1

Soc Contracting Jobs in Minnesota (NOW HIRING)

BID Proposal Specialist

Rochester, MN · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

Ensures continuity between MCL marketing, contracting, pricing, and field staff to provide an integrated client-facing proposal. Communicates project updates and information to all project team ...

Accounting Manager

Minneapolis, MN · On-site

$100K - $125K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... top 50 general contractors in the United States. Our base of operations in Minnesota is ... Manage the collection, review, and after actions related to key software partner SOC-1 audit ...

Accounting Manager

Minneapolis, MN · On-site

$100K - $125K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... top 50 general contractors in the United States. Our base of operations in Minnesota is ... Manage the collection, review, and after actions related to key software partner SOC-1 audit ...

Soc Contracting information

See Minnesota salary details

$36.7K

$60.3K

$104.3K

How much do soc contracting jobs pay per year?

As of Aug 13, 2026, the average yearly pay for soc contracting in Minnesota is $60,282.00, according to ZipRecruiter salary data. Most workers in this role earn between $49,000.00 and $62,700.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in SOC Contracting?

To thrive in SOC Contracting (Security Operations Center Contracting), you need strong knowledge of security operations, contract management, and regulatory compliance, often supported by a relevant degree and experience in security contracts. Familiarity with contract management software, security monitoring tools, and certifications such as CPP (Certified Protection Professional) or CFCM (Certified Federal Contracts Manager) are highly valuable. Attention to detail, negotiation skills, and the ability to communicate effectively with both technical and non-technical stakeholders are crucial soft skills. These capabilities ensure contracts are executed efficiently, risks are minimized, and organizational security objectives are met.

What are some common challenges faced in a SOC Contracting role?

Professionals in SOC Contracting roles often face the challenge of balancing regulatory compliance with client security requirements, ensuring all terms in the contract are both realistic and enforceable. Adapting to rapidly evolving cybersecurity threats and integrating new technology into the scope of contracts also requires constant attention. Additionally, effective communication with cross-functional teams—such as legal, IT security, and external vendors—is essential to prevent misunderstandings and ensure project success. Staying organized and keeping up with industry changes will make handling these challenges much more manageable.

What is a SOC Contracting?

A SOC Contracting job involves managing contracts and agreements related to Security Operations Centers (SOC). Professionals in this role handle negotiations, compliance, and vendor relationships to ensure cybersecurity services align with organizational and regulatory requirements. They work closely with legal, procurement, and security teams to mitigate risks and optimize contract terms. Strong negotiation skills, attention to detail, and knowledge of cybersecurity policies are essential for success in this role.

What are popular job titles related to Soc Contracting jobs in Minnesota?

For Soc Contracting jobs in Minnesota, the most frequently searched job titles are:

Infographic showing various Soc Contracting job openings in Minnesota as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $60,282 per year, or $29 per hour.

Info Systems Security Officer

skywater

Minneapolis, MN

Full-time

Posted 14 days ago


Job description

The Information Systems Security Officer provides day-to-day support to the ISSO, ISSM, and Cyber Governance, Risk, and Compliance (GRC) function across both governed environments (commercial and federal) while developing along a structured path from analyst toward security engineer. The role assists with security documentation, authorization and audit evidence, continuous monitoring records, and SOC and incident-response activity, and receives supervised, hands-on exposure to control implementation, system hardening, secure configuration, and remediation validation. This is a developmental and supervised role that supports, rather than independently owns, ISSO, ISSM, and Cyber GRC deliverables. Commercial work follows NIST CSF 2.0, CMMC, and SOX, evidenced in Drata. Federal work follows RMF, NISPOM, and DFARS 252.204-7012, and for ATO, classified, air-gapped, isolated, or CUI/FCI systems is performed only through the ISSM, ISSE, and ISSO approved authorization structure, evidenced in eMASS.

Responsibilities:

Commercial Environment (SkyWater Technology: NIST CSF 2.0, CMMC, SOX)

  • Collect, organize, index, review, and maintain control evidence across NIST CSF 2.0, CMMC, NIST SP 800-171, and SOX, supporting Cyber GRC in Drata as the commercial system of record.
  • Support commercial audit readiness, including self-assessments, control reviews, evidence refreshes, and SOX and CMMC assessment activities.
  • Track commercial findings, control deficiencies, and remediation through documented closure or approved risk disposition.
  • Assist with commercial continuous monitoring, including evidence refreshes, configuration reviews, and control-status updates in Drata.

