Job Description

Title: Cybersecurity Analyst II – Audit and Compliance (Hybrid & Remote Work Eligible)

Estimated Starting Salary: $72,059.06 – $99,081.20

Location: United States

Full Time

The Cybersecurity Audit and Compliance Analyst contributes to the success of our mission by performing assessments of systems and networks within the network environment or enclave and works with various business units to conduct evaluations of SNC information systems to ensure controls are adequate, appropriate, and effective. Analysts are expected to perform independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within SNC s enterprise information system to determine compliance with published standards. This position will report to the Cybersecurity Governance, Risk, and Compliance (GRC) Manager to execute strategic vision for the team and assist in continued success of the GRC team.

As SNC’s corporate team, we provide the company and its business areas with strategic direction and business support spanning executive management, finance and accounting, operations, human resources, legal, IT, information security, facilities, marketing, and communications.

This role is open to a hybrid schedule or 100% remote work in most states

Responsibilities:

  • Analyze organization’s cyber defense policies and configurations and evaluate compliance with regulations and organizational directives
  • Conduct internal stakeholder interviews to collect artifacts and follow up with stakeholders as necessary to drive the audit to closure
  • Prepare audit reports that identify technical and procedural findings, and provide recommended remediation strategies/solutions
  • Assist with the maintenance and management of an audit database to track and monitor audit requests and responses
  • Support maintenance of a findings list and follow the plan(s) of action and milestones through remediation and closure
  • Assess system or network designs that encompass multiple enclaves, including those with different data protections or categorizations
  • Maintain knowledge of applicable cyber defense policies, regulations, standards, and compliance documents specifically related to cyber defense assessments

Must Haves:

  • Bachelor’s degree in Cybersecurity, Network Engineering, Information Technology, Management Information Systems or related Engineering discipline OR typically 3 or more years of relevant experience
  • Experience supporting, troubleshooting, and administering a variety of networks, OSs, and applications.
  • Knowledge and experience administering a variety of current Microsoft platforms.
  • Knowledge of data security administration principles, methods, and techniques
  • Familiarity with domain structures, user authentication, and digital signatures
  • Knowledge of information security controls and frameworks such as NIST CSF, RMF, SP 800-53, SP 800-171, DFARS, CMMC, FISMA, ISO 27000 series, COBIT, PCI DSS, or Center for Internet Security (CIS) 20 Critical Security Controls
  • Strong analytical, and problem-solving skills
  • Ability to effectively execute multiple, complex tasks
  • Ability to read and interpret security and technical documentation
  • Strong interpersonal and written communication skills
  • The ability to obtain and maintain a Secret U.S. Security Clearance is required

Preferred:

  • Experience responding to, analyzing, and communicating control status through presentations and formal written reports
  • Experience with enterprise GRC tool(s)
  • At least one of the following, or the ability to achieve one of the approved DoDD 8140 cybersecurity certifications within six months:
    • GIAC Certifications (any)
    • CMMC-AB certifications (any)
    • Certified Authorization Professional (CAP)
    • Certified Ethical Hacker (CEH)
    • Certified Information System Auditor (CISA)
    • Certified Information Systems Security Professional (CISSP)
    • Network+, Security+, or Cybersecurity Analyst (CySA+)

APPLY HERE