Logo for ShorePoint Inc

Security Compliance Analyst

Role overview

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field, or equivalent professional experience.
  • 2+ years of experience in federal information security compliance, IT security, or a related field.
  • Experience with Governance, Risk, and Compliance (GRC) tools such as Xacta, CSAM, RSA Archer or similar.
  • Strong written and verbal communication skills

Responsibilities

  • Support the SIAM in executing the program’s information assurance and cybersecurity compliance strategy.
  • Coordinate with ISOs and ISSOs to maintain system security documentation, track control implementation and support Authorization to Operate (ATO) and continuous ATO (cATO) activities.
  • Support FISMA compliance activities, including annual self-assessments, security control assessments and preparation for Inspector General (IG) and Office of Management and Budget (OMB)-driven audits.
  • Track POAM remediation activities to ensure findings from audits, assessments and vulnerability scans are documented, assigned and closed within required timelines.

Key facts

  • Remote from: Virginia (USA)
  • Full time
  • Senior (5-10 years)
  • Security Compliance Analyst
  • English

Hard skills

Other skills

  • Communication
  • Organizational Skills
  • Critical Thinking
  • Detail Oriented

About the company

ShorePoint Inc logo

ShorePoint Inc

IT Services & IT Consulting

ShorePoint recognizes that cybersecurity is the challenge of our generation. Our vision is to be the premier provider of cybersecurity services, delivering a security model capable of keeping pace with today’s rapidly changing landscape. ShorePoint is a privately-held cybersecurity services company with the experience and capabilities needed to help public and private sector clients protect their most critical assets from cyber threats. Founded by cybersecurity veterans Matt Brown and Scott Ackerman and amplified by executives Ryan McCullough and Rob Palmer, ShorePoint offers a focus on establishing meaningful cyber defense strategies across the full cyber lifecycle. We bring a deep expertise in the Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM) program, a technology and vendor agnostic mindset, and small firm agility, ingenuity and responsiveness. The ShorePoint team has designed, implemented and managed proven cyber programs for critical missions within the federal civilian, defense, and intelligence community, and has extensive commercial experience supporting high technology, financial services, critical infrastructure, and healthcare. Beyond excelling in our craft, what sets ShorePoint apart is our culture: a high energy and flexible work environment that enables our team to creatively tackle the cyber challenges of today. We empower and support our employees in outreach programs with a corporate culture focused on being an active member in improving our community.

Company details

IndustryIT Services & IT Consulting
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Who we are:

ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.  

The Perks:

As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers. Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.

Who we’re looking for:

We are seeking a Security Compliance Analyst to support federal cybersecurity compliance activities, including Federal Information Security Modernization Act (FISMA)-driven assessment and authorization (A&A), ongoing risk management and audit readiness. This role supports the Security Information Assurance Manager (SIAM) by coordinating security documentation, control implementation, continuous monitoring and compliance activities across Identity, Credential, and Access Management (ICAM) systems. The Security Compliance Analyst position works with Information System Owners (ISOs), Information System Security Officers (ISSOs), program leadership and other stakeholders to maintain security compliance and support federal requirements. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.

What you’ll be doing:

  • Support the SIAM in executing the program’s information assurance and cybersecurity compliance strategy.
  • Coordinate with ISOs and ISSOs to maintain system security documentation, track control implementation and support Authorization to Operate (ATO) and continuous ATO (cATO) activities.
  • Support FISMA compliance activities, including annual self-assessments, security control assessments and preparation for Inspector General (IG) and Office of Management and Budget (OMB)-driven audits.
  • Develop, review and maintain security artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms) and Risk Assessment Reports (RARs).
  • Support Risk Management Framework (RMF) activities, including control selection, implementation tracking, assessment and continuous monitoring.
  • Track POA&M remediation activities to ensure findings from audits, assessments and vulnerability scans are documented, assigned and closed within required timelines.
  • Assist with the preparation of materials and evidence packages for internal reviews, external audits and compliance inspections (e.g., FISMA, OIG, GAO, or agency-specific audits).
  • Support the security compliance posture of ICAM systems and track security policy, procedure and control updates to maintain alignment with evolving federal requirements.
  • Maintain continuous monitoring documentation and support monthly and quarterly compliance reporting to program leadership and government stakeholders.
  • Participate in security control assessments, walkthroughs and stakeholder interviews to validate control implementation.
  • Maintain organized documentation repositories and audit trails to support inspection readiness.
  • Communicate compliance status, risks and action items to the SIAM and program leadership.

What you need to know:

  • Federal information security compliance and audit practices, including FISMA and A&A activities.
  • NIST RMF, NIST Special Publication (SP) 800-53 security controls and common security compliance artifacts, including SSPs, SARs, POA&Ms, RARs and continuous monitoring reporting.
  • Security documentation, control implementation, continuous monitoring and audit readiness practices.

Must have’s:

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, or a related field, or equivalent professional experience.
  • 2+ years of experience in federal information security compliance, IT security, or a related field.
  • Experience with Governance, Risk, and Compliance (GRC) tools such as Xacta, CSAM, RSA Archer or similar.
  • Demonstrated experience supporting FISMA compliance activities and/or federal security audits.
  • Experience collaborating with ISOs and/or ISSOs on system security documentation and A&A activities.
  • Strong written and verbal communication skills, with the ability to translate technical compliance findings into clear, actionable reporting for government stakeholders.
  • Strong organizational skills and attention to detail, particularly around documentation control and audit readiness.
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Applicants must be a U.S. citizen and eligible to obtain and maintain a Public Trust security clearance, in compliance with federal contract requirements.

Beneficial to have:

  • Experience supporting an ICAM program or similar identity governance initiative.
  • Familiarity with Federal Identity, Credential, and Access Management (FICAM) architecture, NIST SP 800-63 digital identity guidelines or OMB M-19-17 or successor ICAM policy.
  • Relevant certifications such as CompTIA Security+, Certified Authorization Professional (CAP), Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA).
  • Experience supporting continuous monitoring programs or cATO initiatives.
  • Prior experience in a federal contracting environment supporting a civilian or defense agency.

Where it’s done:

  • Remote (Herndon, VA).

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Compliance Analyst Related jobs

Other jobs at ShorePoint Inc

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.