
- A decision analytics firm is seeking a Senior Analyst in Arlington, VA, to provide cybersecurity expertise and lead Risk Management Framework processes. The ideal candidate will have a Bachelor's degree in Cybersecurity Management and at least 10 years of direct experience...Senior
- Booz Allen Hamilton is seeking a Cybersecurity Analyst and Systems Administrator to safeguard joint staff mission systems and comply with RMF/ATO processes across DoD networks. The role supports Zero Trust initiatives, vulnerability remediation, and security documentation...Senior
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team... ...Archer, CSAM, or Telos XactaAbility to engage and influence senior and executive leadershipAbility to use a strong analytical...Full timeContract workPart timeWork at officeLocal areaRemote work$117.2k - $176.7k
...to own the area of responsibility with minimal guidance from senior team members. You should innovate, challenge the status quo, embrace... ...:Minimum 4 years of experience in information security, cybersecurity, accreditation, and other security related areasExperience working...SeniorFull time$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing... ...metrics and KPIs to other operational teams and senior leadership.Join us. The world can't wait.You Have:4+ years...SeniorFull timeContract workPart timeWork at officeLocal areaRemote work$110k - $120k
As Sr. Cybersecurity Analyst II, you’ll Provides a wide array of Information Technology (IT) oriented services to its 4,000 customers. These services include: incident and request support; conducting program analysis and studies; developing, operating, and maintaining IT...SeniorFull timeLocal area$113k - $188k
...Clearance Required:Active SecretGuidehouse is seeking a Senior Consultant to join its Cyber Team - Cybersecurity Risk Assessment Consultant. The Senior Consultant... ....Provide expert guidance to system owners, analysts, and leadership on cybersecurity risk best practices...SeniorFull timeWork at officeFlexible hours- ...Services, Transportation, Federal and State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian Seeks a Senior Cyber Security Specialist (SCA Code: -) in CONUS - Mid Atlantic Washington Metropolitan Area (Northern Virginia | Washington DC |...SeniorFull timeTemporary workFor contractorsWork at officeFlexible hours
$108k - $140k
...clients. We are looking for people who are willing to share ideas and work as part of a collaborative, innovative team.The Senior Cybersecurity and Compliance Consultant (Federal Programs) supports complex technology programs with our clients and oversees, manages, tracks...SeniorContract workLive inWork at officeRemote workFlexible hours- ...Senior Cybersecurity Analyst (Artificial Intelligence) We are seeking up to two Cybersecurity Analysts with experience implementing artificial intelligence (AI) for computer network defense including intrusion detection, prevention and incident response activities....SeniorLocal area
- ...Description Benefits: ~401(k) matching ~ Dental insurance ~ Health insurance ~ Paid time off ~ Vision insurance Senior Cybersecurity Advisor Position Overview The Senior Cybersecurity Advisor provides strategic cybersecurity leadership and guidance...SeniorContract work
- ...leave. There are many more - connect with us to get a preview of the full benefits package. Position Title: Senior Cyber-Security Analyst / Navy Validator Location: Onsite in Arlington, VA Duties & Responsibilities: Provides Information Assurance...SeniorWork at officeImmediate start
- ...Job Description Job Description Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics solution. This role will focus...SeniorFor contractors
- ...experience working in a Security Operations Center and exceptional written communication skills.Must possess one or more relevant cybersecurity certification such as CISSP, CEH, GCIH, GCIA, or other SANS certifications.Position requires a Bachelor’s Degree and 7+ years...Immediate start
$104k - $166k
ResponsibilitiesPeraton is currently seeking a Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or Washington DCRole and Responsibilities... ....QualificationsRequired: Bachelor’s degree in Cybersecurity, Information Technology, or related field. An additional...SeniorContract workShift work$77.6k - $176k
Cybersecurity Compliance AnalystThe Opportunity:Designs, implements, and manages policies and procedures to ensure database and software security... ...concisely communicate cybersecurity posture information to senior department leadership through verbal, written, and visual...Full timeContract workPart timeWork at officeLocal areaRemote work$86k - $138k
Responsibilities Peraton is currently seeking to hire a Cybersecurity Analyst - Security Standards & Baselines to become part of our Federal... ...to both technical and non-technical stakeholders, including senior leadership.Perform extensive research, analysis, and...Contract workCurrently hiringWork at officeShift work$100k - $130k
GovCIO is currently hiring a Journeyman Cybersecurity Analyst to support Information Assurance (IA) and Information System Security Officer (ISSO) activities for the U.S. Coast Guard (USCG). This technical role focuses on maintaining cybersecurity posture, managing vulnerability...Currently hiring$31 - $48 per hour
Worker TypeRegularJob DescriptionSummaryAV is seeking a motivated, detail-oriented Information Security Analyst. In this role, you will work with the Cybersecurity team on a variety of Information Security tasks, to include software vetting, compliance documentation, exception...Permanent employmentFull timeContract workWork experience placementFlexible hours- ...Risk Analyst The Risk Analyst is responsible for providing guidance on tools to measure and manage risk, identify/mitigate threats... ...candidates will assist in ensuring effective execution of cybersecurity strategies and our risk management framework by managing relationships...Work experience placement
$70k - $85k
Cybersecurity Operations Consultant - Senior Associate Job Summary: Lafayette Group is seeking qualified and team-oriented individuals to work with federal government organizations in support of national cybersecurity programs. The Cybersecurity Operations Consultant is...SeniorContract workWork at officeLocal areaFlexible hours2 days per week1 day per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cybersecurity GRC Analyst. Be the first to apply!
- cyber security specialist Washington DC
- cyber security consultant Washington DC
- senior cybersecurity analyst Washington DC
- senior network engineer remote Washington DC
- senior app developer Washington DC
- senior manager legal Washington DC
- senior retail sales associate Washington DC
- sr project manager Washington DC
- senior account executive Washington DC
- senior manager strategic initiatives Washington DC



