75 security compliance analyst jobs at 52 companies in Dumfries, VA
1w
Save
Mark Applied
Hide
1w
Security & Compliance Analyst
Sterling, Virginia, United States
OnsiteFull Time
ASSYST: An award-winning information technology firm helping government agencies solve complex technology challenges and secure critical assets.
1+ YOEBachelor's degree in cybersecurity or related field, 1–3 years of cybersecurity or compliance experience, Security+ or Network+ preferred/required, U.S. citizenship, and ability to obtain a government clearance.
Systems Planning and Analysis: Provides technical and analytical support to national security agencies.
12+ YOEJuris Doctor and bachelor's degree in business, finance, economics, or national security; 12+ years' experience including 5+ in compliance and monitoring; active TS/SCI clearance; travel availability.
H4 Enterprises: Provides technical, logistics, and management services to federal agencies.
Bachelor's degree in IT, 10+ years of hands-on IT experience, U.S. citizenship, Top Secret clearance with SCI eligibility, required security certifications, and RMF, NIST, FISMA, vulnerability assessment, and compliance experience.
Information System Security Compliance Analyst (Multiple Levels)
United States or Atlantic City or Washington
$79k-$218k/yrRemoteFull Time
Noblis: Provides science and technology solutions for government missions.
Support RMF-based security authorization, NIST SP 800-53 control assessment, develop and maintain SSPs/SARs/POA&Ms, track POA&Ms to closure, and communicate compliance to stakeholders.
NIST Risk Management Framework (RMF), NIST SP 800-53, Microsoft Excel, Microsoft Word, Microsoft PowerPoint
ADEPT Force Group: Provides strategic management and acquisition support to government agencies.
Bachelor's degree and 12+ years relevant experience, or equivalent; DoD/Army cybersecurity experience; RMF, continuous monitoring, ACAS, eMASS, AWS/Azure, Security+ certification, and Secret clearance required.
Risk Management Framework (RMF), National Institute of Standards and Technology (NIST), NIST Special Publication (SP) 800-37, NIST SP 800-53, Development, Security, and Operations (DevSecOps), Assured Compliance Assessment Solution (ACAS), Enterprise Mission Assurance Support Service (eMASS), Amazon Web Services (AWS), Microsoft Azure
El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London
$120k-$150k/yrHybridFull Time
CHAOS Industries: Develops advanced radar and sensing systems for modern defense.
5+ YOEBachelor's degree or equivalent experience, 5+ years of GRC or compliance experience, DoD or military experience, audit support, risk assessment, GRC tooling, and knowledge of major security frameworks.
AmentumNYSE: AMTM: Global provider of engineering, technical, and mission support services.
2+ YOEBachelor's degree or equivalent experience, relevant security experience, active Top Secret clearance, ability to obtain a polygraph, analytical and communication skills, and knowledge of ICD 704 or SEAD guidelines.
K2United: Provides cybersecurity advisory and online workforce safety training.
4+ YOEBachelor's degree or equivalent experience, 4+ years in cybersecurity, third-party/vendor risk, or compliance analysis, and experience producing security risk assessments and mitigation recommendations.
NIST SP 800-218, NIST AI Risk Management Framework and Playbook
Armada Ltd.: Provider of physical security, training, and risk management solutions.
10+ YOERequires 10 years of relevant experience, including 3 years of security experience, plus a relevant master's degree or bachelor's degree with 4 additional years. Secret clearance and industrial security expertise required.
Walgreens: Retail pharmacy providing prescriptions and health and wellness products.
2+ YOEBachelor's degree and 2+ years in technology compliance, IT audit, or IT security, or high school diploma/GED and 4+ years. Experience with PCI, HITRUST, or HIPAA required.
X-energy: Develops advanced small modular nuclear reactors and fuel technology.
20+ YOEExtensive plant security experience; knowledge of NRC, SGI, access control, surveillance, and incident response; 20 years in security; Bachelor's in Criminal Justice or Security Management.
Surveillance Systems, Intrusion Detection, Access Control Systems, Security System Infrastructure, SGI Management
Bengaluru or New York City or Washington or Vancouver or London or Galway or Budapest or Munich or Singapore or Sydney
HybridFull Time
Diligent: Private GRC SaaS providing governance, risk, compliance, audit, and ESG software to boards and organizational leaders.
2+ YOERequires 2–4 years in security GRC, compliance, IT audit, or customer assurance; SOC 2 and ISO 27001 knowledge; precise SLA-driven work; strong written English; queue management; and AI-assisted tooling experience.
JANUS Research Group: Provides specialized engineering and technical services for defense organizations.
5+ YOEBachelor's degree and 5+ years managing multidisciplinary DoD security programs, program protection, or military intelligence. Active Secret clearance and proficiency with DISS, PSIP, APACS, ICAM, and AESIP required.
Security Office Actions Tracker, Personnel Security Investigation Portal (PSIP), Defense Information System for Security (DISS), Identity, Credential, and Access Management (ICAM), Army Enterprise Systems Integration Program (AESIP), Aircraft Personnel Automated Clearance System (APACS), DoD Directive 5200.01, NISPOM
Sancorp: San provides counterintelligence and AI solutions for federal agencies.
3+ YOEBachelor's degree or equivalent experience; 3+ years in personnel security or related federal security operations; TS/SCI clearance and U.S. citizenship required; expertise in security systems, risk assessment, and briefings.
Defense Information System for Security (DISS), Scattered Castles, National Background Investigation Services (NBIS), e-QIP, Microsoft 365
ManTech: Provides technology solutions for defense and intelligence agencies.
7+ YOEActive TS/SCI with polygraph required; 7+ years relevant security experience (varies by degree), strong writing/research skills, knowledge of Intelligence Community Directives (ICDs), and ability to manage shifting priorities.
Virtru: Provides data-centric encryption and privacy control software for organizations.
5+ YOE5+ years in information security/GRC or IT audit, deep knowledge of CMMC/NIST/FedRAMP/SOC2/PCI, cloud and GRC tool experience, strong communication and risk assessment skills.
Federal Reserve Board of Governors: The central bank of the United States.
6+ YOESenior information security analyst with 6+ years of experience, bachelor's degree or equivalent, strong risk management, governance, and compliance knowledge.
Watermark Risk Management International: Provides security and risk management services for government agencies.
5+ YOE5+ years of direct information security policy, planning, assessment, and administration experience; knowledge of CNSI/CUI/SBU handling, USCG/DHS policy, strong technical writing and interpersonal skills; U.S. citizenship required.
Northrop GrummanNYSE: NOC: Develops and manufactures advanced aerospace, defense, and space systems.
2+ YOEBachelor's degree plus 2–5 years of security experience or equivalent; active Top Secret clearance, Special Program Access eligibility, program security expertise, and knowledge of DoD security regulations.
JADE, DISS, SIMS, DoD 5205.07 SAP Manual, ICD 705, ICD 704, NISPOM, CDSE SAP Orientation course, CDSE Intro to SAP course