Sr. Analyst, Cybersecurity Risk & Compliance (CRN #003166)
Alameda, CA
Aversan Inc. (www.aversan.com ) is a trusted multi-service engineering and electronics manufacturing company. Aversan delivers leading-edge and reliable safety-critical electronics and software systems to the aerospace, defense, and space industries.
We are seeking a Senior Analyst, Cybersecurity Risk & Compliance. to support and help lead the Risk & Compliance function, with a primary focus on maintaining our ISO 27001 certification and supporting our obligations on NIST 800-171. The right candidate will support Risk and Compliance program, which includes Governance Risk and Compliance (GRC), and Third-Party Risk Management (TPRM), bring structure to our processes, and help stabilize and scale the function
Key Responsibilities:
Basic Qualifications:
We are seeking a Senior Analyst, Cybersecurity Risk & Compliance. to support and help lead the Risk & Compliance function, with a primary focus on maintaining our ISO 27001 certification and supporting our obligations on NIST 800-171. The right candidate will support Risk and Compliance program, which includes Governance Risk and Compliance (GRC), and Third-Party Risk Management (TPRM), bring structure to our processes, and help stabilize and scale the function
Key Responsibilities:
- Contribute to all ISO 27001 activities, including internal audit readiness, external recertification, and ongoing control maintenance.
- Support NIST 800-171 compliance efforts, including maintenance of System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and gap assessments.
- Have working knowledge and able support GDPR, NIST CSF, CMMC, TISAX, ITAR, and AI related compliance as well as the ability to gain knowledge on future certification and regulation requirements.
- Assist in engagement with government compliance stakeholders and maintain awareness of requirements.
- Maintain the Risk Register and track mitigation progress across all functional areas.
- Coordinate the Security Exception process, ensuring proper documentation, approvals, and governance.
- Including vendor assessments, reviews, remediation follow-up, and monitoring.
- Write and update policy and standards and provide governance, oversight, and assurance.
- Administer GRC/TPRM tooling (ZenGRC) and ensure evidence management and workflows are maintained and audit-ready. Have an understanding or ability to use ServiceNow and AuditBoard risk management products.
- Prepare audit documentation and assist with responses for internal and external audits.
- Draft and maintain clear, consistent, and audit-ready documentation, including policies, control responses, and program updates.
- Support customer assurance efforts related to ISO, NIST, and general cyber compliance.
- Lead internal audits and assessments
- Help implement scalable, repeatable governance processes for policy and standard creation and lifecycle management.
- Assist in developing compliance procedures, checklists, and review frameworks.
- Support workflows for User Access Reviews (UAR), TPRM, and continuous monitoring.
- Work cross-functionally with Aptiv Cybersecurity, IT, Legal, HR, and Engineering, across Aptiv, HellermannTyton, Winchester, and Intercable.
- Support communication and coordination with external auditors and internal stakeholders (including Primary Security Officer, Aptiv Legal, WR and Aptiv leadership).
- Support Cybersecurity Training
Basic Qualifications:
- 5+ years of cybersecurity, compliance, or GRC experience
- Familiarity with ISO 27001, NIST 800-171, and enterprise GRC operations
- Strong writing skills, with experience contributing to SSPs and POA&Ms
- Working knowledge of ZenGRC or similar tools
- Demonstrated ability to work across matrixed teams
- Experience with customer audit responses and regulatory compliance
- Experience supporting government-mandated compliance frameworks
- Involvement in ISO 27001 recertification efforts or similar standards
- Experience with third-party risk tools (e.g., BlueVoyant, BitSight)
- U.S. citizenship required due to regulatory requirements
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
2
0
0
Categories:
Analyst Jobs
Compliance Jobs
Tags: Audits CMMC Compliance GDPR Governance ISO 27001 Monitoring NIST POA&M Risk management System Security Plan TISAX
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Systems Engineer jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSystems Administrator jobsSenior Cybersecurity Engineer jobsCybersecurity Editor jobsCybersecurity Content Editor jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsIT Security Analyst jobsSenior Network Security Engineer jobsChief Information Security Officer jobsSenior Information Security Engineer jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsIT Security Engineer jobsSecurity Specialist jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Cyber Security Engineer jobsCybersecurity Specialist jobsSenior IT Auditor jobsSenior Software Engineer jobs
SaaS jobsEncryption jobsTS/SCI jobsJava jobsCEH jobsSplunk jobsTop Secret jobsThreat detection jobsTerraform jobsIDS jobsSDLC jobsMalware jobsIPS jobsRMF jobsFinance jobsSQL jobsForensics jobsDocker jobsIntrusion detection jobsActive Directory jobsSOC 2 jobsCompTIA jobsOWASP jobsVPN jobsAnsible jobs
ITIL jobsClearance Required jobsTCP/IP jobsCRISC jobsGIAC jobsHIPAA jobsDoDD 8570 jobsIT infrastructure jobsMITRE ATT&CK jobsJira jobsOSCP jobsBanking jobsSOAR jobsData Analytics jobsSOX jobsIndustrial jobsDNS jobsZero Trust jobsCCSP jobsJavaScript jobsUNIX jobsGCIH jobsCISO jobsArtificial Intelligence jobsPolygraph jobs