Crawford Thomas Recruiting ยท 13 hours ago
Cyber Security Compliance Analyst
Crawford Thomas Recruiting is representing a rapidly growing cybersecurity company delivering enterprise-grade endpoint protection and zero-trust solutions. They are seeking a Cyber Security Compliance Analyst who will support compliance initiatives, participate in audits, and work closely with security engineering and IT teams to ensure effective implementation of technical controls.
Responsibilities
Support compliance initiatives aligned with NIST 800-53 / 800-171, RMF, STIGs, SOC 2 Type II, ISO 27001, and FedRAMP
Participate in internal and external audits, including evidence collection, control validation, remediation tracking, and auditor support
Assist with the development and maintenance of SSPs, POA&Ms, policies, standards, and procedures
Perform gap analyses and risk assessments against NIST- and RMF-based control sets
Work closely with security engineering, IT, and infrastructure teams to ensure technical controls are implemented and operating effectively
Support SIEM monitoring, incident response documentation, and control monitoring activities
Maintain audit readiness metrics and reporting for leadership
Assist with third-party risk assessments, vendor reviews, and customer security documentation (RFPs, questionnaires)
Qualification
Required
Approximately 6 years of combined IT and cybersecurity experience
Deep familiarity with NIST frameworks, RMF, STIGs, and compliance standards
Experience building, operating, or supporting security and Information Assurance programs
Hands-on background in SIEM monitoring, incident response, vulnerability management, or security operations
Practical experience with endpoint, server, and network security
Exposure to high-security, regulated, or mission-critical environments
Strong documentation skills and the ability to translate technical controls into audit-ready evidence
Ability to work 100% onsite in Orlando
Preferred
Experience supporting FedRAMP-aligned environments (even if not full ATO ownership)
Familiarity with SOC 2 Type II or ISO 27001 audit support
Experience with SSPs, POA&Ms, and continuous monitoring
Certifications such as Security+, CISA, CISM, CISSP, or ISO 27001 Auditor
Background in government, defense, or public-sector-adjacent environments
Experience in SaaS or cybersecurity product companies
Benefits
Bonus
Full benefits