Point your AI agent at freehire and let it find you a job.

Get the CLI →

iceye-us-jobs

NewBe an early applicant

Cybersecurity Compliance Analyst

Posted
Discussion

Summary

Cybersecurity Compliance Analyst at ICEYE US (SAR satellite operator) who maintains compliance programs like CMMC, NIST SP 800-171, ISO 27001, and SOC 2 — collecting audit evidence, running control assessments and gap analyses, tracking POA&Ms/remediation, and supporting internal and external audits. On-site role in Irvine working with Cybersecurity, IT, Engineering, and Legal stakeholders.

Cybersecurity Compliance Analyst

At ICEYE, we design, build and operate the largest fleet of Synthetic Aperture Radar (SAR) satellites in the world. Using advanced technology, our constellation collects topographical data about any location on Earth, day or night, through any weather conditions.

Headquartered in Southern California, our customers are society’s heroes – intelligence professionals, warfighters, first responders, and scientific researchers. As a trusted mission partner, the United States and its allies depend on us for critical information when it matters most.

Role Description

The Cybersecurity Compliance Analyst is responsible for supporting and maintaining ICEYE US cybersecurity compliance programs through continuous assessment, documentation, evidence management, and audit readiness activities. This role works closely with Cybersecurity, IT, Engineering, DevOps, Legal, and other business stakeholders to evaluate security controls and demonstrate compliance with applicable regulatory, contractual, customer, and industry requirements. The position supports internal and external assessments by maintaining accurate compliance artifacts, identifying control gaps, and tracking remediation activities through completion. This role is a key contributor to ensuring ICEYE US can continuously demonstrate an effective and sustainable cybersecurity compliance posture.

Responsibilities

  • Coordinate ongoing compliance activities for cybersecurity frameworks and requirements including CMMC, NIST SP 800-171, NIST CSF, ISO 27001, SOC 2, and applicable customer or contractual requirements.

  • Collect, review, validate, organize, and maintain cybersecurity compliance evidence and supporting documentation.

  • Perform security control assessments, gap analyses, and compliance reviews to identify deficiencies and areas requiring remediation in coordination with the Head of Cybersecurity.

  • Track identified compliance findings, corrective actions, Plans of Action and Milestones (POA&Ms), and remediation activities through closure.

  • Support internal audits, external assessments, customer security reviews, regulatory examinations, and third-party compliance activities.

  • Maintain policies, procedures, standards, system documentation, control narratives, and other artifacts required to demonstrate compliance.

  • Coordinate with control owners and technical teams to obtain evidence, validate control implementation, and document how cybersecurity requirements are satisfied.

  • Support the completion and validation of customer security questionnaires, due diligence requests, and other cybersecurity compliance inquiries.

  • Maintain cybersecurity compliance records and supporting artifacts within applicable Governance, Risk, and Compliance (GRC) platforms or repositories.

  • Monitor changes to applicable cybersecurity requirements and assist with updating controls, documentation, policies, and compliance activities accordingly.

  • Prepare compliance status reporting, metrics, risk summaries, and remediation updates for the Head of Cybersecurity and other stakeholders.

  • Support continuous improvement of cybersecurity governance, compliance processes, evidence collection, control monitoring, and audit readiness.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, Information Systems, Business, Risk Management, or a related discipline, or equivalent relevant professional experience.

  • 2+ years of experience in cybersecurity compliance, governance, risk management, IT audit, information security, or a related GRC function.

  • Experience supporting cybersecurity compliance activities against frameworks or standards such as NIST SP 800-171, CMMC, NIST CSF, ISO 27001, SOC 2, or comparable requirements.

  • Experience collecting and maintaining audit evidence, compliance documentation, policies, procedures, control narratives, or other governance artifacts.

  • Experience performing control assessments, gap analyses, audit support, or remediation tracking.

  • Ability to interpret cybersecurity requirements and work with technical and business stakeholders to document how security controls are implemented and maintained.

  • Current U.S. Government security clearance or eligibility to obtain and maintain the level of clearance required for the position.

Preferred Qualifications

  • Experience supporting CMMC Level 2 or NIST SP 800-171 compliance programs.

  • Experience supporting external cybersecurity audits, C3PAO assessments, customer assessments, or regulatory examinations.

  • Familiarity with NIST SP 800-53, NIST RMF, DFARS cybersecurity requirements, or other U.S. Government cybersecurity requirements.

  • Experience working with Governance, Risk, and Compliance (GRC) platforms.

  • Experience developing or maintaining System Security Plans (SSPs), POA&Ms, control matrices, policies, procedures, or assessment documentation.

  • Experience supporting cybersecurity compliance within the aerospace, defense, government contracting, or other regulated industries.

  • Familiarity with Governance, Risk, and Compliance (GRC) platforms, with a strong preference for hands-on experience administering or supporting compliance programs within Vanta.

  • Familiarity with cloud and enterprise technology environments such as AWS, Microsoft Azure, and Microsoft 365.

  • Experience with third-party risk management, customer security questionnaires, or vendor security assessments.

  • Relevant certification such as Security+, CISA, CRISC, CGRC, CMMC CCP, or equivalent.

Pay Range and Compensation Package

  • The estimated base salary range for this role is $65,000 - $85,000 depending on experience

  • Other benefits include health coverage, flexible PTO, a friendly work environment, plus extra fun perks!

Physical Requirements

This position primarily works in an office environment. It requires the ability to sit or stand for long periods of time and frequent walking. Daily use of a computer, phone, office equipment and other computing and digital devices is required. Some travel may be necessary – the ability to travel by car, plane, train, bus, vessel, or metro, operate a motor vehicle and maintain a valid Driver’s License and/or effectively navigate public transportation is required.

While performing the responsibilities of the job, the employee must be able to read and respond to inter-office communications as well as effectively participate in meetings. The employee is often required to sit and use their hands or fingers, to lift up to 50 lbs., pull, push, carry, handle, or feel. The employee is required to carry, handle items, reach with arms and hands, to stoop, kneel, or crouch; talk, or hear. Mental demands may require prolonged concentration, reading comprehension, understanding and interpretation of concepts, ideas, and philosophies. The physical demands of the position described herein are essential functions of the job and employees must be able to successfully perform these tasks for extended periods. Reasonable accommodations may be made for those individuals with real or perceived disabilities to perform the essential functions of the job described unless such accommodations would cause ICEYE US an undue burden.

EEO Statement

ICEYE US is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected characteristic under federal, state, or local law.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available