asrcfh1d ago
New
New
Senior Cybersecurity Compliance Analyst
Remotesenior
Finance & AccountingCompliance Analyst
0 views0 saves0 applied
Quick Summary
Key Responsibilities
Lead the organization’s readiness efforts toward achieving and maintaining CMMC Level 2 certification. Perform gap assessments, evidence collection, control validation,
Requirements Summary
Implement and monitor Cybersecurity Supply Chain Risk Management (C-SCRM) requirements. Assess vendor cybersecurity posture, conduct supplier assessments, and support acquisition security requiremen
Technical Tools
Finance & AccountingCompliance Analyst
ASRC Federal is looking for detail-oriented and motivated Senior Cybersecurity Compliance Analyst to join our team in a government contracting (GovCon) environment. This is a full-time remote position with occasional on-site support (Beltsville, MD or Reston, VA).
The Senior Cybersecurity Compliance Analyst is responsible for leading, managing, and executing compliance activities aligned to CMMC Level 2, NIST SP 800-171, NIST SP 800-161, and NIST SP 800-53. This role will support enterprise cybersecurity, audit readiness, risk assessments, POA&M management, continuous monitoring, and the implementation of required security controls across systems, vendors, and business units.The ideal candidate will bring deep expertise in federal cybersecurity frameworks, strong analytical skills, and the ability to collaborate with technical and non-technical stakeholders to ensure robust compliance.
Key Responsibilities
CMMC Level 2 Compliance:
Lead the organization’s readiness efforts toward achieving and maintaining CMMC Level 2 certification.
Perform gap assessments, evidence collection, control validation, and SSP/POA&M development.
Coordinate with internal engineering teams and external assessors during CMMC audits.
NIST SP 800-171:
Oversee compliance with DFARS 252.204-7012 and NIST 800-171 requirements for protecting Controlled Unclassified Information (CUI).
Maintain and update System Security Plans (SSPs) and associated security documentation.
Manage risk assessments, incident response requirements, and continuous monitoring activities.
NIST SP 800-161 (Supply Chain Risk Management):
Implement and monitor Cybersecurity Supply Chain Risk Management (C-SCRM) requirements.
Assess vendor cybersecurity posture, conduct supplier assessments, and support acquisition security requirements.
Develop processes to track, evaluate, and mitigate supply chain-related risks.
NIST SP 800-53:
Support enterprise-level compliance with NIST 800-53 security and privacy controls.
Assist in RMF activities including categorization, control selection, control assessments, and continuous monitoring.
Work with system owners to remediate findings and ensure controls are implemented effectively.
General Responsibilities
Collaborate with engineering, IT, procurement, legal, and executive teams to ensure compliance alignment across the organization.
Prepare compliance reports, dashboards, and metrics for leadership.
Lead internal audits and coordinate external audits.
Serve as a subject matter expert on cybersecurity compliance frameworks and best practices.
Improve and mature enterprise cybersecurity governance processes, policies, and procedures.
Required Qualifications
Bachelor’s degree in cybersecurity, information systems, or related field (or equivalent experience).
7+ years of relevant cybersecurity compliance or risk management experience. 5+ years of experience with a Master's degree in Cybersecurity.
Hands-on experience implementing: CMMC Level 2 controls, NIST SP 800-171, NIST SP 800-161, NIST SP 800-53.
Strong understanding of Risk Management Framework (RMF).
Experience preparing SSPs, POA&Ms, security documentation, and audit evidence.
Ability to work with cross-functional teams and communicate complex requirements clearly.
U.S. citizenship required; ability to obtain and maintain a security clearance may be required depending on contract.
Preferred Qualifications
Industry certifications (one or more): CISSP, CISM, CRISC, CAP, CCAK, or CMMC Certified Professional/Assessor.
Experience supporting DoD, federal agencies, or defense contractors.
Familiarity with FedRAMP, DFARS, SCF, or ISO 27001 frameworks.
Experience with continuous monitoring technologies and GRC tools (e.g., Archer, ServiceNow, eMASS).
Additional Information
Reports to: Cybersecurity Governance, Risk & Compliance Leadership
Travel: Minimal (0–10%)
Clearance: Secret clearance preferred but not required; may be required based on project needs.
Location & Eligibility
Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location
Listing Details
- Posted
- June 8, 2026
- First seen
- June 8, 2026
- Last seen
- June 9, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 58%
- Scored at
- June 8, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application · ~5 min on asrcfh's site
Please let asrcfh know you found this job on Jobera.
4 other jobs at asrcfh
View all →Explore open roles at asrcfh.
Similar Compliance Analyst jobs
View all →Compliance Analyst, Client Onboarding Operations #3613512
about 10 hours ago
Compliance Analyst
Permanent
Senior Compliance Analyst - Advertising Review
$85k–$100k/yr
Remote
Tax & Compliance Analyst - Client Services
R
RushstreetinteractiveRemoteTechnical Compliance Analyst
USD 60000-75000
Remote
F
FamilyofficeCompliance Analyst
Browse Similar Jobs
Accountant1.6kFinance Manager625Controller501Financial Analyst404Tax Specialist345Accounting Manager296Payroll Specialist211Chief Accountant194Tax144Audit121Risk Manager90Accounts Payable86Accounts Receivable Specialist82Accounts Payable Specialist80Tax Manager78Financial Planning72Accounts Receivable71FP&A Analyst70Billing Specialist66Treasury66
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.