Information Security GRC Analyst
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Information Security
Job Overview & Responsibilities
At ULA, Information Security GRC Analyst 3 plays a critical role in supporting cybersecurity, assurance, and compliance activities for mission‑focused Aerospace and Defense programs. This role ensures the organization maintains compliance with multiple U.S. government and commercial cybersecurity frameworks—such as CNSSI 1253, NIST SP 800‑171, NIST SP 800‑172, and ISO/IEC 27001:2022—while enabling secure, resilient, and efficient operations across unclassified environments.
This midcareer position is ideal for an analytical, detail‑oriented professional with a solid grounding in risk management, cybersecurity controls, and compliance operations who is ready to take ownership of significant program responsibilities.
Key Responsibilities- Support governance, risk, and compliance activities across unclassified A&D programs.
- Translate framework requirements (CNSSI 1253, NIST 800‑171/172, ISO 27001:2022) into actionable technical and procedural controls.
- Assist with developing, maintaining, and improving System Security Plans (SSPs), POA&M, risk registers, and related artifacts.
- Participate in system categorization, control inheritance, and continuous monitoring activities for information systems and enclaves.
- Conduct risk assessments, document findings, and work with engineering and operations teams to define mitigation strategies.
- Support internal and external audits, customer assessments, and inspection readiness activities.
- Contribute to policy and procedure development and ensure alignment to regulatory, contractual, and corporate requirements.
- Monitor changes in U.S. government cybersecurity policy, DoD directives, and commercial standards; assess impact to internal environments.
- Assist with incident response processes from a compliance and documentation perspective.
- Provide GRC guidance to project teams and stakeholders while maintaining a strong customer‑service orientation.
Bachelor
Required Years of ExperienceMinimum of 4 years of related work experience
Basic Qualifications- Bachelor's degree in a STEM (Science, Technology, Engineering, Mathematics) field from an accredited college or university
- Four years of directly related exempt work experience may be used to satisfy the bachelor's degree requirement
- Working knowledge of at least two of the following frameworks: CNSSI 1253, NIST SP 800 53, NIST SP 800‑171/172, ISO/IEC 27001:2022
- Experience supporting compliance in regulated or defense‑aligned environments (DoD, IC, A&D contractors, or similar)
- Strong analytical, documentation, and communication skills
- Experience with Risk Management Framework (RMF) authorization packages or audits
- Understanding of Zero Trust principles and enhanced cybersecurity requirements under 800‑172
- Professional certifications such as Security+, CySA+, CISM, CISSP, CCP, or CCA preferred
- Experience working with cross‑functional engineering, IT, and programming teams in high‑security environments
- Prior experience with DFARS/CMMC compliance preferred
- Denver, ULA
- Cape Canaveral, ULA
- Decatur, ULA
- Vandenberg AFB only)
$ - $
What makes ULA different?Because we understand launch success comes through the collective efforts of a team, we seek the best to join us. We value ethics, ingenuity, engagement, and professional development for employees at all levels.
Benefits- 401(k) match plus an additional employer contribution
- Discretionary annual incentive bonus for eligible employees
- Generous paid time off
- Flexible work environments
Additionally, most salaried ULA team members work a "9/80 schedule," meaning they enjoy every other Friday off.
Security Clearance / International Traffic In Arms Regulations (ITAR)This position requires use of information which is subject to the International Traffic In Arms Regulations (ITAR). Therefore, all applicants must be U.S. Persons as defined in ITAR 22 CFR 120.62 (e.g., U.S. Citizen, Lawful Permanent Resident (Green Card holder) or protected individual). See 8 U.S.C. 1101(a)(20) and 8 U.S.C. 1324b(a)(3) for additional information.
Equal Opportunity EmploymentULA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment.
E‑Verify ParticipationULA is a participant in the federal E‑Verify Program. Posters in PDF format pertaining to this program can be accessed by clicking on the links identified below. E‑Verify Participation poster (English / Spanish) and Right to Work Poster (English / Spanish).
Colorado Equal Pay for Equal Work ActColorado Equal Pay for Equal Work Act requires covered employees to follow a post‑selection notification process. A hired candidate may opt out of this process by notifying the hiring manager in writing at the time the offer is accepted.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).