Full-Time

Senior Cybersecurity & Compliance Analyst

Posted on 7/18/2025

CyberSheath

CyberSheath

51-200 employees

Cybersecurity compliance consulting for defense contractors

Compensation Overview

$145k - $165k/yr

Remote in USA

Remote

Category
IT & Security (1)
Requirements
  • Experience within the Defense Industrial Base (DIB) with expertise in assessing compliance for DIB contractors.
  • Hands-on experience with NIST 800-171, CMMC, DFARS 252.204-7012 and led compliance assessments and demonstrated independent leadership of audits or regulatory efforts.
  • CMMC Certified Assessor, CISSP, CISM, or other relevant cybersecurity certifications.
  • Broad understanding of systems and security engineering principles, including the ability to build and troubleshoot systems (e.g., servers, Active Directory).
  • Understanding of network fundamentals, cloud technologies (IaaS, PaaS, SaaS), and cybersecurity concepts.
Responsibilities
  • Own and lead all compliance efforts for assigned clients, acting as the primary advisor on cybersecurity compliance and regulatory alignment.
  • Maintain proactive communication with clients on compliance status, assessment results, and remediation; deliver regular updates through executive briefings, business reviews, and detailed reporting.
  • Lead and execute regulatory assessments (e.g., DFARS, NIST 800-171, and CMMC Maturity Level 2); perform annual assessments and ensure evidence-based control.
  • Lead the implementation and continuous monitoring of compliance frameworks (e.g., NIST SP 800-171, CMMC); develop and manage System Security Plans (SSPs) and Plans of Action & Milestones (POA&M) for clients.
  • Guide clients through internal and external audits, ensuring all necessary evidence, documentation, and artifacts are in place for successful certification.
  • Collaborate with clients to develop, update, and maintain compliance documentation, including policies, procedures, SSPs, POA&Ms, and other governance materials.
  • Ensure compliance policies and procedures aligned with NIST 800-171, CMMC, and DFARS; provide expertise in drafting and maintaining control documentation.
  • Develop and maintain incident response plans; conduct tabletop exercises with clients to test incident response readiness and improve incident management capabilities.
  • Perform regular risk assessments to identify compliance gaps and develop mitigation strategies; maintain risk registers and ensure continuous improvement of compliance postures.
  • Deliver or facilitate client training programs, including basic security awareness, privileged user training, and handling of Controlled Unclassified Information (CUI).
Desired Qualifications
  • Budgeted pay range is provided as $145,000–$165,000 USD, though not a qualification per se.
  • Leadership experience in compliance management or governance programs is desirable.
  • Experience leading DFARS/NIST SP 800-171/CMMC assessments for DIB contractors is highly desirable.
  • CMMC Certified Assessor, CISSP, CISM, or other senior cybersecurity certifications beyond the minimum requirements are desirable.

CyberSheath provides cybersecurity and compliance services for organizations handling sensitive government data, especially defense contractors. It helps meet standards like NIST 800-171 and CMMC through consulting, risk assessments, compliance assessments, incident response, and staffing resources. It integrates compliance into daily operations, offers privileged access risk assessments, and focuses on outcome-based deployment and risk-based professional services to deliver audit-ready evidence. Its goal is to help clients achieve verifiable, auditable compliance while reducing cyber risk and ensuring expertise is available on demand.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Reston, Virginia

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • CMMC 2.0 enforcement accelerates demand from reluctant DIB contractors.
  • BV Investment Partners' majority stake funds scaling operations.
  • Emil Sayegh's August 2025 CEO appointment boosts sales leadership.

What critics are saying

  • Jeremy Mares' 2022 exit signals sales instability eroding DIB expansion.
  • Redspin's Level 3 certification steals market share from CyberSheath.
  • Frequent CEO changes disrupt CMMC execution in 6-12 months.

What makes CyberSheath unique

  • CyberSheath delivers end-to-end CMMC managed services beyond assessments.
  • Largest CMMC managed service vendor serves DIB contractors exclusively.
  • Outcome-based deployments ensure audit-proof compliance daily.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Company News

CyberSheath
Mar 31st, 2026
CyberSheath supports CTG Federal's achievement of CMMC Level 2 certification.

