GRC Analyst II - Maritime Defense

Pole Star DefenseSaint Petersburg, FL
37d

About The Position

The GRC Analyst II is responsible for supporting the implementation, maintenance, and continuous improvement of Pole Star’s Governance, Risk, and Compliance programs. This role ensures organizational adherence to CMMC Level 1 and Level 2, ISO 27001, ISO 9001, NIST SP 800-53, NIST SP 800-171, and other applicable regulatory and contractual cybersecurity requirements. The position requires strong analytical skills, attention to detail, and the ability to interact effectively with technical and non-technical stakeholders.

Requirements

  • 2–5 years of experience in Governance, Risk & Compliance, cybersecurity, IT audit, or IAM governance.
  • Working knowledge of CMMC Level 1 and Level 2, NIST SP 800-53, NIST SP 800-171, ISO 27001, and ISO 9001.
  • Experience conducting audits, risk assessments, control testing, and maintaining compliance documentation.
  • Understanding of identity and access governance principles, including RBAC, least privilege, and access recertification processes.
  • Strong analytical, organizational, and written communication skills.

Nice To Haves

  • CISA, CMMC RA
  • Ability to obtain DoD Security Clearance

Responsibilities

  • Support compliance activities and control implementation associated with CMMC Level 1 and Level 2, ISO 27001, ISO 9001, NIST SP 800-171, and NIST SP 800-53.
  • Conduct internal audits, gap analyses, and readiness assessments across assigned compliance frameworks.
  • Collect and maintain evidence demonstrating ongoing control effectiveness.
  • Collaborate with IT and Security teams to remediate identified deficiencies and implement control improvements.
  • Assist in developing, updating, and reviewing compliance documentation to ensure continued audit readiness.
  • Support the IAM governance lifecycle, including user provisioning/deprovisioning, access reviews, entitlement certifications, and privileged access oversight.
  • Ensure IAM processes meet CMMC, NIST SP 800-53 (AC, IA), and NIST SP 800-171 access control requirements.
  • Work with IT and Security teams to improve IAM procedures, workflows, and documentation.
  • Coordinate and manage corporate cybersecurity and compliance training programs in alignment with CMMC, NIST SP 800-53 (AT), and ISO training requirements.
  • Administer annual and new-hire training, role-based training, and privileged user training.
  • Support and track phishing awareness campaigns and other user-focused security initiatives.
  • Maintain complete and accurate training records for internal and external audit purposes.

Benefits

  • Medical insurance for employees and their dependents (Premiums are 100% covered by the Company)
  • Dental and Vision insurance for employees and their dependents (Premiums are 50% covered by the Company)
  • Life and Disability insurance, Company funded
  • 20 days annual leave
  • 5 days of Wellbeing leave
  • Up to a 5% 401k matching
  • Gym membership subsidy
  • PTO for Volunteer Day
  • Refer-a-friend recruitment bonus
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service