1

Cyber Security Compliance Analyst Jobs (NOW HIRING)

Cybersecurity Compliance Analyst

Suitland, MD ยท On-site

$115K - $125K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Cybersecurity Compliance Analyst ISSO Support Continuous Monitoring Security Control Assessments Location: Suitland, MD (Hybrid) Work Schedule: Full-Time Hybrid (3 Days On-Site / 2 Days Telework ...

New

Cybersecurity Compliance Analyst

Suitland, MD ยท On-site

$115K - $125K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Cybersecurity Compliance Analyst ISSO Support | Continuous Monitoring | Security Control Assessments Location: Suitland, MD (Hybrid) Work Schedule: Full-Time | Hybrid (3 Days On-Site / 2 Days ...

Posted today

Principal Cybersecurity Compliance Analyst

Oakland, CA ยท On-site

$150K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client's generation assets. This role will focus on ensuring adherence to regulatory ...

Principal Cybersecurity Compliance Analyst

Roseville, CA

$150K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client's generation assets. This role will focus on ensuring adherence to regulatory ...

Principal Cybersecurity Compliance Analyst

Sacramento, CA

$150K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client's generation assets. This role will focus on ensuring adherence to regulatory ...

Principal Cybersecurity Compliance Analyst

Roseville, CA ยท On-site

$150K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client's generation assets. This role will focus on ensuring adherence to regulatory ...

Principal Cybersecurity Compliance Analyst

Roseville, CA ยท On-site

$150K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Principal Cybersecurity Compliance Analyst, you will support critical compliance initiatives across a client's generation assets. This role will focus on ensuring adherence to regulatory ...

$94K - $137K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

Cybersecurity Compliance Analyst As a Cybersecurity Compliance Analyst, you will support the Airports Authority's cybersecurity compliance with applicable laws, regulations, contractual requirements ...

Compliance Analyst

Mooresville, NC ยท On-site

  • Medical

  • Life

  • Retirement

  • PTO

This role will support cybersecurity compliance efforts across multiple business units, offices ... analyze, design and manufacture products for aerospace, DoD, and commercial customers. We offer a ...

Compliance Analyst

Mooresville, NC ยท On-site

  • Medical

  • Life

  • Retirement

  • PTO

This role will support cybersecurity compliance efforts across multiple business units, offices ... analyze, design and manufacture products for aerospace, DoD, and commercial customers. We offer a ...

next page

Showing results 1-20

Cyber Security Compliance Analyst information

See salary details

$43K

$99.4K

$150K

How much do cyber security compliance analyst jobs pay per year?

As of Aug 14, 2026, the average yearly pay for cyber security compliance analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is the difference between Cyber Security Compliance Analyst vs Cyber Security Auditor?

AspectCyber Security Compliance AnalystCyber Security Auditor
CertificationsCompTIA Security+, CISSP, CISACISA, CISSP, CRISC
Work EnvironmentCorporate, IT departments, compliance teamsAudit firms, consulting agencies, internal audit teams
Primary FocusEnsuring compliance with security standards and policiesAssessing security controls and identifying vulnerabilities
Industry UsageFinance, healthcare, government, any regulated industrySimilar industries, often within audit or consulting firms

While both roles focus on security standards, the Cyber Security Compliance Analyst primarily ensures organizations meet regulatory requirements and internal policies. In contrast, the Cyber Security Auditor evaluates the effectiveness of security controls through audits. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and approach.

What are the key skills and qualifications needed to thrive as a cyber security compliance analyst, and why are they important?

To thrive as a Cyber Security Compliance Analyst, you need a solid understanding of information security principles, risk management frameworks, and regulatory requirements such as GDPR, HIPAA, or PCI-DSS, often supported by a degree in cybersecurity or related fields. Familiarity with compliance management tools, security assessment platforms, and certifications like CISSP, CISA, or CompTIA Security+ is typically required. Attention to detail, strong analytical thinking, and effective communication are vital soft skills for interpreting regulations and collaborating with stakeholders. These competencies ensure organizations maintain regulatory compliance and protect sensitive data from evolving cyber threats.

What are some of the key challenges a cyber security compliance analyst faces when ensuring ongoing adherence to regulatory standards?