CyberSheath supports CTG Federal's achievement of CMMC Level 2 certification. RESTON, Va. - March 31, 2026 - CyberSheath, a leading provider of cybersecurity and compliance services for the defense industrial base, supported CTG Federal, a U.S. small-business government IT solutions provider, in the implementation and successful achievement of Cybersecurity Maturity Model Certification (CMMC) Level 2. CTG Federal delivers advanced IT infrastructure and mission systems to U.S. government customers, including organizations within the Department of War. As part of its commitment to protecting controlled unclassified information (CUI) and maintaining the highest standards of cybersecurity, CTG Federal established a comprehensive security program aligned to the CMMC Level 2 framework. To support this effort, CTG Federal worked with CyberSheath to augment internal capabilities across several areas of the program, including security architecture validation, control implementation support, and ongoing operational processes required to meet CMMC Level 2 standards. "Defense contractors responsible for handling controlled unclassified information must operate with a high degree of discipline and technical rigor," said Emil Sayegh, CEO of CyberSheath. "CTG Federal demonstrated a strong internal cybersecurity foundation, and we were proud to support their team as they finalized the architecture and operational controls necessary to meet CMMC Level 2 requirements." The formal assessment was conducted by Cybersec Investments, a Certified Third-Party Assessor Organization (C3PAO). Achieving CMMC Level 2 certification validates that CTG Federal's security environment and operational processes meet the Department of War requirements for safeguarding controlled unclassified information. "Cybersecurity and responsible stewardship of government information are core to how we operate," said Brian Reynolds, President and CEO of CTG Federal. "Our team invested significant effort in building a mature security program aligned with CMMC, and CyberSheath provided valuable support during the implementation and validation process. Achieving CMMC Level 2 reinforces our commitment to protecting the missions and information entrusted to us by our government customers." As CMMC requirements expand across the defense industrial base, CTG Federal's certification ensures the company is positioned to continue supporting defense customers that require validated cybersecurity maturity. About CyberSheath Established in 2012, CyberSheath is one of the most experienced and trusted IT security services partners for the U.S. defense industrial base. From CMMC compliance to strategic security planning to managed security services, CyberSheath offers a comprehensive suite of offerings tailored to clients' information security and regulatory compliance needs. Learn more at https://www.cybersheath.com/. About CTG Federal CTG Federal, a Cohesive Technology Group company, is a U.S.-based small business federal IT solutions provider and trusted partner to civilian, defense, and intelligence agencies. The company designs, integrates, and supports mission-ready infrastructure and platforms spanning sovereign AI and high-performance computing (HPC), storage and data management, secure networking, and enterprise services. CTG Federal specializes in delivering complex technology deployments in sensitive environments, with a strong emphasis on cybersecurity, supply chain assurance, and operational excellence. Through a disciplined, customer-first approach and partnerships with leading technology providers, CTG Federal helps government organizations modernize IT, accelerate mission outcomes, and protect critical information. CyberSheath Kristen Morales Lexie Capperella Gregory for CyberSheath

CyberSheath
Aug 20th, 2025
CyberSheath Names Tech and Cybersecurity Veteran Emil Sayegh as CEO

RESTON, Va. - Aug. 21, 2025 - CyberSheath, the largest CMMC managed service vendor in the DIB, has appointed Emil Sayegh as Chief Executive Officer.

Business Wire
Jul 16th, 2025
Social Engineering Expert and Hacker Rachel Tobac to Deliver Keynote at CyberSheath's CMMC CON 2025

CyberSheath, the largest CMMC managed service vendor in the DIB, will host its sixth annual free virtual conference, CMMC CON 2025: Compliance Blueprint - Plan.

Business Wire
Jun 18th, 2025
CyberSheath Launches Revamped CMMC CON Ninja Training Program as Compliance Enforcement Intensifies

CyberSheath launches revamped CMMC CON ninja training program as compliance enforcement intensifies.

Executive Mosaic
Sep 26th, 2024
Chenega & CyberSheath Pass JVSA Validation With Perfect Score

Chenega Corporation has collaborated with CyberSheath to pass a Joint Surveillance Voluntary Assessment-or JSVA-validation with a perfect score of 110.

INACTIVE