Skip to content

Open nowPosted 17 days ago

Cybersecurity Compliance Analyst

Workable (global search)108,016 open roles

Where
Suitland, MD, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCybersecurity Compliance AnalystWorkable (global search) · Suitland, MD, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 17 days ago

Workable (global search) median: 7 days open

The posting

Cybersecurity Compliance Analyst

ISSO Support | Continuous Monitoring | Security Control Assessments

Location: Suitland, MD (Hybrid) Work Schedule: Full-Time | Hybrid (3 Days On-Site / 2 Days Telework) Clearance Requirement: U.S. Citizenship Required | Must hold an active Secret Clearance

Salary Range: $115,000 – $125,000

Who We Are

At RCG, Inc., we're more than just a federal contracting company—we're a team of innovators, problem-solvers, and collaborators dedicated to delivering exceptional technology solutions that support critical government missions.

We're proud to have been Certified™ as a Great Place to Work® for four consecutive years, a recognition that reflects our commitment to fostering a culture of trust, collaboration, inclusion, and professional growth. We believe our people are our greatest strength, and we're committed to creating an environment where employees can build rewarding careers while making a meaningful impact.

The Opportunity

RCG is seeking a Cybersecurity Compliance Analyst to support Information System Security Officers (ISSOs) in maintaining cybersecurity compliance for assigned federal FISMA systems.

This role is focused on the day-to-day coordination and execution of cybersecurity compliance activities, including Continuous Monitoring, Security Control Assessments (SCAs), RMF and A&A/ATO support, POA&M tracking, vulnerability remediation, and security documentation.

The successful candidate will work under the direction of the ISSO and collaborate closely with System Owners, engineers, system administrators, and other technical stakeholders to ensure cybersecurity documentation, evidence, and supporting artifacts are complete, current, accurate, and ready for Government or assessor review.

What You'll Do

Cybersecurity Compliance & Continuous Monitoring

  • Provide day-to-day cybersecurity compliance and systems-analysis support to assigned ISSOs and FISMA systems.
  • Prepare, maintain, and update Continuous Monitoring schedules, trackers, packages, and supporting documentation.
  • Collect, organize, review, and track security-control evidence and supporting artifacts for recurring compliance activities.
  • Maintain compliance calendars, action-item logs, deliverable trackers, and status reports for ISSO review.
  • Identify missing, overdue, or incomplete compliance requirements and escalate risks, deficiencies, or schedule concerns to the ISSO.
  • Support recurring compliance meetings, cybersecurity data calls, assessment activities, and status reporting.

Security Control Assessments & Audit Readiness

  • Prepare Security Control Assessment documentation and evidence packages.
  • Coordinate security-control evidence and artifact requests with system and technical stakeholders.
  • Maintain assessment trackers and document outstanding evidence requests.
  • Track SCA findings through remediation and closure.
  • Review cybersecurity documentation and supporting artifacts for completeness, consistency, currency, and readiness for Government or assessor review.
  • Support audit and assessment readiness by maintaining complete, current, and traceable documentation and evidence for internal and external reviews, assessments, inspections, and authorization activities.

RMF, A&A & Security Documentation

  • Support NIST Risk Management Framework (RMF) and Assessment & Authorization (A&A)/Authority to Operate (ATO) activities.
  • Develop, update, and perform quality reviews of cybersecurity documentation, including:
  • System Security Plans (SSPs)
  • FIPS 199/200 documentation
  • Risk assessments
  • Security-control implementation statements
  • Authorization artifacts
  • Review system Change Requests and support the preparation and tracking of Security Threshold Analysis (STA) and Security Impact Analysis (SIA) documentation.
  • Coordinate updates to cybersecurity documentation resulting from system or configuration changes.
  • Maintain accurate cybersecurity records and compliance information in JSAM and other Government-designated repositories and tracking tools.

POA&M & Vulnerability Remediation

  • Support the creation, maintenance, and status tracking of Plans of Action and Milestones (POA&Ms).
  • Track remediation activities, supporting evidence, milestones, and closure documentation.
  • Review vulnerability findings and track patching, configuration hardening, and remediation activities.
  • Coordinate with technical teams to obtain supporting evidence demonstrating remediation.
  • Ensure applicable POA&M records and supporting documentation remain accurate and current for ISSO review.

Stakeholder Coordination

  • Coordinate with ISSOs, System Owners, engineers, system administrators, and other technical stakeholders to obtain required compliance documentation and evidence.
  • Track outstanding actions and follow up with responsible stakeholders to ensure compliance deadlines are met.
  • Communicate compliance status, outstanding requirements, and potential schedule concerns clearly and accurately.
  • Provide organized and timely information to support ISSO decision-making and Government reporting requirements.

Requirements

What We're Looking For

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, or a related field. An equivalent combination of education and relevant experience may be considered based on applicable labor-category requirements.
  • Experience supporting cybersecurity compliance, federal FISMA systems, security documentation, Continuous Monitoring, Security Control Assessments, or related RMF activities.
  • Working knowledge of:
  • NIST Risk Management Framework (RMF)
  • NIST SP 800-53
  • FISMA
  • FIPS 199/200
  • Assessment & Authorization (A&A) / Authority to Operate (ATO)
  • Continuous Monitoring
  • POA&M management
  • Security Control Assessment processes
  • Experience developing, reviewing, maintaining, and tracking cybersecurity documentation and supporting evidence.
  • Experience supporting vulnerability remediation and compliance tracking.
  • Strong documentation, organization, quality-review, and stakeholder-coordination skills.
  • Ability to manage multiple compliance activities, deliverables, and deadlines while maintaining accurate records and supporting evidence.
  • Strong written and verbal communication skills.
  • Ability to work effectively with both cybersecurity and technical infrastructure teams.
  • U.S. Citizenship Required | Must hold an active Secret Clearance

Preferred Qualifications

  • Experience supporting federal government cybersecurity or information assurance programs.
  • Experience using JSAM or similar Government cybersecurity compliance and tracking systems.
  • Experience supporting Security Control Assessments, audits, inspections, and authorization activities.
  • Experience supporting vulnerability management and POA&M remediation activities.
  • CompTIA Security+ or an equivalent certification meeting applicable labor-category requirements.
  • Additional certifications such as CGRC, CISA, CISM, CISSP, or relevant cloud-security certifications are desirable based on assignment.

Role Alignment

The Cybersecurity Compliance Analyst supports the ISSO by preparing, reviewing, coordinating, and tracking cybersecurity documentation, evidence, assessment materials, remediation activities, and compliance status information.

This position supports—but does not replace—the ISSO function. Cybersecurity risk determinations, formal security advisory responsibilities, and approval or risk-acceptance decisions remain with the ISSO or designated Government authority.

Work Environment

  • Hybrid position based in Suitland, Maryland.
  • Three (3) days per week on-site and two (2) days telework, subject to contract and customer requirements.
  • Full-time position supporting mission-critical federal cybersecurity programs.
  • Collaborative environment requiring regular coordination with ISSOs, System Owners, engineers, system administrators, cybersecurity personnel, and Government stakeholders.

Benefits

  • Health, vision and dental Insurance
  • Paid Time Off
  • 401k
  • Education, Training & Development
  • Collaborative, supportive, and inclusive work environment.

Equal Opportunity Employer

RCG, Inc. is an Equal Opportunity Employer. We are committed to creating an inclusive workplace and providing equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the position.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.