×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Compliance Analyst; Hybrid - Bay Area)

Job in Lafayette, Contra Costa County, California, 94549, USA
Listing for: Xantrion
Full Time position
Listed on 2026-09-20
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 100000 - 120000 USD Yearly USD 100000.00 120000.00 YEAR
Job Description & How to Apply Below

If you’re looking to join a winning information technology teamand receive outstanding benefits that support your family—while working for a company that takes apeople-first approach to business—we invite you to explore our Cybersecurity Compliance Analyst position.

Location:

San Francisco Bay Area

Hybrid: 2 days in office / 3 days remote per week

Primary Purpose and Function

Xantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.

This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.

Travel: None required.

Roles and Responsibilities Client Compliance and Documentation
  • Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
  • Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
  • Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
  • Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
  • Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
  • Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
  • Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
  • Maintain annual testing schedules and track documentation, review dates, and follow-up items.
  • Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
  • Improve reusable templates and assessment procedures that support consistent delivery across clients.
  • Use Xantrion-approved AI tools to increase productivity and streamline research, analysis, and documentation while maintaining accuracy and protecting confidential company and client information.
Internal Compliance Support
  • Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
  • Organize audit documentation, maintain request trackers, and follow up with internal control owners.
  • Review evidence for completeness and consistency and identify missing or outdated documentation.
  • Provide seasonal support during internal audit preparation and review periods.
Position Requirements

Required Qualifications
  • Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
  • Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
  • Experience reviewing technical configurations or administrative reports against documented standards.
  • Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
  • Strong writing…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary