โ† back to jobs
> job detail
D
๐Ÿ‘ฝOther

IT Security & Compliance Analyst

Deftec ยท 23324, US
// classified as
Other (Adjacent or hard to classify.)
posted
2d ago
location
23324, US
languages
python
tools
โ€”
> stack
python
> description

IT Security & Compliance Analyst

Remote (Washington State)


DEFTEC delivers mission critical solutions through skillfully delivered services and innovative products. We are inspired by the critical missions of our clients, and we are driven to provide the most effective solutions to execute their missions, operational challenges, and requirements. Our dedicated, experienced, and talented employees work closely with our clients to ensure the delivery of exceptional services and products.


POSITION OVERVIEW

The IT Security & Compliance Analyst supports the day-to-day execution of DEFTEC's information technology and cybersecurity operations under the direction of the Director of Strategic Operations & Innovation. Serves as a primary operational coordinator with DEFTEC's managed service provider (MSP), executes recurring security and compliance activities supporting the company's CMMC Level 2 and NIST SP 800-171 compliance program, and contributes hands-on data and automation capability to internal tooling, reporting, and business system initiatives. This is a part-time position (approximately 24-25 hours per week) with potential for transition to full-time.


JOB RESPONSIBILITIES:

  • Serves as the day-to-day point of contact with DEFTEC's managed service provider for service requests, ticket tracking, and escalation.
  • Coordinates account provisioning, license assignment, and deprovisioning requests with the MSP under established authorization thresholds.
  • Executes established onboarding and offboarding procedures to ensure timely creation and deprovisioning of user accounts, coordinated with the MSP, HR, and program management.
  • Maintains the account retention log, including Controlled Unclassified Information (CUI) access determinations and record retention timelines, in accordance with CMMC Level 2 and NIST SP 800-171 requirements.
  • Performs cadenced security reviews, including monthly audit log reviews in accordance with DEFTEC security policy, compiling reports and flagging anomalies.
  • Supports maintenance of compliance artifacts, including POA&M tracking, evidence collection, and System Security Plan updates.
  • Assists in preparation for third-party (C3PAO) assessments and customer compliance inquiries.
  • Develops and maintains asset refresh schedules, standard asset package definitions, and asset inventory records; coordinates procurement of compliant hardware through approved channels.
  • Develops training plans and cybersecurity course content; administers training assignments and certification tracking through DEFTEC's HR platform, tracking completion to closure.
  • Supports the design, development, and maintenance of internal data pipelines, reporting tools, and business process automations using the Microsoft Power Platform.
  • Supports the evaluation and implementation of enterprise business systems, including requirements analysis, data migration, validation, and reporting.
  • Documents procedures and contributes to DEFTEC's internal policy and SOP library.

QUALIFICATIONS:

Required Qualifications:

  • Must be a US citizen (required for work supporting Department of Defense contracts and the handling of Controlled Unclassified Information).
  • Bachelor's degree in cybersecurity, information technology, or a related field, or an equivalent combination of education and experience.
  • Working knowledge of core cybersecurity principles, including access control, audit logging, and incident response.
  • Strong analytical and data-management skills, with the ability to compile, interpret, and present security reporting.
  • Strong written documentation skills and attention to detail.
  • Demonstrated ability to manage recurring, deadline-driven tasks independently.

Preferred Qualifications:

  • Familiarity with Microsoft 365 administration and security tools (Entra ID, Intune, Microsoft Defender, Microsoft Purview).
  • Familiarity with NIST SP 800-171, CMMC, and DFARS 252.204-7012 requirements.
  • Experience with the Microsoft Power Platform (Power Automate, Power BI) or comparable workflow automation tools.
  • Scripting or data analysis experience (e.g., Python, PowerShell, SQL).
  • Experience coordinating with managed service providers or third-party technology vendors.
  • Current or prior U.S. government security clearance, or eligibility to obtain one.

This position is part-time and not currently benefits-eligible. Full-time DEFTEC employees receive a comprehensive whole-life benefits package that includes medical, dental, vision, holiday, paid time off, 401K with a match, life insurance, short/long-term disability, and educational reimbursement.

DEFTEC is a Drug-Free Workplace where post-offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria are met as outlined in our policies.


AAP/EEO Statement

DEFTEC Corp is an Equal Opportunity and Affirmative Action Employer and prohibits discrimination and harassment of any type based on actual or perceived race, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, and medical conditions related to pregnancy, childbirth or breastfeeding), gender, gender identity, and gender expression, religious creed, disability (mental and physical) including HIV and AIDS, medical condition (cancer and genetic characteristics), genetic information, age, marital status, civil union status, sexual orientation, military and veteran status, denial of family and medical care leave, arrest record and/or any other characteristic(s) protected by federal, state or local law.