Security Analyst / ISSO
Job description
About the role
You will own the end-to-end cybersecurity compliance lifecycle for Lynk's most critical programs, driving the implementation and evidence collection for CMMC Level 2, NIST SP 800-171, DFARS 7012, SOC 2 Type II, and GDPR requirements. You will serve as the primary liaison between the technical teams and the C3PAO, owning the System Security Plan and Plan of Action & Milestones to ensure audit readiness at all times. In this capacity, you will conduct rigorous control assessments against all 110 NIST SP 800-171 practices, identify security gaps, and drive remediation to a compliant state. You will define, track, and report security metrics that provide clear insight into the posture of CUI-scoped systems for executive leadership. You will also manage the security policy lifecycle, ensuring documents are current, aligned with regulatory frameworks, and formally acknowledged by staff. This role requires deep collaboration with contract and legal teams to support DFARS clause adherence and customer security questionnaires. You will own the vendor risk management program, ensuring third-party relationships meet the organization's security and compliance standards.
Key facts
What you'll do
Conduct comprehensive compliance assessments of all 110 NIST SP 800-171 controls, documenting implementation and effectiveness for CMMC Level 2.
Author, maintain, and audit the System Security Plan (SSP) and Plan of Action & Milestones (POA&M) for all systems that store or process Controlled Unclassified Information.
Map existing security controls from Wazuh, ThreatDown, Tenable, ManageEngine, Active Directory GPOs, and SnipeIT to CMMC requirement families, and drive remediation for identified gaps.
Lead the preparation for CMMC Level 2 assessments, including evidence packaging, interaction with the C3PAO, and resolution of assessor findings.
Develop, update, and version control cybersecurity policies, procedures, and standards in alignment with CMMC, DFARS, SOC 2 Type II, and GDPR requirements.
Establish and report security metrics and key performance indicators to the CISO and non-technical stakeholders such as legal, contracts, and business development teams.
Provide subject matter expertise to contract teams regarding DFARS clause requirements, cybersecurity representations, and responses to customer security questionnaires.
Perform vendor and third-party risk assessments, maintaining accurate supplier risk documentation and treatment plans.
Manage the security awareness training program and phishing simulation schedule, tracking completion to satisfy CMMC mandates.
Monitor SIEM platforms for events and alerts related to CUI systems, writing and tuning detection rules to ensure robust audit logging.
Investigate security alerts generated by EDR solutions for CUI-scoped endpoints, coordinating response activities with IT operations.
Work with IT partners to ensure vulnerability findings are remediated within CMMC-mandated timeframes, tracking status and reporting outcomes.
Leverage Mobile Device Management and Active Directory to enforce device compliance, security baselines, and least-privilege access for CUI-scoped endpoints.
Maintain an authoritative asset inventory of hardware and software assets to support CMMC system boundary documentation and audit evidence.
Conduct periodic access control audits, enforcing least-privilege principles across Active Directory, single sign-on, and SaaS applications that touch CUI.
Requirements
Bring 3-6 years of cybersecurity experience with a strong focus on Governance, Risk, and Compliance, and prior experience as an Information System Security Officer or in a similarly accountable role.
Possess deep, working knowledge of NIST SP 800-171 and DFARS 7012, with the ability to independently assess, perform gap analysis, and provide evidence for all 110 controls.
Demonstrate proven experience authoring System Security Plans and POA&Ms for government-facing or highly regulated environments.
Show familiarity with the CMMC Level 2 assessment process and engagement with C3PAOs, including evidence expectations and findings remediation.
Apply hands-on SIEM experience, including writing detection rules, querying log data, and producing audit-grade evidence to satisfy AU requirements.
Apply hands-on experience with Endpoint Detection and Response tools and vulnerability scanning platforms, mapping outputs to NIST controls and generating documentation for assessors.
Demonstrate working knowledge of SOC 2 Type II and GDPR compliance requirements and their implications for controlled unclassified information.
Possess foundational cloud security knowledge, with Amazon Web Services preferred, covering IAM, CloudTrail, and access policy management.
Communicate clearly and structure information logically, producing formal policy documents and briefing non-technical executives with equal comfort.
Nice to have
Experience supporting contract teams with security questionnaires, response packages, and compliance evidence collection.
Background in the satellite communications, aerospace, or critical infrastructure sectors.
Practical notes
This is a full-time position based in Chevy Chase, Maryland, operating in a hybrid model.
The role involves access to Controlled Unclassified Information; U.S. citizenship or Lawful Permanent Resident status is required, and no security clearance is necessary at the time of hire.