Information System Security Compliance Analyst (Multiple Levels)
$78.9k - $123.3kNoblis
Responsibilities
Position Overview
We are seeking a detail-oriented cybersecurity compliance professional to support system authorization and continuous monitoring activities within a Federal environment. This role is responsible for managing the security authorization lifecycle for one or more information systems, ensuring compliance with Federal cybersecurity requirements, and maintaining the documentation necessary to support Authorization to Operate (ATO) decisions.
The ideal candidate will have experience working with NIST RMF, NIST SP 800-53 controls, security authorization packages, POA&M management, and compliance documentation. Candidates should be comfortable working with technical teams to assess control implementation, identify compliance gaps, and provide guidance to support remediation efforts and POA&M closure.
Key Responsibilities
Manage the security authorization lifecycle for one or more information systems in accordance with Federal Risk Management Framework (RMF) requirements.
Coordinate activities required to obtain and maintain Authorization to Operate (ATO) approvals.
Assess and track implementation of NIST SP 800-53 security controls and associated compliance requirements.
Develop, review, update, and maintain authorization package documentation, including:
System Security Plans (SSPs)
Security Assessment Reports (SARs)
Plan of Action and Milestones (POA&Ms)
Risk Assessments
Continuous Monitoring documentation
Security-related policies and procedures
Manage POA&M activities by tracking findings, monitoring remediation progress, validating corrective actions, and supporting closure efforts.
Provide technical guidance and compliance recommendations to system owners, engineers, administrators, and security stakeholders to facilitate POA&M remediation and closure.
Coordinate with technical teams to gather evidence supporting security control implementation and compliance requirements.
Review vulnerability scan results, assessment findings, and security documentation to identify compliance gaps and areas requiring remediation.
Support continuous monitoring activities by tracking security posture, compliance status, and ongoing control effectiveness.
Participate in security assessments, audits, and compliance reviews conducted by internal and external stakeholders.
Assist in the development of risk mitigation strategies and recommendations for addressing identified security weaknesses.
Track authorization milestones, compliance deadlines, and remediation activities to ensure timely completion.
Communicate compliance status, risks, findings, and recommendations to both technical and non-technical stakeholders.
Support audits and reporting activities related to Federal cybersecurity requirements and organizational security programs.
Required Qualifications
Experience supporting cybersecurity compliance, security authorization, risk management, or information security programs.
Experience working with the NIST Risk Management Framework (RMF).
Subject matter expertise with NIST SP 800-53 security controls and Federal cybersecurity compliance requirements.
Experience supporting the development, maintenance, or review of authorization package documentation, including SSPs, SARs, POA&Ms, and Risk Assessments.
Understanding of the Authorization to Operate (ATO) process and continuous monitoring requirements.
Experience tracking and managing POA&M findings through remediation and closure.
Ability to review technical security information and translate findings into compliance documentation and actionable recommendations.
Understanding of cybersecurity principles, security controls, vulnerability management, and risk management concepts.
Strong organizational skills with the ability to manage multiple systems, priorities, and compliance activities simultaneously.
Strong written and verbal communication skills, including the ability to develop and review formal security documentation.
Proficiency with Microsoft Office applications, particularly Excel, Word, and PowerPoint.
U.S. Citizen or Green Card Permanent Resident with a minimum of three (3) years of U.S. residency.
Ability to obtain and maintain an FAA Public Trust.
Education & Experience Substitutions
Substitutions are subject to government customer review and approval.
Mid to senior
Bachelor's degree in Cybersecurity, Information Technology, Telecommunications, or a related field.
9+ years of experience in cybersecurity or network security roles
Substitutions: For anything requiring a substitution, the government customer is subject to further review and either approve or deny the request.
A High School degree with a total of 15 years of experience in cybersecurity or network security roles
Masters degree with a total of 6 years of experience in cybersecurity or network security roles.
Compensation Ranges: for D.C., NJ, Remote: $78,900 - $123,300
Senior:
Bachelor's degree in Cybersecurity, Information Technology, Telecommunications, or a related field.
