Enterprise Risk Analyst (Aerospace SaaS)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Onsite in Centennial, CO; Long Beach, CA; SF Bay Area; or Washington, DC. Candidates must be U.S. citizens, lawful permanent residents, or protected individuals under ITAR requirements, and must have an active or obtainable SECRET or TS/SCI security clearance.
Base salary: $115,000–$155,000 in Denver; $120,000–$165,000 in Long Beach or Washington, DC; $132,000–$178,000 in the SF Bay Area.
Company
develops autonomous spacecraft, advanced payloads, mission software, and space-based interceptors for U.S. and allied space-security missions.
What you will do
- Support the enterprise risk management program, including structured OCTAVE assessments, FAIR-based risk quantification, risk register maintenance, and residual risk tracking.
- Build dashboards, KPI/KRI reports, and status tracking using Jira, Confluence, MS Project, enterprise GRC platforms, and related tools.
- Support audit readiness, evidence collection, control documentation, POA&M management, and remediation tracking for IL5 and IL6 environments.
- Execute third-party vendor risk assessments, including questionnaires, documentation reviews, tiering, scoring, lifecycle tracking, and monitoring of risk signals.
- Support procurement and contract teams with vendor risk findings, mitigation language, CMMC supply-chain alignment, DFARS, and ITAR/export-control considerations.
- Coordinate milestones, corrective actions, internal audits, leadership briefings, assessor interactions, and cross-functional risk inquiries.
Requirements
- 5+ years of experience in enterprise risk management, GRC, cybersecurity risk, compliance, or a related discipline.
- Working knowledge of NIST SP 800-53, NIST SP 800-171, DoD RMF for IL5/IL6, and CMMC, with experience supporting assessments or audits.
- Experience with FAIR and/or OCTAVE risk assessment methodologies and third-party/vendor risk assessments.
- Hands-on experience with Jira, Confluence, MS Project, enterprise GRC platforms, and MS Visio or Lucidchart.
- Strong written and verbal communication, organization, self-direction, and ability to manage multiple workstreams.
- Active or obtainable SECRET or TS/SCI clearance and eligibility under U.S. ITAR requirements are required.
Nice to have
- Startup, aerospace, defense technology, SaaS, or regulated government-market experience.
- CRISC, CISA, Open FAIR, CompTIA Security+, Certified ScrumMaster, or similar certifications.
- Experience with Azure Government, AWS GovCloud, POA&M management, SSP documentation, and DoD authorization contexts.
- Knowledge of ITAR, EAR, DFARS, export controls, Agile/Scrum, or hybrid project delivery.
Culture & Benefits
- Onsite work in a standard office or production-factory environment.
- Health, dental, vision, HRA/HSA options, PTO, and paid holidays.
- 401(k), parental leave, and equity.
- Work with engineering, security, legal, compliance, operations, and government partners on space-security technology.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →