| Title | Cybersecurity Compliance Analyst |
|---|---|
| Department | Information Security / Security GRC / Compliance |
| Reports to | [Security Compliance Manager / GRC Manager / CISO] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Cybersecurity Compliance Analyst supports [Company]'s security compliance program, ensuring the organization meets the control requirements of applicable frameworks, regulations, and customer commitments. This role maps requirements to controls, collects evidence, tracks gaps, and helps the business stay audit-ready.
Working alongside security engineers, IT, and control owners, the analyst runs control assessments, coordinates audits and certifications, and keeps compliance documentation current. The role turns security frameworks into practical, repeatable evidence and reporting.
This is a hands-on role for a security-minded professional who enjoys structure, documentation, and working across teams to close gaps.
Key responsibilities
Framework and control mapping
- Map security requirements to a unified control set.
- Maintain the control library and framework crosswalks.
- Identify overlapping requirements across frameworks and customer commitments.
- Keep control documentation current as the environment changes.
Control assessment and evidence
Assess controls against applicable frameworks and collect the evidence needed to demonstrate they operate effectively.
- Perform periodic control self-assessments.
- Collect and organize audit evidence and artifacts.
- Track control ownership and testing cadence.
- Identify and log control gaps and deficiencies.
Audit and certification support
Coordinate SOC 2, ISO 27001, and similar audits and certifications. Prepare evidence packages, manage auditor requests, and track findings through remediation.
Gap and remediation tracking
- Maintain a register of control gaps and remediation actions.
- Work with control owners to close deficiencies.
- Report on remediation progress and residual risk.
Policy and documentation
Support the maintenance of security policies, standards, and procedures, and confirm they align to the frameworks the organization commits to.
Customer and vendor assurance
Respond to customer security questionnaires and support vendor and audit inquiries with accurate control information.
Required qualifications
- Bachelor's degree in Information Systems, Cybersecurity, or a related discipline, or equivalent experience.
- 2 to 5 years of experience in security compliance, GRC, IT audit, or information security.
- Working knowledge of common security frameworks and control concepts.
- Experience collecting audit evidence and supporting certifications.
- Strong documentation, organization, and communication skills.
- Ability to work across security, IT, and business teams.
Preferred certifications
One or more of: CompTIA Security+, CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, or equivalent.
Technical knowledge
Security control assessment, framework mapping and crosswalks, evidence collection, audit and certification support, gap and remediation tracking, security policy documentation, customer security questionnaires, and GRC platforms.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in cybersecurity compliance and controls rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Cybersecurity Compliance Analyst do?
A Cybersecurity Compliance Analyst helps an organization meet its security control obligations. They map requirements to controls, run control assessments, collect audit evidence, track gaps, and support audits and certifications such as SOC 2 and ISO 27001.
What qualifications and certifications does a Cybersecurity Compliance Analyst need?
Most bring 2 to 5 years in security compliance, GRC, or IT audit. Common certifications include CompTIA Security+, CISA, CRISC, and ISO 27001 Lead Auditor or Lead Implementer.
What frameworks does a Cybersecurity Compliance Analyst use?
Common references include the NIST Cybersecurity Framework, ISO 27001, SOC 2, NIST 800-53, and the CIS Controls, along with any customer or regulatory commitments the organization has made.
What is the difference between security compliance and security engineering?
Security engineering builds and operates the technical controls, while security compliance confirms those controls meet framework and regulatory requirements and produces the evidence to prove it. The two work closely together.