Full-Time

GRC Analyst

Updated on 5/26/2026

Spire

Spire

501-1,000 employees

Satellite data and analytics for maritime

Compensation Overview

$189k - $225k/yr

+ Equity Awards

No H1B Sponsorship

Boulder, CO, USA

Hybrid

Three days on-site per week required.

US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
Fedramp
Requirements
  • Five or more years of progressive experience in cybersecurity governance, risk, and compliance; IT audit; or a closely related discipline, with substantial hands-on exposure to framework interpretation and contract requirement analysis.
  • Demonstrated working knowledge of NIST SP 800-171 and NIST SP 800-53, including control families, assessment procedures, and common implementation patterns.
  • Experience contributing to SSP and POA&M artifacts, compliance matrices, or Requirements Traceability Matrices in a regulated environment.
  • Practical experience supporting at least one formal audit, certification, or assessment cycle (for example CMMC, ISO 27001, SOC 2, FedRAMP, or comparable).
  • Strong technical writing skills, including the ability to produce accurate, concise, and audience-appropriate compliance documentation.
  • Demonstrated comfort and interest in reading contractual and regulatory language carefully and translating it into specific, actionable internal requirements.
  • Comfort working across multiple stakeholder groups — legal, sourcing, engineering, IT, security operations, and program management — and adjusting communication style accordingly.
  • Bachelor's degree in Information Security, Information Systems, Business, a related field, or equivalent practical experience.
Responsibilities
  • Review customer contracts, statements of work, security annexes, CDRLs, data protection addenda, and flow-down clauses to identify cybersecurity, privacy, and information handling obligations applicable to the company.
  • Extract and catalog specific security requirements from contractual language, and translate them into structured, testable statements suitable for traceability and control mapping.
  • Compare identified requirements against the company's current product scope, control environment, and certification posture to determine where compliance is already met, partially met, or requires new implementation work.
  • Produce gap analyses, compliance matrices, and Requirements Traceability Matrix artifacts that clearly communicate the state of compliance for a given contract, program, or system.
  • Serve as the security function's primary point of contact for legal and sourcing during contract review, redline cycles, and flow-down negotiation, including review of subcontractor and supplier flow-down language.
  • Maintain working proficiency across the frameworks relevant to the company's regulatory and contractual posture, including NIST SP 800-171, NIST SP 800-53, NIST CSF, CMMC, ISO 27001, FedRAMP, and applicable European frameworks such as NIS2 and GDPR.
  • Map controls across frameworks to minimize duplicated work and enable consistent responses to overlapping requirements; contribute to a shared control inventory used by compliance, security, and program teams.
  • Interpret framework language and authoritative guidance (NIST publications, DoD guidance, regulator FAQs) in the context of specific company systems and business scenarios and escalate ambiguity for formal risk decisions when appropriate.
  • Contribute to the maintenance of the company's Information Security Management System (ISMS) documentation set, including keeping control descriptions, evidence references, and scope statements accurate and current.
  • Support the policy and standard lifecycle, including periodic review cycles, version control, exception governance, and clarification of control owner accountability.
  • Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review, including framework coverage, finding aging, and remediation progress.
  • Draft and revise compliance deliverables including System Security Plans (SSP), Plans of Action & Milestones (POA&M), policy and standard content, control narratives, customer security questionnaire responses, and audit artifacts.
  • Author clear, concise written responses to customer, auditor, and regulator inquiries, calibrated to the technical level of the audience and consistent with approved company positioning.
  • Own the operational risk assessment process and the supporting risk register, including conducting periodic and event-driven risk assessments, documenting current state, identifying deficiencies, and developing risk treatment recommendations.
  • Route risk acceptance and exception decisions to the appropriate decision authority with the underlying analysis and documentation prepared for review; track decisions and ensure follow-through on conditions or expirations.
  • Track open compliance findings and remediation activities, prepare status updates, and flag aging or high-severity items for escalation.
  • Contribute to vendor and supplier security review activities, including evaluating vendor security questionnaires, reviewing supplier control attestations, and assessing residual risk for inclusion in procurement and program decisions.
  • Support assessment of subcontractor and supplier flow-down compliance, including coordinating with sourcing and program management on supplier security obligations and remediation.
  • Support internal and external audit, assessment, and certification activities, including C3PAO engagements, ISO 27001 surveillance audits, customer assessments, and regulator inquiries.
  • Coordinate evidence collection with system owners and control operators; validate that evidence is accurate, complete, and appropriately scoped before submission.
  • Participate in assessor and auditor interviews as a subject matter contributor on specific controls and artifacts.
  • Partner with legal and sourcing on contract review, redlines, and flow-down language; with security program management on milestones, schedules, and audit coordination; and with security engineering and IT on evidence, control implementation detail, and remediation planning.
  • Serve as a knowledgeable point of contact for internal teams seeking to understand what a given regulatory or contractual requirement means in practice.
Desired Qualifications
  • Direct experience with CMMC 2.0 assessment preparation, including familiarity with DFARS 252.204-7012 and 48 CFR Part 204.
  • Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual-use export control regimes.
  • Experience handling Controlled Unclassified Information (CUI) in accordance with NARA and DoD requirements.
  • Exposure to aerospace, defense, space, or other regulated technology environments.
  • Experience reviewing or negotiating cybersecurity flow-down language in customer or supplier contracts.
  • Working familiarity with Governance, Risk, and Compliance tooling such as ServiceNow GRC, Archer, Hyperproof, Drata, Vanta, or equivalent.
  • Industry certifications such as CISA, CRISC, CISSP, CGRC (formerly CAP), ISO 27001 Lead Implementer / Lead Auditor, CMMC Registered Practitioner (RP), or CMMC Certified Professional / Certified Assessor (CCP / CCA).
  • Active US security clearance, or eligibility to obtain one.

