Cybersecurity Compliance Analyst

Iceye UsIrvine, CA
Onsite

About The Position

The Cybersecurity Compliance Analyst is responsible for supporting and maintaining ICEYE US cybersecurity compliance programs through continuous assessment, documentation, evidence management, and audit readiness activities. This role works closely with Cybersecurity, IT, Engineering, DevOps, Legal, and other business stakeholders to evaluate security controls and demonstrate compliance with applicable regulatory, contractual, customer, and industry requirements. The position supports internal and external assessments by maintaining accurate compliance artifacts, identifying control gaps, and tracking remediation activities through completion. This role is a key contributor to ensuring ICEYE US can continuously demonstrate an effective and sustainable cybersecurity compliance posture.

Requirements

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, Information Systems, Business, Risk Management, or a related discipline, or equivalent relevant professional experience.
  • 2+ years of experience in cybersecurity compliance, governance, risk management, IT audit, information security, or a related GRC function.
  • Experience supporting cybersecurity compliance activities against frameworks or standards such as NIST SP 800-171, CMMC, NIST CSF, ISO 27001, SOC 2, or comparable requirements.
  • Experience collecting and maintaining audit evidence, compliance documentation, policies, procedures, control narratives, or other governance artifacts.
  • Experience performing control assessments, gap analyses, audit support, or remediation tracking.
  • Ability to interpret cybersecurity requirements and work with technical and business stakeholders to document how security controls are implemented and maintained.
  • Current U.S. Government security clearance or eligibility to obtain and maintain the level of clearance required for the position.

Nice To Haves

  • Experience supporting CMMC Level 2 or NIST SP 800-171 compliance programs.
  • Experience supporting external cybersecurity audits, C3PAO assessments, customer assessments, or regulatory examinations.
  • Familiarity with NIST SP 800-53, NIST RMF, DFARS cybersecurity requirements, or other U.S. Government cybersecurity requirements.
  • Experience working with Governance, Risk, and Compliance (GRC) platforms.
  • Experience developing or maintaining System Security Plans (SSPs), POA&Ms, control matrices, policies, procedures, or assessment documentation.
  • Experience supporting cybersecurity compliance within the aerospace, defense, government contracting, or other regulated industries.
  • Familiarity with Governance, Risk, and Compliance (GRC) platforms, with a strong preference for hands-on experience administering or supporting compliance programs within Vanta.
  • Familiarity with cloud and enterprise technology environments such as AWS, Microsoft Azure, and Microsoft 365.
  • Experience with third-party risk management, customer security questionnaires, or vendor security assessments.
  • Relevant certification such as Security+, CISA, CRISC, CGRC, CMMC CCP, or equivalent.

Responsibilities

  • Coordinate ongoing compliance activities for cybersecurity frameworks and requirements including CMMC, NIST SP 800-171, NIST CSF, ISO 27001, SOC 2, and applicable customer or contractual requirements.
  • Collect, review, validate, organize, and maintain cybersecurity compliance evidence and supporting documentation.
  • Perform security control assessments, gap analyses, and compliance reviews to identify deficiencies and areas requiring remediation in coordination with the Head of Cybersecurity.
  • Track identified compliance findings, corrective actions, Plans of Action and Milestones (POA&Ms), and remediation activities through closure.
  • Support internal audits, external assessments, customer security reviews, regulatory examinations, and third-party compliance activities.
  • Maintain policies, procedures, standards, system documentation, control narratives, and other artifacts required to demonstrate compliance.
  • Coordinate with control owners and technical teams to obtain evidence, validate control implementation, and document how cybersecurity requirements are satisfied.
  • Support the completion and validation of customer security questionnaires, due diligence requests, and other cybersecurity compliance inquiries.
  • Maintain cybersecurity compliance records and supporting artifacts within applicable Governance, Risk, and Compliance (GRC) platforms or repositories.
  • Monitor changes to applicable cybersecurity requirements and assist with updating controls, documentation, policies, and compliance activities accordingly.
  • Prepare compliance status reporting, metrics, risk summaries, and remediation updates for the Head of Cybersecurity and other stakeholders.
  • Support continuous improvement of cybersecurity governance, compliance processes, evidence collection, control monitoring, and audit readiness.

Benefits

  • health coverage
  • flexible PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service