16+ years of experience in cybersecurity or network security roles
Substitutions: For anything requiring a substitution, the government customer is subject to further review and either approve or deny the request.
A High School degree with a total of 20 years of experience in cybersecurity or network security roles
An Associates Degre with a total of 18 years of experience in cybersecurity or network security roles
Masters degree with a total of 13 years of experience in cybersecurity or network security roles
Compensation Ranges: for D.C., NJ, Remote: $95,500 - $180,525
Desired Qualifications
Experience supporting federal government programs, preferably within the FAA, Department of Transportation, or other civilian federal agencies.
FAA or transportation sector experience preferred.
Experience serving as an Information System Security Officer (ISSO), Security Control Assessor (SCA), Information System Security Manager (ISSM), or similar cybersecurity compliance role.
Experience managing authorization packages for multiple systems simultaneously.
Strong knowledge of NIST SP 800-53 Rev. 5, NIST RMF, FISMA, and related Federal cybersecurity requirements.
Experience developing, reviewing, and maintaining SSPs, SARs, POA&Ms, Risk Assessments, Contingency Plans, and other authorization artifacts.
Experience conducting control assessments, compliance reviews, and security documentation audits.
Ability to interpret technical findings from vulnerability scans, configuration assessments, and security reviews to support risk-based decision-making.
Experience providing technical guidance to engineering and operations teams to support corrective actions and POA&M closure.
Familiarity with continuous monitoring programs and ongoing authorization requirements.
Experience working with vulnerability management tools, compliance dashboards, and governance, risk, and compliance (GRC) platforms.
Knowledge of cloud security compliance, Zero Trust Architecture, and modern Federal cybersecurity initiatives.
Industry certifications such as:
CISSP
CAP (Certified Authorization Professional)
Security+ CISM
GSLC
CGRC
or equivalent certifications
Strong written, verbal, analytical, and interpersonal communication skills, with the ability to interact effectively with technical teams, auditors, system owners, and government stakeholders.
Overview
Noblis ( and our wholly owned subsidiaries, Noblis ESI , and Noblis MSD tackle the nation's toughest problems and apply advanced solutions to our clients' most critical missions. We bring the best of scientific thought, management, and engineering expertise together in an environment of independence and objectivity to deliver enduring impact on federal missions. Noblis works with a wide range of government clients in the defense, intelligence and federal civil sectors. Learn more at Noblis -About Us (
Why work at a Noblis company?
Our employees find greater meaning in their work and balance the other things in life that matter to them. Our people are our greatest asset. They are exceptionally skilled, knowledgeable, team-oriented, and mission-driven individuals who want to do work that matters and benefits the public. Noblis has won numerous workplace awards ( . Noblis maintains a drug-free workplace.
- Remote/hybrid status is subject to change based on Noblis and/or government requirements
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to race, color, ethnicity, sex, age, national origin, religion, physical or mental disability, pregnancy/childbirth and related medical conditions, veteran or military status, or any other characteristics protected by applicable federal, state, or local law.
If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact us ( .
EEO is the Law ( | E-Verify ( | Right to Work (
Total Rewards
At Noblis we recognize and reward your contributions, provide you with growth opportunities, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, and work-life programs. Our award programs acknowledge employees for exceptional performance and superior demonstration of our service standards. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in our benefit programs. Other offerings may be provided for employees not within this category. We encourage you to learn more about our total benefits by visiting the Benefits ( page on our Careers ( site.
Compensation at Noblis is determined by various factors, including but not limited to, the combination of education, certifications, knowledge, skills, competencies, and experience, internal and external equity, location, clearance level, as well as contract-specific affordability, organizational requirements and applicable employment laws. The projected compensation range for this position is based on full time status. For part time or on-call staff, compensation is proportionately adjusted based on hours worked. While monetary compensation is important, it's just one component of Noblis' total compensation package.
Posted Salary Range
USD $78,900.00 - USD $180,525.00 /Yr.
