Apply Edge Start your job search

Cybersecurity/GRC Compliance Analyst

Crawford Thomas Recruiting · Orlando, FL

Apply & track with Apply Edge
Cybersecurity Compliance Analyst – Orlando, FLSalary: $80,000–$100,000 base + 25% bonusLocation: Onsite in Orlando, FL 32810This role does not offer relocation assistance. Candidates must already reside within commuting distance of the Orlando area.SummaryOur client is a rapidly growing cybersecurity company seeking a Cybersecurity Compliance Analyst to support governance, risk, compliance, and audit readiness initiatives across the organization.What You’ll DoWork heavily within frameworks like NIST CSF, NIST 800-53, NIST 800-171, RMF, FedRAMP, ISO 27001, SOC 2, and STIGSupport audits by gathering evidence, validating controls, tracking remediation items, and working directly with auditorsComplete customer security questionnaires and support security reviews tied to sales opportunitiesReview access controls, PAM processes, vulnerability scans, and continuous monitoring activitiesHelp assess vendor risk and third-party security postureWork with infrastructure, development, MDR/SOC, IT, leadership, and business teams to validate controls and resolve compliance gapsHelp manage policies, documentation, ownership, retention standards, and version controlTrack compliance and audit-related tasks through resolution across multiple teamsSupport FedRAMP and other compliance readiness initiatives in a fast-moving environmentHelp balance security requirements with business needs instead of acting as a blockerWhat You Bring6+ years of experience in cybersecurity, GRC, IT compliance, cyber risk, audit, or related environmentsStrong understanding of governance, risk, and compliance concepts, including control frameworks, audit lifecycle activities, risk management, and access governanceAbility to explain and differentiate frameworks such as NIST CSF, NIST 800-53, NIST 800-171, RMF, ISO 27001, SOC 2, FedRAMP, and STIGExperience supporting or participating in audits, evidence review, remediation tracking, policy governance, or compliance programsFamiliarity with PAM, identity/access governance, vulnerability management, access reviews, and continuous monitoring processesStrong communication skills with the ability to work across technical and non-technical teamsAbility to stay composed and think critically in high-pressure audit and compliance environmentsCollaborative, solutions-oriented mindset with the ability to balance security requirements and business objectivesComfortable operating in fast-paced, high-growth environments with shifting prioritiesPreferred BackgroundsCybersecurity consultingGRC or IT complianceSecurity compliance analystInternal IT auditMSSP/MDR environmentsSaaS, healthcare tech, fintech, cloud, or regulated industriesFedRAMP, healthcare, financial services, or regulated enterprise environmentsWho This Is ForSomeone with a cybersecurity compliance or GRC background who wants to stay close to real-world security operations and enterprise riskSomeone technical enough to understand security controls, but who also enjoys governance, audits, frameworks, and cross-functional collaborationSomeone who can communicate clearly, operate calmly under pressure, and work effectively in a fast-moving audit environmentSomeone who is coachable, grounded, solutions-oriented, and comfortable taking ownership in a high-accountability environment,