The IT GRC Analyst (CMMC Control Specialist) is responsible for the daily monitoring, operational testing, and ongoing compliance analysis of the organization’s cybersecurity controls. Rather than developing high-level enterprise security policies, this operational role focuses on hands-on control execution, reviewing technical logs, verifying evidence, and authoring, maintaining, and updating granular Standard Operating Procedures (SOPs). This position ensures that hybrid IT environments, cloud enclaves, and technical infrastructure continuously satisfy CMMC Level 2 and NIST SP 800-171 requirements through standardized, repeatable processes.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level