Cyber Security Compliance Analysts often face challenges such as keeping up with frequently changing regulations, managing documentation for multiple frameworks (like GDPR, HIPAA, or PCI DSS), and ensuring that technical teams remain aligned with compliance requirements. Balancing the need for robust security controls with business efficiency can also be demanding, as can communicating complex compliance requirements to non-technical stakeholders. Success in this role often depends on strong organizational skills, continuous learning, and effective collaboration across IT, legal, and business units.

What does a cyber security compliance analyst do?

A Cyber Security Compliance Analyst ensures that an organization's information systems follow applicable laws, regulations, and internal security policies. They assess security risks, conduct audits, and help implement controls to safeguard sensitive data. These analysts also prepare compliance reports and work with teams to address any gaps or vulnerabilities. Their work is vital for organizations to avoid legal penalties and maintain trust with customers and partners.
More about Cyber Security Compliance Analyst jobs

What cities are hiring for Cyber Security Compliance Analyst jobs?

Cities with the most Cyber Security Compliance Analyst job openings:

What states have the most Cyber Security Compliance Analyst jobs?

States with the most job openings for Cyber Security Compliance Analyst jobs include:

What job categories do people searching Cyber Security Compliance Analyst jobs look for?

The top searched job categories for Cyber Security Compliance Analyst jobs are:

Infographic showing various Cyber Security Compliance Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $99,400 per year, or $47.8 per hour.

Cybersecurity Compliance Analyst

RCG

Suitland, MD โ€ข On-site

$115K - $125K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Cybersecurity Compliance Analyst
ISSO Support Continuous Monitoring Security Control Assessments
Location: Suitland, MD (Hybrid)
Work Schedule: Full-Time Hybrid (3 Days On-Site / 2 Days Telework)
Clearance Requirement: U.S. Citizenship Required Must be Eligible to Obtain a Secret Clearance
Salary Range: $115,000 - $125,000
Who We Are
At RCG, Inc., we're more than just a federal contracting company-we're a team of innovators, problem-solvers, and collaborators dedicated to delivering exceptional technology solutions that support critical government missions.
We're proud to have been Certifiedโ„ข as a Great Place to Workยฎ for four consecutive years, a recognition that reflects our commitment to fostering a culture of trust, collaboration, inclusion, and professional growth. We believe our people are our greatest strength, and we're committed to creating an environment where employees can build rewarding careers while making a meaningful impact.
The Opportunity
RCG is seeking a Cybersecurity Compliance Analyst to support Information System Security Officers (ISSOs) in maintaining cybersecurity compliance for assigned federal FISMA systems.
This role is focused on the day-to-day coordination and execution of cybersecurity compliance activities, including Continuous Monitoring, Security Control Assessments (SCAs), RMF and A&A/ATO support, POA&M tracking, vulnerability remediation, and security documentation.
The successful candidate will work under the direction of the ISSO and collaborate closely with System Owners, engineers, system administrators, and other technical stakeholders to ensure cybersecurity documentation, evidence, and supporting artifacts are complete, current, accurate, and ready for Government or assessor review.
What You'll Do
Cybersecurity Compliance & Continuous Monitoring
  • Provide day-to-day cybersecurity compliance and systems-analysis support to assigned ISSOs and FISMA systems.
  • Prepare, maintain, and update Continuous Monitoring schedules, trackers, packages, and supporting documentation.
  • Collect, organize, review, and track security-control evidence and supporting artifacts for recurring compliance activities.
  • Maintain compliance calendars, action-item logs, deliverable trackers, and status reports for ISSO review.
  • Identify missing, overdue, or incomplete compliance requirements and escalate risks, deficiencies, or schedule concerns to the ISSO.
  • Support recurring compliance meetings, cybersecurity data calls, assessment activities, and status reporting.
Security Control Assessments & Audit Readiness
  • Prepare Security Control Assessment documentation and evidence packages.
  • Coordinate security-control evidence and artifact requests with system and technical stakeholders.
  • Maintain assessment trackers and document outstanding evidence requests.
  • Track SCA findings through remediation and closure.
  • Review cybersecurity documentation and supporting artifacts for completeness, consistency, currency, and readiness for Government or assessor review.
  • Support audit and assessment readiness by maintaining complete, current, and traceable documentation and evidence for internal and external reviews, assessments, inspections, and authorization activities.
RMF, A&A & Security Documentation
  • Support NIST Risk Management Framework (RMF) and Assessment & Authorization (A&A)/Authority to Operate (ATO) activities.
  • Develop, update, and perform quality reviews of cybersecurity documentation, including:
    • System Security Plans (SSPs)
    • FIPS 199/200 documentation
    • Risk assessments
    • Security-control implementation statements
    • Authorization artifacts
  • Review system Change Requests and support the preparation and tracking of Security Threshold Analysis (STA) and Security Impact Analysis (SIA) documentation.
  • Coordinate updates to cybersecurity documentation resulting from system or configuration changes.
  • Maintain accurate cybersecurity records and compliance information in JSAM and other Government-designated repositories and tracking tools.
POA&M & Vulnerability Remediation
  • Support the creation, maintenance, and status tracking of Plans of Action and Milestones (POA&Ms).
  • Track remediation activities, supporting evidence, milestones, and closure documentation.
  • Review vulnerability findings and track patching, configuration hardening, and remediation activities.
  • Coordinate with technical teams to obtain supporting evidence demonstrating remediation.
  • Ensure applicable POA&M records and supporting documentation remain accurate and current for ISSO review.
Stakeholder Coordination
  • Coordinate with ISSOs, System Owners, engineers, system administrators, and other technical stakeholders to obtain required compliance documentation and evidence.
  • Track outstanding actions and follow up with responsible stakeholders to ensure compliance deadlines are met.
  • Communicate compliance status, outstanding requirements, and potential schedule concerns clearly and accurately.
  • Provide organized and timely information to support ISSO decision-making and Government reporting requirements.