- ...applications are received. Compliance Information Security Engineer Meet the... ...the highest levels of security assurance... ...Information Security Analyst will play a meaningful... ...‑on experience with multiple compliance and... ...Organization! #J-18808-Ljbffr Cisco Systems, Inc.SuggestedLocal areaWorldwide
$30 per hour
...development in fields such as information technology, technical/systems consulting, technical... ...supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work... ...remains posted. Career Level - IC0 About Us Only...Information SystemHourly payTemporary workInternshipFlexible hours$124.2k - $186.2k
...About the team: The Information Security organization advances the overall state of security... ...secure software and protect data and systems with appropriate security controls. Information... ...; Perform ongoing activities in compliance with service and contractual...Information SystemLocal areaRemote work$76.4k - $138.6k
...is fueled by vast amounts of information. Data is more valuable than ever... ...data and information systems is central to doing business,... ...and everyone in EY Information Security has a critical role to play.... ...As an Offensive Security Analyst on the Attack Surface Management...Information SystemSummer holidayLocal areaFlexible hours- ...The Workday Security Administrator is a Senior Workday HRIS Analyst responsible for the administration... ..., the Human Resources Information System (HRIS). They develop... ...ensure data integrity and compliance. The administrator... ...load data using advanced‑level Excel skills. Workday...Information SystemWork at office
- ...IT Security Analyst needs 3+ years experience IT Security Analyst requires... ...Analyst duties: Supports Information Security and Cyber Threat management... ...the Bank at an advanced level of ability. Analyzes... ...Evaluates the Banks networks and systems to identify technical security...
- ...eventually obtain a security clearance*... ...previous security analyst role involved with... ...or similar entry-level certifications Microsoft... ...Experience with ticketing systems (ServiceNow, Jira,... ...Understanding of compliance frameworks... ...Correlate alerts across multiple data sources to...
- ...alternative application process. IT Security Operations Analyst Full-time Regular Cary, NC... ...Governance, Risk & Compliance Control frameworks, risk... ...-4 years of experience in Information Security, Security... ...judgment Ability to manage multiple priorities Collaborative and...Full time
$100k - $115k
...Zachary Piper Solutions is hiring an Information Security Analyst (Tier 2) for a leading cybersecurity operations team supporting secure government environments company located in Raleigh, NC (RTP) . The Information Security Analyst will support IL6 security operations...$70k - $90k
...initiatives. You will execute critical security operations activities - incident response... ...Bachelor’s degree in Computer Science, Information Systems, IT Security, or equivalent work... ...and written communication skills. High level of initiative, self‑motivation, resourcefulness...Information SystemTemporary workWork experience placementWork at officeLocal area3 days per week- Teradata Corporation (SE) is seeking a Compliance Analyst to support security compliance programs across global cloud offerings. The role includes... ...standards. The ideal candidate will possess a degree in Information Security and have experience in security, compliance,...Flexible hours
- A financial services company in Raleigh seeks an experienced IT Security Analyst. This role includes supporting information security programs, analyzing threats, and enhancing security measures. Ideal candidates will have over 3 years of experience in IT security, preferably...
