Senior Cybersecurity Analyst
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job
Date Posted:
August 31, 2026
Space Dynamics Laboratory (SDL) is seeking an experienced Senior Cybersecurity Analyst to join our corporate Governance, Risk, and Compliance (GRC) team. This position will serve as a senior contributor responsible for leading the development and maintenance of cybersecurity documentation and policies, performing assessments, and managing continuous monitoring activities.
This role requires a strong understanding of cybersecurity risk and compliance, exceptional technical writing skills, and the ability to translate complex requirements into practical, risk-based actions.
This is an opportunity to take a leadership role in protecting information systems that support national defense, space exploration, and other mission-critical work.
Key Responsibilities Governance, Policy, and Documentation- Leads the development, review, and maintenance of corporate cybersecurity policies, standards, procedures, plans, and supporting documentation
- Ensures cybersecurity documentation accurately reflects implemented controls, organizational practices, contractual requirements, and current regulatory guidance
- Leads the maintenance of System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), control implementation narratives, assessment records, and other compliance documentation
- Establishes and maintains documentation governance practices, including document ownership, review cycles, version control, approvals, and evidence retention
- Evaluates existing documentation for consistency, completeness, and audit readiness, and lead efforts to address identified gaps
- Translates technical security implementations and federal requirements into clear, accurate, and defensible documentation
- Leads internal security assessments, control validations, self-assessments, and compliance reviews against applicable requirements
- Plans and coordinates assessment activities, including determining scope, identifying evidence requirements, interviewing control owners, validating assessment objectives, and documenting results
- Supports organizational readiness for CMMC third-party assessments, government reviews, customer assessments, and other external compliance activities
- Evaluates the design and implementation of security controls and determine whether available evidence adequately demonstrates compliance
- Identifies compliance gaps, document findings, recommend corrective actions, and communicate results to technical teams and organizational leadership
- Serves as a subject matter expert on NIST SP 800-171, CMMC, CUI protection requirements, and related federal cybersecurity frameworks
- Leads continuous monitoring activities designed to verify that security controls remain implemented and effective over time
- Develops and maintains continuous monitoring schedules, assessment plans, evidence requirements, and reporting mechanisms
- Coordinates with control owners to gather, review, and maintain evidence and artifacts supporting ongoing compliance
- Monitors changes to systems, technologies, threats, vulnerabilities, and regulatory requirements to determine their potential effect on organizational risk and compliance
- Leads the tracking and management of identified deficiencies, POA&Ms items, remediation activities, and risk-based exceptions
- Conducts cybersecurity risk assessments for information systems, business processes, third-party providers, and proposed technologies
- Analyzes assessment and monitoring results to identify trends, recurring issues, and opportunities to improve the organization’s security and compliance posture
- Prepares risk-based recommendations and clearly communicates material risks to technical and non-technical stakeholders
- Partners with information technology, engineering, legal, contracts, and business teams to integrate cybersecurity requirements into projects and operational processes
- Provides senior-level GRC guidance during system implementations, architecture reviews, technology evaluations, and organizational change initiatives
- Advises system owners and technical teams on security control requirements, documentation expectations, evidence sufficiency, and remediation strategies
- Presents assessment results, compliance status, risks, and recommended actions to management and other stakeholders
- Helps promote a culture of accountability, continuous improvement, and risk-informed decision-making throughout the organization
- Contributes to the development of security awareness and role-based compliance training materials
- Bachelor’s degree or higher in cybersecurity, information assurance, computer science, information systems, risk management, or a related field
- Five to ten years of progressive cybersecurity experience, with substantial experience in governance, risk, and compliance
- Demonstrated experience leading the development and maintenance of cybersecurity policies,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).