Skip to content

Open nowPosted 16 hours ago

Compliance Analyst - Cloud Security

Knox Systems15 open roles

Where
United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCompliance Analyst - Cloud SecurityKnox Systems · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Knox Systems's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Knox Systems postings stay open a median of 45 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 16 hours ago

Knox Systems median: 45 days open

The posting

About Knox

Knox runs the largest Federal & DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.

Work at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.

THE ROLE

Knox is seeking a Compliance Analyst with strong technical and regulatory expertise to help ensure Knox and its customers continuously meet federal and commercial compliance requirements. This role is responsible for driving ongoing compliance across FedRAMP, FISMA, NIST 800-53, IL4, IL5, CMMC, SOC 2, StateRamp, and GovRAMP environments while partnering closely with Security, DevOps, Operations, and customer teams.

This is not a point-in-time audit support role. This position is expected to operate as a technical compliance lead who can validate controls in cloud environments, track remediation and POA&M performance, enforce compliance SLAs, support audits and assessments, and provide clear risk visibility to internal leadership and customers.

KEY RESPONSIBILITIES

● Assist with continuous compliance oversight for Knox and assigned customer environments across FedRAMP, FISMA, NIST 800-53, IL4, IL5, CMMC, SOC 2, StateRamp, GovRAMP, and related frameworks.

● Track and enforce compliance obligations, remediation deadlines, POA&M milestones, vulnerability remediation timelines, and continuous monitoring requirements.

● Review and validate technical control implementation across AWS, Azure, and GCP environments, including logging, monitoring, IAM, incident response, vulnerability management, endpoint security, network segmentation, and change management.

● Partner with Sr. Compliance specialists and Security Operations, Compliance, DevOps, Engineering, and customer teams to ensure required controls are implemented and operating effectively.

● Support FedRAMP authorization and ongoing assessment activities, including SSP updates, evidence collection, ConMon support, 3PAO coordination, audit preparation, and customer artifact reviews.

● Evaluate findings and weaknesses using both compliance requirements and operational risk, including exploitability, exposure, compensating controls, and customer responsibility boundaries.

● Maintain visibility into customer compliance posture and ensure customers meet shared-responsibility obligations and required service-level timelines.

● Assist with customer-facing compliance activities, including coordinating Continuous Monitoring (ConMon) submissions, leading POA&M reviews, managing Security Change Requests/Notifications (SCR/SCN) with customers, and acting as a primary liaison for agency communication.

● Prepare dashboards, metrics, and executive reporting for overdue findings, POA&Ms, control gaps, remediation status, audit readiness, and overall compliance posture.

● Escalate material compliance gaps, SLA misses, and recurring customer issues to Knox leadership with clear recommendations and risk context.

● Assist with documentation of Knox’s compliance processes, templates, playbooks, and automation capabilities, leveraging compliance-as-code and KnoxAI, to support scalable, repeatable, and audit-ready operations.

QUALIFICATIONS

● 3-5 years of experience in cybersecurity compliance, GRC, cloud security, or related security assurance roles.

● Experience with FedRAMP and NIST SP 800-53 in cloud or SaaS environments.

● Working knowledge of FISMA, SOC 2, StateRamp, GovRAMP, and at least one of the following: IL4, IL5, CMMC, NIST 800-171.

● Experience supporting audits, assessments, or authorization activities in regulated cloud environments.

● Understanding of cloud platforms such as AWS, Azure, and/or GCP and how security controls are implemented within them.

● Experience partnering with technical teams such as DevOps, SOC, SRE, Engineering, or IT Operations to validate control implementation and drive remediation.

● Ability to assist with and manage multiple customers, priorities, deadlines, and dependencies in a fast-paced environment.

● Strong written and verbal communication skills, including the ability to explain compliance requirements, technical findings, and risk decisions clearly to both technical and non-technical stakeholders.

PREFERRED QUALIFICATIONS

● Experience with FedRAMP High and/or DoD IL4 / IL5 environments.

● Experience working with continuous monitoring, POA&M governance, vulnerability remediation tracking, and customer audit readiness.

● Familiarity with cloud/security tooling such as CSPM, SIEM, EDR/XDR, ticketing/GRC platforms, and evidence automation workflows.

● Experience with shared responsibility models in managed cloud or regulated SaaS environments.

● Certifications such as CISSP, CISA, CAP, Security+, CCSP, or cloud security certifications.

● Experience in a high-growth cloud company, managed services provider, or regulated SaaS provider.

SUCCESS IN THIS ROLE

● Knox and assigned customers maintain strong compliance posture with minimal overdue remediation items.

● Audit and assessment artifacts are complete, accurate, and ready when needed.

● Control gaps are identified early and driven to closure.

● Customers clearly understand what they own, what Knox owns, and what deadlines must be met.

● Leadership has accurate, timely visibility into compliance health, risk, and SLA performance.

Compensation Range: $100-$115k, variable annual bonus, and equity

Benefits & Perks

Knox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PTO, and an employee funded 401k plan. Please note, benefits are subject to change.

We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.

Knox is proud to support veteran hiring — we encourage veterans and transitioning service members to apply and welcome the unique skills and experience you bring.

Hiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.

Any offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Knox Systems's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Knox Systems's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Knox Systems's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.