Spire Global collects and analyzes satellite data to provide real-time information for maritime tracking, weather forecasting, and global intelligence. It uses a constellation of nanosatellites to observe ship positions and weather, then downlinks data that is processed into insights delivered through APIs and data licenses. It differentiates itself with broad, real-time coverage from a large network of small satellites and API-centric data products for easy integration. Its goal is to help customers optimize operations, improve safety, and support decision-making across shipping, weather, and government intelligence.

Company Size

501-1,000

Company Stage

IPO

Headquarters

Tysons, Virginia

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • European defense and security programs can create recurring mission revenue.
  • Amadeus deployment validates aviation data in live operational workflows.
  • AI weather products expand Spire into energy and trading markets.

What critics are saying

  • Canada's contract termination shows sovereign buyers can cancel large programs abruptly.
  • Spire remains cash-burning and unprofitable, delaying self-funded growth.
  • European manufacturing capacity risks underutilization if program awards slip or shift rivals.

What makes Spire unique

  • Spire sells space-derived data and analytics, not satellites alone.
  • Its nanosatellite constellation enables real-time maritime, aviation, and weather intelligence.
  • Munich manufacturing strengthens sovereign European delivery and in-country production.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Spire who can refer or advise you

Benefits

Hybrid Work Options

Unlimited Paid Time Off

Professional Development Budget

Mental Health Support

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

0%
Intellectia.AI
Apr 9th, 2026
Spire Global raises $70M in private placement to expand space-based data services

Spire Global has secured $70 million in a private placement. The company operates a satellite constellation that provides space-based data and analytics, offering weather intelligence, aircraft tracking and security detection services globally. Spire Global builds and operates satellites that observe earth in real time using radio frequency technology. The company also offers space-as-a-service solutions, allowing customers to leverage its infrastructure for their own operations, alongside research and development services for satellite technologies. The firm maintains operations across the United States, Canada, Luxembourg and other locations.

Business Wire
Apr 7th, 2026
Spire integrates satellite soil moisture data with 45-day weather forecasts for agriculture intelligence

Spire Global has launched an expanded agriculture intelligence offering that integrates soil moisture data with weather forecasting capabilities. The solution combines over 40 years of historical records, daily satellite observations, site-specific forecasts extending up to 45 days, and AI-driven sub-seasonal guidance. The system uses proprietary Global Navigation Satellite System radio occultation and reflectometry data to provide near real-time global soil moisture observations. It can identify early signs of crop stress up to a week before visible canopy damage, enabling more efficient irrigation and water management. Delivered via API, the platform allows digital farming platforms, insurers, agribusinesses and government agencies to embed environmental intelligence into operational workflows. The solution aims to reduce reliance on hardware-based sensors whilst enabling scalable deployment across global agricultural portfolios.

Business Wire
Apr 1st, 2026
Spire Global launches satellite with diamond quantum magnetometer to advance Earth's magnetic field measurement for NGA's MagQuest Challenge

Spire Global has launched a satellite as part of the National Geospatial-Intelligence Agency's MagQuest Challenge, which offers multi-million-dollar prizes for advancing Earth's magnetic field measurement. The satellite, launched aboard SpaceX's Transporter 16 mission, combines Spire's infrastructure with SBQuantum's diamond quantum magnetometer system. MagQuest aims to improve efficiency and reliability of geomagnetic data for the World Magnetic Model, which powers navigation in mobile applications, GPS and military systems. Spire and SBQuantum will demonstrate the satellite system and provide data to NOAA and NASA for assessment over three years. The mission represents the first diamond-powered geomagnetic data collection from low Earth orbit. Results will inform NGA's acquisition strategy for global magnetic field data collection capabilities.

