Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Complete Turbine Services

IT GRC Analyst Level II

Career Insights for Technical Consultant / Analyst

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Florida data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Technical Consultant or Analyst provides information technology consulting services to businesses and organizations. Advises or manages installation or expansion of computer network systems; provides problem-solving assistance and staff training with new systems. May work independently or as part of a consulting team.

$93,923 / year median in Florida

-0% projected decline

Explore Career

Job Description

IT GRC Analyst Level II Complete Turbine Services - 1.0 Coral Springs, FL Job Details 18 hours ago Qualifications Government information & network security CMMC Internal controls Information security audit implementation Standard Operating Procedures (SOPs) implementation Technical documentation Governance, risk, and compliance (GRC) software Public Cloud DoD experience NIST standards Virtualization Log analysis tools Compliance documentation IT control testing Cloud compliance SIEM Regulatory compliance analysis Standard operating procedures (SOPs) Information security auditing Active Directory Standard operating procedures drafting Full Job Description Position Overview The IT GRC Analyst (CMMC Control Specialist) is responsible for the daily monitoring, operational testing, and ongoing compliance analysis of the organization's cybersecurity controls. Rather than developing high-level enterprise security policies, this operational role focuses on hands-on control execution, reviewing technical logs, verifying evidence, and authoring, maintaining, and updating granular Standard Operating Procedures (SOPs). This position ensures that hybrid IT environments, cloud enclaves, and technical infrastructure continuously satisfy CMMC Level 2 and
NIST SP 800-171
requirements through standardized, repeatable processes.
Key Responsibilities SOP Development, Maintenance & Operationalization:
Draft, review, and continuously refine detailed Standard Operating Procedures (SOPs) that translate complex
NIST SP 800-171
controls into step-by-step technical workflows for IT staff. Audit operational practices regularly to ensure procedural alignment with active SOPs, updating documentation whenever technical environments or baseline configurations evolve. Maintain the centralized repository of GRC SOPs, work instructions, and execution templates, ensuring version control and strict alignment with the enterprise System Security Plan (SSP). Partner with System Administrators and IT Operations to convert POA&M remediation outcomes into formalized, repeatable SOPs to prevent recurring compliance gaps. Daily Control Monitoring & Evidence Analysis Perform daily, weekly, and monthly operational reviews of technical controls across all 14 NIST
SP 800-171
practice domains (e.g., auditing SIEM logs, validating MFA enforcement, and reviewing access requests) in accordance with established SOPs . Collect, inspect, and archive technical artifacts and evidence (configuration baselines, backup logs, patch records) to maintain continuous audit readiness. Identify, document, and report control drift or non-compliance issues across hybrid Active Directory, cloud environments (GCC High/Azure), and virtualization platforms. Execute recurring internal control tests to verify that technical safeguards operate as documented in the SSP and procedural guidelines. Risk Tracking & POA&M Execution Track and validate the daily progress of remediation items listed on the active Plan of Action & Milestones (POA&M). Collaborate directly with System Administrators and IT Operations to test and verify fixed items before closing out open POA&M entries. Monitor daily CUI flow paths and enclave access logs to verify that Controlled Unclassified Information (CUI) boundary controls remain strictly enforced. Conduct routine vendor risk checks, verifying that subcontractors maintain active compliance with
DFARS 252.204-7012 / 7020
flow-down requirements. Audit Support & Reporting Analyze compliance data to support regular SPRS score updates and internal readiness reporting. Serve as the primary hands-on evidence and procedural coordinator during internal compliance reviews, DIBCAC audits, and external C3PAO assessments. Generate weekly operational risk metrics, process execution logs, and gap analysis reports for the IT Security Manager.
Qualifications & Requirements Experience:
2-4+ years of hands-on experience performing IT compliance monitoring, internal auditing, procedural documentation, or security control testing in a DoD/DFARS environment.
Documentation & SOP Skills:
Proven ability to author clear, step-by-step technical Standard Operating Procedures (SOPs), system administration guides, and audit-ready control execution logs.
Framework Knowledge:
Direct experience monitoring and analyzing controls under
NIST SP 800-171 , CMMC
Level 2 , and
DFARS 252.204-7012
.
Technical Familiarity:
Practical experience inspecting control evidence within Active Directory / Entra ID, Microsoft 365 / GCC High, firewalls, SIEM platforms, and hypervisors.
Education:
Bachelor's Degree in Cybersecurity, Information Systems, or equivalent practical technical experience. Preferred Certifications CMMC /
Compliance:
CCP (CMMC Certified Professional) or CISA.
General Security:
Security+, Network+, or SSCP.