$40 - $45 per hour
...penetration test results. Retest fixed issues and validate remediation. Provide guidance to management and application developers on security findings. Qualifications Must‑Have: App penetration testing lifecycle, OWASP Top 10, vulnerability management, remediation...Hourly payTemporary workFlexible hours- ...is seeking an experienced Security Analyst/Data Security Specialist to... ...of the organization's information security programs. This role... ...file integrity monitoring systems, while addressing potential... ...tools. Documentation and Compliance: Document security incidents...Information SystemLocal area
- ...Shell. We're looking for a Security Analyst to support our security program... ...management, and compliance support. You will work with... ...infrastructure and data across multiple environments. This role is... ...s degree in Cybersecurity, Information Technology, Computer Science...Work at officeWorldwide
- ...is seeking a Senior Workday Security Administrator to serve as the... ...security configuration across multiple functional areas. The position... ...to ensure data integrity, compliance, and scalable security design... ...supporting ongoing enhancements and system maturity. The role requires...Full timeH1bRelocation package
- ...Information Security Specialist Hybrid - 3 days a week onsite. Responsibilities: Identify and evaluate potential areas of Information... .../Leaver (JML) automation using IAM tools integrated with HR systems. Experience with role-based or policy-based access models...3 days per week
$40 per hour
...knowledge, and excellent analytical skills. A bachelor's degree and cybersecurity certifications are preferred. Compensation starts at $40 per hour, and the position is open to candidates in multiple countries, including the US and Canada. #J-18808-Ljbffr DataAnnotationHourly payRemote workFlexible hours$53.28k - $218.48k
...Administration (FAA) Air Traffic Systems and Surveillance... ..., data, network, or security solutions that support... ..., including subsystem‑level design of electronic... ...Plan (TEMP) to ensure compliance with requirements.... ...Cybersecurity Support - Analyze information systems data, develop...Information SystemPermanent employmentTemporary workLocal areaRemote work- ...developing applications, networks, information security, databases, operating systems, or web technologies to meet... ...~ Coordination and management of multiple automated tasks or services to achieve... ...and managers at all levels across the enterprise, serving as...Information System
$50 - $60 per hour
...committed to creating high-quality AI. We are looking for a Securities Analyst to join our team to help train the next generation of AI while... ...performance. Qualifications Fluency in English (native or bilingual level). Detail-oriented. Proficient in financial analysis,...Hourly payFull timeContract workPart timeWork experience placementRemote workFlexible hours- ...software engineering, systems development,... ...these services in multiple computing environments... .../operations information, brand and intellectual... ...risk to the security of the client. • Continually... ...with all levels of staff and management... ...Security Analyst (CSA) - Certified...Information System
- Cisco Systems, Inc. is seeking a Data Security Analyst to join their team in RTP, North Carolina, in a hybrid work model. The analyst will transform complex security telemetry into actionable insights to improve governance and reduce risk across various environments including...
- ...is looking for an experienced Security Analyst/Data Security Specialist in Morrisville... ...include managing firewall systems, threat monitoring, and ensuring compliance with security standards.... ...equivalent experience and 5-7 years in information security. Preferred...
$128.1k - $239.6k
...fueled by vast amounts of information. Data is more valuable... ...data and information systems is central to doing... ...everyone in EY Information Security has a critical role to... ...Security Portfolio Compliance Enablement function,... ...Ability to maintain a high level of integrity,...Information SystemWork experience placementSummer holidayLocal areaFlexible hours$40 per hour
A cybersecurity training company is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. You will work remotely, assessing accuracy, and contributing to the development of AI security tools. Candidates...Hourly payRemote workFlexible hours$44.8k
...integrity, reliability, and security of critical technology systems by planning and executing audits across information systems and related... ...or suggestions. Ensures compliance with IS audit standards, guidelines... ...complex issues to higher-level staff. Ability to build...Information SystemMinimum wageFull timeContract workTemporary workWork experience placement- ...currently looking for an Information Systems Security Officer (ISSO) to provide... ...Requirements Knowledge and Skills In compliance with DoD Cyber Workforce 8... ...Assurance Management Level 2 (IAM Level II). The... ...knowledge and understanding of multiple technology infrastructures...Information SystemLocal area
- ...to have Sr. to Expert level experience within ISO... ...of ISO 27001 across multiple data centers within the... ...regards to policy an compliance issues. Communication... ...Compliance, Global Information Security, as well as executive... ...management ticketing system Experience Ten years...Contract workLocal areaFlexible hours
- ...relapsing forms of multiple sclerosis (RMS... .... For more information, visit Role... ...Information Security reports directly... ...governance, system and product availability... .... Ensure compliance with relevant... ..., including analysts, engineers,... ...stakeholders at all levels of the...Information System
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information System Security Compliance Analyst (Multiple Levels). Be the first to apply!
- data protection analyst Raleigh, NC
- business information analyst Raleigh, NC
- data analyst - r python sql Raleigh, NC
- data analyst bank Raleigh, NC
- certified health data analyst Raleigh, NC
- data analyst Raleigh, NC
- data center analyst Raleigh, NC
- senior financial data analyst Raleigh, NC
- provider data analyst Raleigh, NC
- sql data analyst Raleigh, NC


