Logo for iZeno

Compliance & Security Analyst

Role overview

Qualifications

  • Bachelor’s degree in a related field
  • Mastery of CMMC 2.0 (Level 2) and NIST SP 800-171
  • CCP (CMMC Certified Professional) certification
  • Experience using GRC platforms (e.g., Apptega, FutureFeed, or Microsoft Purview)

Responsibilities

  • Act as the lead Point of Contact for the Overwatch Continuous Compliance program
  • Architect and author System Security Plans (SSPs)
  • Develop and manage the Plan of Action and Milestones (POAM)
  • Lead the Evidence Collection phase

Key facts

  • Remote from: United States
  • Full time
  • Security Compliance Analyst
  • English

Hard skills

Other skills

  • Communication
  • Customer Service

About the company

iZeno logo

iZeno

IT Services & IT Consulting

iZeno was founded in 2003 to provide enterprises with the best-in-class technology solutions they need to keep their business running seamlessly. With a team of 150+ in-house innovators, iZeno has delivered, implemented, and optimised over 500 Enterprise Solutions to enable smarter insights and better business outcomes. iZeno’s team draws on industry experiences in delivering a portfolio of mission-critical applications, integrating AI & machine learning, DevOps, ITSM, cloud, CRM & CX, data analytics, and other leading technologies within its clients existing IT frameworks. With a leading presence in the region, the business is headquartered in Singapore and has operations in Malaysia, Indonesia, Thailand, and the Philippines. In the year 2023, iZeno Singapore achieved the certification as a Great Place To Work. Visit our website to learn more about iZeno and discover how we can collaborate with you to expedite your Digital Transformation journey. Please also take note that iZeno will never request recruitment fees from candidates under any circumstances. Please be cautioned that individuals or organizations are misusing the iZeno brand name to demand money in exchange for interviews or employment opportunities with iZeno. Please note that these fraudulent entities are unlawfully using iZeno's brand and copyright on fake job advertisements and emails to deceive innocent victims. As a responsible organization, iZeno places great importance on conducting ethical and transparent recruitment processes. We advise all potential candidates to remain vigilant and report any suspicious activity encountered during their job search. Our commitment is to protect the interests of our candidates and our organization, and we will remain vigilant against these fraudulent attempts.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Summary

Acts as the lead Point of Contact (POC) for the Overwatch Continuous Compliance program, managing a portfolio of approximately 10 customers. Responsible for consulting with and navigating clients through the high-stakes journey of CMMC 2.0 (Level 2)—taking them to a state of total audit readiness. The Compliance & Security Analyst translates complex federal mandates into a clear, technical roadmap for the client’s leadership and IT teams.

Essential Duties and Responsibilities

  • Architects and authors System Security Plans (SSPs), the "source of truth" for the client's security posture, detailing exactly how each NIST 800-171 control is implemented.
  • Develops and manages the Plan of Action and Milestones (POAM), tracking every deficiency and guiding the client’s IT team through remediation.
  • Drafts all formal security policies, ensuring they are not just "templates" but functional, defensible documents that reflect the client’s real-world operations.
  • Designs and facilitates annual Incident Response (IR) and Disaster Recovery (DR) tabletop drills.
  • Leads the Evidence Collection phase, verifying that the client’s logs and configurations meet the rigorous sufficiency standards of a C3PAO auditor.
  • Demonstrates and actively promotes an understanding and commitment to the mission of Logicalis through performing behaviors consistent with the organization's values.
  • Maintains a working knowledge of applicable Federal, State, and Local laws and regulations as well as policies and procedures of Logicalis in order to ensure adherence in a manner that reflects honest, ethical and professional behaviors.
  • Supports and conducts self in a manner consistent with customer service expectations.
  • undefined

Supervisory Responsibilities

This job has no supervisory responsibilities.

Qualifications

To perform this job successfully, an individual should be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education/Experience/Technical Requirements/Certifications    

Equivalent combination accepted.                     

   Education

  • Bachelor’s degree in a related field.

   Experience / Technical Requirements:

  • Compliance Enclaves: Advising on how to segment CUI to limit audit scope and cost.
  • FIPS 140-2/3 Validation: Verifying that encryption modules (VPNs, Wi-Fi, Storage) meet federal standards.
  • Network Architecture: Interpreting network diagrams and identifying gaps in boundary protection and data flow.
  • Log Logic: Knowing exactly what a "passing" audit log looks like for MFA, access control, and system monitoring.
  • Framework Expert: Mastery of CMMC 2.0 (Level 2) and NIST SP 800-171.
  • Technical Writing: Superior ability to write clear, audit-proof documentation (SSPs, SOPs, and Policies).
  • Knowledge of SOC2, ISO 27001, HIPAA, or GDPR.
  • Experience using GRC platforms (e.g., Apptega, FutureFeed, or Microsoft Purview).

   Certifications:  

·       CCP (CMMC Certified Professional)

·       CISA

·       Security +

Other Skills and Abilities

  • Ability to work with C-Suite Executives and across client technical teams throughout the consulting process.
  • Portfolio Management: Proven ability to manage ~10 concurrent clients/projects without sacrificing quality or missing milestones.
  • Ability to manage through high level of ambiguity and multiple requests from variety of sources. 
  • Ability to work on multiple projects simultaneously and translate business data into digestible information that improves corporate processes.
  • Outstanding technical/business communication skills.

Physical Demands

The physical demands described here are representative of those that should be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this Job, the employee is constantly required to sit, talk, see, hear, and use hands and arms.  The employee is frequently required to stand; move about, climb steps or balance and stoop, kneel, crouch, or crawl. The employee may occasionally lift and/or move up to 10 pounds.

The above statements describe the general nature and level of work being performed by individuals assigned to this classification. This is not intended to be an exhaustive list of all responsibilities and duties required of personnel so classified.


Logicalis is an Equal Opportunity Employer. It is our policy to employ people who are qualified by reason of education, training, experience, and demonstrated performance.   We value inclusion and belonging at our company. We do not discriminate on the basis of race, color, religion, national origin, sexual orientation, gender identity and gender expression, marital status, age, height, weight, disability, veteran status, or any other reason prohibited by applicable federal or state laws.


Salary Compensation Range:  $90,321 to $120,000 annual



LogicalisUS Benefits Summary

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Compliance Analyst Related jobs

Other jobs at iZeno

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.