Glasgow City of Science and Innovation
Mar 31st, 2026
Three Glasgow satellites successfully deployed in major SpaceX launch.

Three Glasgow satellites successfully deployed in major SpaceX launch. 31/03/2026 Three satellites built in Glasgow have successfully launched aboard SpaceX's Transporter-16 mission, marking a significant milestone for the city's growing space sector. Developed by Spire Global and AAC Clyde Space, the satellites highlight Glasgow's strength in spacecraft manufacturing and satellite communications, reinforcing its position as Europe's leading city for small-satellite production. The mission was backed by funding from the UK Space Agency through the European Space Agency's Pioneer Programme, part of the Advanced Research in Telecommunications Systems (ARTES) programme, which supports emerging UK companies to become mission providers. One of the satellites, launched by Spire Global UK, is testing optical inter-satellite link (ISL) technology, using high-speed laser crosslinks to reduce data latency. The innovation is designed to support near-real-time data delivery for aviation, maritime, weather and space weather services. Meanwhile, two satellites developed by AAC Clyde Space form part of the xSPANCION project, delivered in collaboration with partners including University of Strathclyde and the Satellite Applications Catapult. The project demonstrates the UK's capability in high-volume, low-cost satellite manufacturing and operations. These satellites will contribute to AAC Clyde Space's VIREON(TM) constellation, designed to provide space-enabled insights for agriculture, forestry and environmental management, supporting decision-making for governments and industry. The launch underscores the growing importance of satellite communications across both civil and defence applications, from broadband connectivity to secure communications. The UK Space Agency has committed more than £600m to satellite communications research and development, alongside new funding through its Connectivity in Low Earth Orbit (C-LEO) programme. Together, the missions strengthen UK capability across advanced communications technologies, manufacturing and operations - while showcasing Glasgow as a global hub for next-generation space innovation.

FySelf
Mar 31st, 2026
Scottish company pioneers satellite communications with spacex launch.

Scottish company pioneers satellite communications with spacex launch. By March 31, 2026 No Comments 3 Mins Read Three new scottish-built satellites have been launched aboard spacex's Transporter 16 mission. The launch marks a significant step forward for the UK's leadership in laser communications, spacecraft manufacturing and satellite communications. Developed by Spire Global and AAC Clyde Space in Glasgow, the satellites are backed by UK Space Agency funding through the European Space Agency's Pioneer Programme, which supports start-up UK space companies to become new mission providers. The Pioneer program falls under the Advanced Research in Telecommunications Systems (ARTES) program. The importance of satellite communications in critical industries. The UK Government has identified satellite communications as a priority area for further support due to its increasingly important role in both civil and defense applications, from providing broadband services to remote areas to providing secure connectivity for military operations. As part of this initiative, the UK Space Agency will invest more than £600m in satellite communications research and development over the next few years. Optical satellite-to-satellite link testing by Spire Global UK. One of the satellites was launched by Spire Global UK to test an innovative optical intersatellite link (ISL) payload. The mission is designed to demonstrate high-speed laser cross-linking on a compact 6U platform and aims to significantly reduce data latency for aviation, maritime, weather, and space weather services. Once validated, this technology will support near real-time global data distribution across a constellation of microsatellites. AAC Clyde Space demonstrates UK mass production capabilities. As part of the xSPANTION project, the two satellites were developed by AAC Clyde Space in collaboration with several UK partners including Bright Ascension Ltd., University of Strathclyde, Satellite Applications Catapult, Alden Legal and D-Orbit UK. These satellites will be the first in-orbit demonstration of the UK's new high-volume, low-cost satellite manufacturing and operational capabilities. These satellites form part of VIREON(TM), AAC Clyde Space's new satellite constellation designed to enhance decision-making across agriculture, forestry and environmental management, providing government, industry and environmental organizations with insights from space. Supporting the growth of satellite communications across the UK. Together these missions will strengthen the UK's capabilities across optical ISL technology, high-volume manufacturing, advanced operational platforms and highly skilled jobs across the UK supply chain. They also demonstrate Glasgow's position as Europe's leading city in small satellite manufacturing. Henny Sands, Director of Telecommunications at the UK Space Agency, explained: "The launch of Transporter 16 is a significant step forward for the UK's ambitions in next-generation satellite communications. "Supporting both breakthrough optical technology and high-volume production methods will enable British companies to lead the market that will define the future of global connectivity." Companies can also apply to the UK Space Agency's Low Earth Orbit Connectivity (C-LEO) program. Currently, £30m is available to support the development of new components and technology for the constellation, with further funding to be launched later this year.