Job ID: 9388
Date Posted: August 31, 2026
Space Dynamics Laboratory (SDL) is seeking an experienced Senior Cybersecurity Analyst to join our corporate Governance, Risk, and Compliance (GRC) team. This position will serve as a senior contributor responsible for leading the development and maintenance of cybersecurity documentation and policies, performing assessments, and managing continuous monitoring activities.
The successful candidate will help ensure SDL’s information systems remain aligned with applicable federal cybersecurity and contractual requirements, including NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC). This role requires a strong understanding of cybersecurity risk and compliance, exceptional technical writing skills, and the ability to translate complex requirements into practical, risk-based actions.
This is an opportunity to take a leadership role in protecting information systems that support national defense, space exploration, and other mission-critical work.
Key Responsibilities
Governance, Policy, and Documentation
- Leads the development, review, and maintenance of corporate cybersecurity policies, standards, procedures, plans, and supporting documentation
- Ensures cybersecurity documentation accurately reflects implemented controls, organizational practices, contractual requirements, and current regulatory guidance
- Leads the maintenance of System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), control implementation narratives, assessment records, and other compliance documentation
- Establishes and maintains documentation governance practices, including document ownership, review cycles, version control, approvals, and evidence retention
- Evaluates existing documentation for consistency, completeness, and audit readiness, and lead efforts to address identified gaps
- Translates technical security implementations and federal requirements into clear, accurate, and defensible documentation
Assessments and Compliance
- Leads internal security assessments, control validations, self-assessments, and compliance reviews against applicable requirements
- Plans and coordinates assessment activities, including determining scope, identifying evidence requirements, interviewing control owners, validating assessment objectives, and documenting results
- Supports organizational readiness for CMMC third-party assessments, government reviews, customer assessments, and other external compliance activities
- Evaluates the design and implementation of security controls and determine whether available evidence adequately demonstrates compliance
- Identifies compliance gaps, document findings, recommend corrective actions, and communicate results to technical teams and organizational leadership
- Serves as a subject matter expert on NIST SP 800-171, CMMC, CUI protection requirements, and related federal cybersecurity frameworks
Continuous Monitoring and Risk Management
- Leads continuous monitoring activities designed to verify that security controls remain implemented and effective over time
- Develops and maintains continuous monitoring schedules, assessment plans, evidence requirements, and reporting mechanisms
- Coordinates with control owners to gather, review, and maintain evidence and artifacts supporting ongoing compliance
- Monitors changes to systems, technologies, threats, vulnerabilities, and regulatory requirements to determine their potential effect on organizational risk and compliance
- Leads the tracking and management of identified deficiencies, POA&M items, remediation activities, and risk-based exceptions
- Conducts cybersecurity risk assessments for information systems, business processes, third-party providers, and proposed technologies
- Analyzes assessment and monitoring results to identify trends, recurring issues, and opportunities to improve the organization’s security and compliance posture
- Prepares risk-based recommendations and clearly communicates material risks to technical and non-technical stakeholders
Organizational Collaboration and Advisory Support
- Partners with information technology, engineering, legal, contracts, and business teams to integrate cybersecurity requirements into projects and operational processes
- Provides senior-level GRC guidance during system implementations, architecture reviews, technology evaluations, and organizational change initiatives
- Advises system owners and technical teams on security control requirements, documentation expectations, evidence sufficiency, and remediation strategies
- Presents assessment results, compliance status, risks, and recommended actions to management and other stakeholders
- Helps promote a culture of accountability, continuous improvement, and risk-informed decision-making throughout the organization
- Contributes to the development of security awareness and role-based compliance training materials
Required Qualifications
- Bachelor’s degree or higher in cybersecurity, information assurance, computer science, information systems, risk management, or a related field
- Five to ten years of progressive cybersecurity experience, with substantial experience in governance, risk, and compliance
- Demonstrated experience leading the development and maintenance of cybersecurity policies, standards, procedures, SSPs, POA&Ms, or comparable compliance documentation
- Demonstrated experience planning or leading cybersecurity assessments, control testing, self-assessments, audits, or continuous monitoring activities
- Strong working knowledge of NIST SP 800-171, CMMC, and the protection of Controlled Unclassified Information
- Familiarity with related cybersecurity frameworks and standards, such as NIST SP 800-53, the NIST Risk Management Framework, or comparable federal requirements
- Ability to interpret complex regulatory, contractual, and technical requirements and translate them into practical organizational controls and documentation
- Strong understanding of cybersecurity risk assessment, control validation, remediation tracking, and evidence management
- Exceptional technical writing, analytical, organizational, and communication skills
- Ability to independently manage multiple complex GRC initiatives and coordinate activities across technical and business teams
- Current CISSP certification or an equivalent advanced cybersecurity certification
- Must be a U.S. citizen
- Must be able to obtain and maintain a U.S. Government security clearance
Preferred Qualifications
- Experience preparing an organization for a CMMC C3PAO assessment, DIBCAC assessment, or comparable federal cybersecurity review
- Experience supporting or assessing information systems that process, store, or transmit CUI
- CMMC Certified Professional, CMMC Certified Assessor, or another relevant compliance or risk management certification
- Experience using GRC, evidence management, and workflow tools such as FutureFeed, Archer, Telos, Jira, or comparable platforms
- Experience managing enterprise POA&M and corrective-action processes
- Familiarity with DISA Security Technical Implementation Guides, secure configuration baselines, and system-hardening practices
- Familiarity with Microsoft Azure, Microsoft 365 Government environments, AWS GovCloud, or other regulated cloud environments
- Knowledge of FedRAMP, DFARS cybersecurity requirements, or other federal security and contracting requirements
- General familiarity with vulnerability scanning, SIEM, EDR, identity and access management, and other technical security capabilities relevant to control assessments
- Master’s degree in cybersecurity, information assurance, risk management, or a related field
*Salary Range
- $93,000 - $170,000
- Salary commensurate on education and relevant experience
This range serves as a general guideline and may vary based on factors such as role, level, location, market conditions, and individual qualifications, including job-related skills, experience, and relevant education or training. The range displayed in the job advertisement reflects the minimum and maximum target salaries across all US locations. Specific salary details for a candidate’s preferred location can be provided by the recruiter or HR manager during the hiring process.
Why Join SDL?
*SDL offers competitive salaries and a comprehensive benefits package. Visit our Benefits Page to learn more about what we offer.
SDL delivers advanced multi-domain solutions to protect national security and enable scientific discovery. Our expertise in satellites, sensors and instruments, ground systems and data processing, and autonomous systems plays a critical role in missions supporting NASA and the Department of Defense. Join our team of engineers, scientists, technicians, and business professionals in our seventh decade of delivering mission success.
At SDL, we strive to uphold a culture of respect, collaboration, empowerment, and accountability. We listen with open minds, seek to understand diverse perspectives, and engage in thoughtful dialogue. We work together by sharing knowledge, involving others, and offering support. We trust and empower our team members to take ownership, act with integrity, and be accountable. Above all, we deliver on our commitments to each other and to our mission partners.
The application window for this position is expected to remain open for approximately 7 days; however, it may be shortened or extended depending on business needs and the availability of qualified candidates. We encourage interested candidates to submit their applications promptly.
For questions, assistance, or accommodation with the application process or the DoD SkillBridge program, please contact employment@sdl.usu.edu.
Learn more about this Employer on their Career Site
