Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Compliance Analyst – ISO 42001 / CMMC / SOC 2 image - Rise Careers
Job details

Compliance Analyst – ISO 42001 / CMMC / SOC 2

Position Overview

By Light is seeking a full-time Cyber Security SME to join our growing security and compliance team. This role supports By Light’s Security Operations Center (SOC) and compliance initiatives, with a focus on achieving and maintaining certifications under ISO/IEC 42001 (AI Management Systems), CMMC Level 2, and SOC 2. The ideal candidate will assist in the implementation, documentation, monitoring, and continuous improvement of enterprise security controls to meet internal policy, federal requirements, and industry standards.

 

This is a hands-on role that blends technical knowledge, compliance strategy, audit preparation, and cross-team collaboration to ensure enterprise-wide security and assurance for AI, cloud, and IT/OT systems.

Responsibilities

  • Support compliance operations aligned with ISO/IEC 42001, CMMC Level 2, and SOC 2 frameworks.
  • Maintain security documentation including policies, procedures, system security plans (SSPs), plans of action and milestones (POA&Ms), and risk assessments.
  • Assist in the implementation and monitoring of cybersecurity controls across cloud environments (AWS, Azure) and hybrid infrastructure.
  • Collaborate with IT, engineering, and operations teams to ensure controls are enforced, evidence is collected, and remediation timelines are met.
  • Develop and generate compliance metrics and dashboards using tools like Splunk and AWS CloudWatch.
  • Conduct internal control reviews and gap analyses; support third-party audits and government assessments.
  • Track and respond to security incidents, policy violations, and control deficiencies.
  • Provide briefings, written reports, and presentations to leadership and stakeholders.

Required Experience/Qualifications

  • 2+ years of experience supporting compliance efforts for one or more of the following: ISO/IEC 42001, CMMC Level 2, SOC 2, NIST SP 800-53, or NIST SP 800-171.
  • Working knowledge of AWS services including EC2, S3, IAM, and CloudWatch.
  • Experience using Splunk to create dashboards and compliance views for evidence tracking and control monitoring.
  • Understanding of security operations and risk management in Linux and Windows environments.
  • Strong technical writing and documentation skills for policies, audit artifacts, and risk assessments.
  • Ability to manage multiple concurrent deadlines with minimal supervision.

Preferred Experience/Qualifications

  • Familiarity with AI governance concepts and the ISO/IEC 42001 AI Management System structure.
  • Experience coordinating audit readiness for FedRAMP, ISO, or DoD assessments.
  • Prior work with vulnerability management, patch tracking, or compliance ticketing workflows.
  • Experience working with external auditors, assessors, or federal partners.
  • Experience with compliance dashboards, automated evidence collection, and reporting pipelines.

Special Requirements/Security Clearance

  • ISC2 CISSP or equivalent combination of training and experience.
  • CGRC

Average salary estimate

$97500 / YEARLY (est.)
min
max
$85000K
$110000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs

Experienced Network Administrator needed to support enterprise network operations and cybersecurity for defense communications at Picatinny Arsenal under a veteran-owned joint venture.

Fairstead ESC LLC Hybrid Houston, Texas, United States
Posted 22 hours ago

Fairstead is looking for a detail-oriented Compliance Specialist to manage regulatory compliance and resident certifications across their property portfolio in Houston.

Photo of the Rise User
SmartRecruiters Inc Hybrid United States, Remote, United States
Posted 8 hours ago

Experienced Senior Commercial Counsel needed for a remote, contract role with a leading tech employer to manage complex commercial agreements and partner cross-functionally in the US.

Photo of the Rise User
Posted 35 minutes ago

Senior Commercial Counsel needed at Sierra, a pioneering AI company, to lead complex commercial contract negotiations and provide broad legal expertise in a dynamic, fast-paced environment.

Photo of the Rise User
Dental Insurance
Disability Insurance
Vision Insurance
Equity
Paid Time-Off
Medical Insurance
Mental Health Resources
Paid Holidays
Company Retreats

Lead state government affairs initiatives in the Northeast at Hims & Hers, shaping policy to improve healthcare through innovative, personalized services.

Photo of the Rise User
Posted 7 hours ago

Experienced Senior Counsel needed to guide TD Bank's US Data, Digital, and Payments legal operations in a dynamic financial services environment.

Posted 22 hours ago

Seeking a knowledgeable Corporate Counsel to manage complex contracts and legal risks within the power and construction sectors at a leading construction-focused energy company.

Photo of the Rise User
Posted 8 hours ago

MacDonald-Miller seeks a detail-oriented Contracts Coordinator to manage contract processes and support legal and compliance functions within their Seattle headquarters.

Photo of the Rise User
Posted 9 hours ago

Experienced IT Audit Manager needed to lead SOX compliance audits and manage IT control risks within a collaborative, evolving technology setting.

Photo of the Rise User
Posted 20 hours ago

Experienced technology transfer professional needed to lead CRADA negotiations and intellectual property management at BryceTech supporting government innovation.

A fully remote Legal Intake Specialist opportunity with a top U.S. personal injury legal funding company focused on client case management and documentation review.

Photo of the Rise User
Posted 24 hours ago

Sierra seeks a skilled Commercial Counsel with expertise in commercial contracts and AI-related legal matters to support its growth and product innovation.

Photo of the Rise User

Paragon Cyber Solutions is looking for a technically skilled Policy Executive / Strategic Planner to create and maintain cybersecurity documentation and strategic plans for naval defense initiatives.

Photo of the Rise User
Visa Hybrid Atlanta, GA, USA
Posted 18 hours ago

Visa seeks a Senior IT Audit Manager to oversee technology-related audits and enhance risk and control processes within a global financial services leader.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
July 24, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!