Federal Environment (SkyWater Federal: RMF, NISPOM, DFARS 252.204-7012)

  • Support the ISSO with day-to-day maintenance of federal security artifacts, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), control implementation statements, authorization records, and Enterprise Mission Assurance Support Service (eMASS) entries.
  • Assist with eMASS package updates, evidence uploads, control-status updates, milestone tracking, and package-quality reviews.
  • Support assessment and authorization (A&A) package preparation, self-inspections, and government or customer assessment activities under ISSO and ISSM direction.
  • Assist with federal continuous monitoring aligned to NIST SP 800-53 and DFARS 252.204-7012, including evidence refreshes, vulnerability-status and security-control reviews, configuration reviews, change documentation, and authorization-package updates.
  • Preserve authorization-boundary evidence, and perform work on classified, air-gapped, isolated, or CUI/FCI systems only through approved ISSM, ISSE, ISSO, system-administration, and change-management channels.
  • Identify and report undocumented changes, configuration deviations, and missing or expired evidence affecting authorization posture; treat undocumented deviations within a boundary as potential findings and escalate to the ISSO and ISSM.
  • Support NISPOM and ICD-aligned handling, security training records, authorized-user records, and other system-specific compliance records as assigned.
  • Security Operations and Engineering Development 
  • Monitor and respond to SOC alerts and detections, and support incident response activations across commercial and federal environments, following environment-specific handling on authorized systems.
  • Work alongside Security Architecture and Engineering to gain hands-on experience with control implementation, secure configuration, and system hardening, evaluating configurations against DISA STIGs, CIS Benchmarks, and organization-approved baselines.
  • Review vulnerability scan results and configuration findings to help determine whether corrective actions adequately address identified deficiencies and support technical validation of remediation as a structured engineering-development activity.
  • Maintain accurate, traceable, assessment-ready documentation in approved systems of record, and coordinate with GRC, Security Engineering, system administrators, and system owners to collect evidence and track assigned actions.
  • Participate in structured training, mentoring, technical labs, and progressively independent assignments that build toward a security engineering role.

The job also requires performing other duties as assigned. Duties may be modified with concurrence of the Contracting Officer, contractor Program Manager and Information Systems Security Manager (ISSM).

 

Required Qualifications:

Education: Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related field.

  • Four years of relevant professional experience may be considered in place of the degree.
  • Sufficient certifications and industry training may also be considered in place of the degree.

 

Experience and Skills:

  • One or more years of relevant professional, internship, military, or substantive academic experience in cybersecurity, IT, systems administration, information assurance, or federal compliance support.
  • Exposure to federal information-security requirements, cybersecurity controls, or the NIST Risk Management Framework, and to maintaining organized technical documentation or compliance evidence.
  • Foundational familiarity with the NIST 800 series (including SP 800-53 and SP 800-171) and the NIST Risk Management Framework and authorization lifecycle.
  • Basic understanding of security controls, continuous monitoring, assessment evidence, and findings management.
  • Basic systems-administration aptitude across Windows, Linux, networking, identity, or cloud domains.
  • Strong documentation, organization, and evidence-handling discipline, with the ability to work within defined authorization and change-management structures.
  • Effective communication with technical, compliance, and leadership stakeholders, and working knowledge of Microsoft Word, Excel, and PowerPoint.
  • Demonstrated interest in developing toward a security engineering role.

 

Certifications & DoD Framework:

  • CompTIA Security+ CE required at the time of hire or within six months of the date of hire (preferred minimum certification).
  • Must meet applicable DoD 8140.03 and DoD Cyber Workforce Framework qualification requirements for the assigned work role and proficiency level, at minimum equivalent to the legacy DoD 8570.01-M Information Assurance Technician Level II baseline and complete any component- or customer-specific requirements for the assigned role.

 

Clearance & Security Requirements

  • US Citizen with minimum Secret Clearance eligibility (TS/SCI preferred). Must be able to obtain and maintain the clearance and system access required for assigned duties.
  • Must comply with need-to-know, information-handling, personnel-security, facility-security, and authorized-system requirements, and perform federal-system work only within the assigned ISSM, ISSE, and ISSO authorization structure.
  • Occasional travel up to 10% may be required.

Desired Qualifications:

Education:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related engineering-adjacent field.

 

Experience:

  • Two to three years in IT, systems administration, security operations, federal compliance, or information assurance.
  • Hands-on support of eMASS entries, SSP maintenance, POA&M tracking, evidence collection, control assessments, or continuous monitoring, in a government-contractor, cleared, regulated, CUI, or classified environment.
  • Experience supporting technical remediation, vulnerability management, system hardening, or configuration validation, and personal lab, scripting, or homelab experience demonstrating initiative.

 

Skills and Certifications:

  • Basic scripting using PowerShell, Python, Bash, or an equivalent language, and familiarity with DISA STIGs, CIS Benchmarks, and secure configuration practices.
  • Familiarity with Windows or Linux administration, Active Directory, Microsoft Entra ID, networking, cloud, virtualization, or endpoint management, and with vulnerability scanners, GRC platforms (Drata), or authorization systems (eMASS).

 

 

Physical Requirements & Environmental Conditions:

Ability to perform standard office and workstation functions, including extended computer use, documentation review, data entry, technical analysis, and virtual collaboration, with on-site engagements as needed. The position may require access to secure facilities, controlled work areas, authorized information systems, and air-gapped or isolated environments. Reasonable accommodation will be made for qualified individuals with disabilities.