IT GRC Analyst Level II

Posted Yesterday
Be an Early Applicant
Coral Springs, FL, USA
In-Office
Mid level
Aerospace
The Role
Monitors and tests cybersecurity controls across hybrid IT, cloud, and virtualization environments to support CMMC Level 2 and NIST SP 800-171 compliance. Develops and maintains technical SOPs, reviews logs and evidence, tracks POA&M remediation, validates CUI boundary controls, performs vendor risk checks, and supports SPRS reporting, DIBCAC audits, and C3PAO assessments.
Summary Generated by Built In

Description

  

Position Overview

The IT GRC Analyst (CMMC Control Specialist) is responsible for the daily monitoring, operational testing, and ongoing compliance analysis of the organization’s cybersecurity controls. Rather than developing high-level enterprise security policies, this operational role focuses on hands-on control execution, reviewing technical logs, verifying evidence, and authoring, maintaining, and updating granular Standard Operating Procedures (SOPs). This position ensures that hybrid IT environments, cloud enclaves, and technical infrastructure continuously satisfy CMMC Level 2 and NIST SP 800-171 requirements through standardized, repeatable processes.Key Responsibilities

SOP Development, Maintenance & Operationalization:

  • Draft,      review, and continuously refine detailed Standard Operating Procedures (SOPs) that translate complex NIST SP 800-171 controls into      step-by-step technical workflows for IT staff.
  • Audit      operational practices regularly to ensure procedural alignment with active      SOPs, updating documentation whenever technical environments or baseline      configurations evolve.
  • Maintain      the centralized repository of GRC SOPs, work instructions, and execution      templates, ensuring version control and strict alignment with the      enterprise System Security Plan (SSP).
  • Partner      with System Administrators and IT Operations to convert POA&M      remediation outcomes into formalized, repeatable SOPs to prevent recurring      compliance gaps.

Daily Control Monitoring & Evidence Analysis

  • Perform  daily, weekly, and monthly operational reviews of technical controls      across all 14 NIST SP 800-171 practice domains (e.g., auditing SIEM logs,      validating MFA enforcement, and reviewing access requests) in      accordance with established SOPs.
  • Collect,      inspect, and archive technical artifacts and evidence (configuration      baselines, backup logs, patch records) to maintain continuous audit      readiness.
  • Identify,      document, and report control drift or non-compliance issues across hybrid      Active Directory, cloud environments (GCC High/Azure), and virtualization      platforms.
  • Execute      recurring internal control tests to verify that technical safeguards      operate as documented in the SSP and procedural guidelines.

Risk Tracking & POA&M Execution

  • Track      and validate the daily progress of remediation items listed on the active Plan      of Action & Milestones (POA&M).
  • Collaborate      directly with System Administrators and IT Operations to test and verify      fixed items before closing out open POA&M entries.
  • Monitor      daily CUI flow paths and enclave access logs to verify that Controlled      Unclassified Information (CUI) boundary controls remain strictly      enforced.
  • Conduct      routine vendor risk checks, verifying that subcontractors maintain active      compliance with DFARS 252.204-7012 / 7020 flow-down requirements.

Audit Support & Reporting

  • Analyze      compliance data to support regular SPRS score updates and internal      readiness reporting.
  • Serve      as the primary hands-on evidence and procedural coordinator during      internal compliance reviews, DIBCAC audits, and external C3PAO      assessments.
  • Generate      weekly operational risk metrics, process execution logs, and gap analysis      reports for the IT Security Manager.

Qualifications & Requirements

  • Experience:      2–4+ years of hands-on experience performing IT compliance monitoring,      internal auditing, procedural documentation, or security control testing      in a DoD/DFARS environment.
  • Documentation      & SOP Skills: Proven ability to author clear, step-by-step      technical Standard Operating Procedures (SOPs), system administration      guides, and audit-ready control execution logs.
  • Framework      Knowledge: Direct experience monitoring and analyzing controls under NIST      SP 800-171, CMMC Level 2, and DFARS 252.204-7012.
  • Technical      Familiarity: Practical experience inspecting control evidence within      Active Directory / Entra ID, Microsoft 365 / GCC High, firewalls, SIEM      platforms, and hypervisors.
  • Education:      Bachelor’s Degree in Cybersecurity, Information Systems, or equivalent      practical technical experience.

Preferred Certifications

  • CMMC      / Compliance: CCP (CMMC Certified Professional) or CISA.
  • General      Security: Security+, Network+, or SSCP.

Skills Required

  • 2-4+ years of hands-on experience in IT compliance monitoring, internal auditing, procedural documentation, or security control testing in a DoD/DFARS environment
  • Ability to author step-by-step technical SOPs, system administration guides, and audit-ready control execution logs
  • Direct experience with NIST SP 800-171, CMMC Level 2, and DFARS 252.204-7012 controls
  • Practical experience inspecting evidence in Active Directory or Entra ID, Microsoft 365 or GCC High, firewalls, SIEM platforms, and hypervisors
  • Bachelor's degree in Cybersecurity, Information Systems, or equivalent practical technical experience
  • CMMC Certified Professional (CCP) or CISA certification
  • Security+, Network+, or SSCP certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Lauderdale, FL
201 Employees
Year Founded: 2002

What We Do

CTS Engines is a recognized world leader of mature aircraft engine maintenance, providing MRO and testing services for commercial and military operators worldwide. CTS specializes in the overhaul of CF6-80C2, CF6-80A, and CF6-50 engines from our main service center located adjacent to Fort Lauderdale-Hollywood International Airport in Florida. We are industry leaders in independent high thrust engine testing at our 155,000 lb/ft thrust engine test facility.

Similar Jobs

PNC Bank Logo PNC Bank

Technology Solution Center Analyst Lead

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
41K-83K Annually

Boeing Logo Boeing

Customer Product Support

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Davie, FL, USA
170000 Employees
101K-143K Annually

Boeing Logo Boeing

Office Administrator

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Titusville, FL, USA
170000 Employees
60K-81K Annually

Boeing Logo Boeing

X-37B Product Review Engineer (Liaison Engineering)

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Titusville, FL, USA
170000 Employees
104K-140K Annually

Similar Companies Hiring

Red 6 Thumbnail
Aerospace • Hardware • Software • Virtual Reality • Defense
Orlando, Florida
186 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account