Requirements
What We're Looking For
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, or a related field. An equivalent combination of education and relevant experience may be considered based on applicable labor-category requirements.
  • Experience supporting cybersecurity compliance, federal FISMA systems, security documentation, Continuous Monitoring, Security Control Assessments, or related RMF activities.
  • Working knowledge of:
    • NIST Risk Management Framework (RMF)
    • NIST SP 800-53
    • FISMA
    • FIPS 199/200
    • Assessment & Authorization (A&A) / Authority to Operate (ATO)
    • Continuous Monitoring
    • POA&M management
    • Security Control Assessment processes
  • Experience developing, reviewing, maintaining, and tracking cybersecurity documentation and supporting evidence.
  • Experience supporting vulnerability remediation and compliance tracking.
  • Strong documentation, organization, quality-review, and stakeholder-coordination skills.
  • Ability to manage multiple compliance activities, deliverables, and deadlines while maintaining accurate records and supporting evidence.
  • Strong written and verbal communication skills.
  • Ability to work effectively with both cybersecurity and technical infrastructure teams.
  • U.S. Citizenship required.
  • Must be eligible to obtain and maintain a Secret clearance.

Preferred Qualifications
  • Experience supporting federal government cybersecurity or information assurance programs.
  • Experience using JSAM or similar Government cybersecurity compliance and tracking systems.
  • Experience supporting Security Control Assessments, audits, inspections, and authorization activities.
  • Experience supporting vulnerability management and POA&M remediation activities.
  • CompTIA Security+ or an equivalent certification meeting applicable labor-category requirements.
  • Additional certifications such as CGRC, CISA, CISM, CISSP, or relevant cloud-security certifications are desirable based on assignment.

Role Alignment
The Cybersecurity Compliance Analyst supports the ISSO by preparing, reviewing, coordinating, and tracking cybersecurity documentation, evidence, assessment materials, remediation activities, and compliance status information.
This position supports-but does not replace-the ISSO function. Cybersecurity risk determinations, formal security advisory responsibilities, and approval or risk-acceptance decisions remain with the ISSO or designated Government authority.
Work Environment
  • Hybrid position based in Suitland, Maryland.
  • Three (3) days per week on-site and two (2) days telework, subject to contract and customer requirements.
  • Full-time position supporting mission-critical federal cybersecurity programs.
  • Collaborative environment requiring regular coordination with ISSOs, System Owners, engineers, system administrators, cybersecurity personnel, and Government stakeholders.

Benefits
  • Health, vision and dental Insurance
  • Paid Time Off
  • 401k
  • Education, Training & Development
  • Collaborative, supportive, and inclusive work environment.

Equal Opportunity Employer
RCG, Inc. is an Equal Opportunity Employer. We are committed to creating an inclusive workplace and providing equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the position.