> Markdown version of [/jobs/ext/2578339-cybersecurity-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2578339-cybersecurity-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Analyst - **Company:** Amro Fabricating Corporation - **Location:** Huntington Beach, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Artificial Intelligence, JIRA, Microsoft Outlook, Software as a Service, Software Documentation, CompTIA Security+, Cyber Security, Information Systems, Information Technology Audit, Information Systems Security Architecture Professional, Microsoft PowerPoint, Microsoft SharePoint, Enterprise Software Applications, IT General Controls (ITGC), Office365, Information Technology, Data Management, Servicenow - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/88bad66a-3d18-4d0e-85fb-eb771fa6e16c ## About the Role * Bachelor's degree in cybersecurity, information technology, information systems, business, risk management, accounting, audit, or a related field; equivalent relevant experience may be considered. * 5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines. * Experience assessing control design, operating effectiveness, and evidence sufficiency and translating findings into practical remediation and leadership reporting. * Working knowledge of CMMC Level 2, NIST SP 800-171, DFARS, CUI, SOX IT or comparable regulated control environments. * Experience maintaining cybersecurity policies, control narratives, SSPs or equivalent system documentation, evidence repositories, risk registers, Plans of Action and Milestones (POA\&Ms), and remediation trackers. * Ability to exercise independent judgment, challenge unsupported conclusions, organize complex requirements, and escalate material risk appropriately. * Strong written, analytical, presentation, and stakeholder-management skills across technical teams, business owners, auditors, assessors, vendors, sites, and executives. * Proficiency with Microsoft 365 tools, including Excel, PowerPoint, Word, Teams, SharePoint, and Outlook. Preferred Qualifications * Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment. * Experience supporting CMMC Level 2 readiness, NIST SP 800-171 assessments, DFARS compliance, CUI governance, Supplier Performance Risk System (SPRS) requirements, or defense-contractor cybersecurity needs. * Experience with SOX IT internal or external audit, control testing, information technology risk, and remediation governance. * Experience with SSPs, site-specific control documentation, specialized-asset scoping, CUI flows, system boundaries, evidence validation, and POA\&M management. * Experience with supplier cyber risk, SaaS and AI governance, M\&A due diligence, international operations, export controls, or cross-border access risk. * Experience using Governance, Risk, and Compliance (GRC) or audit platforms such as ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, or Hyperproof. * Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Governance, Risk and Compliance (CGRC), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Cybersecurity Maturity Model Certification Certified CMMC Professional (CMMC CCP), or comparable certification. This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees. ## Description Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies' core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs. This role helps drive enterprise-wide cybersecurity governance, risk, compliance, and assurance activities that strengthen control quality, evidence readiness, and risk management across Karman. You will translate regulatory, contractual, and customer requirements into clear controls and reliable evidence; independently assess control effectiveness and risk; and partner with business and technology owners to embed sustainable practices that support audit, assessment, and operational readiness. Responsibilities * Interprets and operationalizes cybersecurity, regulatory, contractual, and customer requirements with business, legal, and technology stakeholders. * Maintains cybersecurity governance artifacts including policies, standards, control documentation, mappings, ownership records, and assurance schedules. * Evaluates control design, operating effectiveness, evidence sufficiency, exceptions, and residual risk and recommends corrective actions or escalation. * Supports sustainable CMMC Level 2, NIST SP 800-171, DFARS, and Controlled Unclassified Information (CUI) obligations through assessment, evidence validation, remediation, and monitoring. * Maintains the Enterprise System Security Plan (SSP), Controlled Site Addenda, system boundaries, inventories, and supporting evidence across regulated environments. * Coordinates contractual, regulatory, and CAGE-code traceability, ensuring accurate alignment among obligations, boundaries, sites, and assessment records. * Supports Sarbanes-Oxley (SOX) Information Technology General Controls (ITGC) through narrative development, testing coordination, evidence quality, exception identification, and remediation tracking. * Governs cybersecurity risks, exceptions, remediation plans, compensating controls, and acceptance records and prepares leadership-ready materials that translate issues into decisions and business impact. * Oversees identity, access, and vulnerability governance, including coverage, aging, remediation performance, exceptions, and validation of closure across responsible teams. * Coordinates cybersecurity reviews for third-party services, Software-as-a-Service (SaaS), artificial intelligence (AI) tools, suppliers, and M\&A activities, ensuring security, privacy, data-handling, and evidence requirements are met. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)