IT Security & Compliance Analyst Remote (Washington)

DEFTEC Corporation
Chesapeake, VA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Compensation
$62,400.0 - $76,960.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Data Analysis Audit Trail Business Systems Data Migration Issue Tracking Systems Information Security Management Python (Programming Language) Windows PowerShell Power BI SQL Databases Scripting
+9 more
Information Security Management System Microsoft Power Automate Microsoft InTune Information Technology Data Management Tools for Reporting Data Pipelines Plan of Action and Milestones User Accounts

Job description

The IT Security & Compliance Analyst supports the day-to-day execution of DEFTEC’s information technology and cybersecurity operations under the direction of the Director of Strategic Operations & Innovation. Serves as a primary operational coordinator with DEFTEC’s managed service provider (MSP), executes recurring security and compliance activities supporting the company’s CMMC Level 2 and NIST SP 800-171 compliance program, and contributes hands-on data and automation capability to internal tooling, reporting, and business system initiatives. This is a part-time position (approximately 24-25 hours per week) with potential for transition to full-time., * Serves as the day-to-day point of contact with DEFTEC’s managed service provider for service requests, ticket tracking, and escalation.

  • Coordinates account provisioning, license assignment, and deprovisioning requests with the MSP under established authorization thresholds.
  • Executes established onboarding and offboarding procedures to ensure timely creation and deprovisioning of user accounts, coordinated with the MSP, HR, and program management.
  • Maintains the account retention log, including Controlled Unclassified Information (CUI) access determinations and record retention timelines, in accordance with CMMC Level 2 and NIST SP 800-171 requirements.
  • Performs cadenced security reviews, including monthly audit log reviews in accordance with DEFTEC security policy, compiling reports and flagging anomalies.
  • Supports maintenance of compliance artifacts, including POA&M tracking, evidence collection, and System Security Plan updates.
  • Assists in preparation for third-party (C3PAO) assessments and customer compliance inquiries.
  • Develops and maintains asset refresh schedules, standard asset package definitions, and asset inventory records; coordinates procurement of compliant hardware through approved channels.
  • Develops training plans and cybersecurity course content; administers training assignments and certification tracking through DEFTEC’s HR platform, tracking completion to closure.
  • Supports the design, development, and maintenance of internal data pipelines, reporting tools, and business process automations using the Microsoft Power Platform.
  • Supports the evaluation and implementation of enterprise business systems, including requirements analysis, data migration, validation, and reporting.
  • Documents procedures and contributes to DEFTEC’s internal policy and SOP library.

Requirements

  • Must be a US citizen (required for work supporting Department of Defense contracts and the handling of Controlled Unclassified Information).
  • Bachelor’s degree in cybersecurity, information technology, or a related field, or an equivalent combination of education and experience.
  • Working knowledge of core cybersecurity principles, including access control, audit logging, and incident response.
  • Strong analytical and data-management skills, with the ability to compile, interpret, and present security reporting.
  • Strong written documentation skills and attention to detail.
  • Demonstrated ability to manage recurring, deadline-driven tasks independently.

Preferred Qualifications:

  • Familiarity with Microsoft 365 administration and security tools (Entra ID, Intune, Microsoft Defender, Microsoft Purview).
  • Familiarity with NIST SP 800-171, CMMC, and DFARS 252.204-7012 requirements.
  • Experience with the Microsoft Power Platform (Power Automate, Power BI) or comparable workflow automation tools.
  • Scripting or data analysis experience (e.g., Python, PowerShell, SQL).
  • Experience coordinating with managed service providers or third-party technology vendors.
  • Current or prior U.S. government security clearance, or eligibility to obtain one.

Benefits & conditions

Pulled from the full job description Tuition reimbursement Health insurance 401(k) matching Paid time off Vision insurance Dental insurance Life insurance, This position is part-time and not currently benefits-eligible. Full-time DEFTEC employees receive a comprehensive whole-life benefits package that includes medical, dental, vision, holiday, paid time off, 401K with a match, life insurance, short/long-term disability, and educational reimbursement.

About the company

DEFTEC delivers mission critical solutions through skillfully delivered services and innovative products. We are inspired by the critical missions of our clients, and we are driven to provide the most effective solutions to execute their missions, operational challenges, and requirements. Our dedicated, experienced, and talented employees work closely with our clients to ensure the delivery of exceptional services and products., DEFTEC is a Drug-Free Workplace where post-offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria are met as outlined in our policies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:57 min

Securing sensitive defense infrastructure with dual-vendor cloud strategies

Boris Hecker Boris Hecker +3 · World Congress 2025

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

Videos

See all

Related articles

See all