Karman Space & Defense Logo

Karman Space & Defense

Senior Cybersecurity GRC Analyst

Posted One Month Ago
Be an Early Applicant
In-Office
Huntington Beach, CA, USA
120K-136K Annually
Senior level
In-Office
Huntington Beach, CA, USA
120K-136K Annually
Senior level
Drives enterprise cybersecurity governance, risk, compliance, and assurance activities. Translates regulatory and contractual requirements into controls and evidence, assesses control effectiveness, manages CMMC, NIST, DFARS, CUI, and SOX ITGC obligations, maintains SSPs and risk documentation, oversees remediation and access governance, and coordinates security reviews for suppliers, SaaS, AI tools, and M&A activities. Partners with technical, business, legal, audit, and executive stakeholders to improve assessment and operational readiness.
The summary above was generated by AI

Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies’ core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.

This role helps drive enterprise-wide cybersecurity governance, risk, compliance, and assurance activities that strengthen control quality, evidence readiness, and risk management across Karman. You will translate regulatory, contractual, and customer requirements into clear controls and reliable evidence; independently assess control effectiveness and risk; and partner with business and technology owners to embed sustainable practices that support audit, assessment, and operational readiness.

Responsibilities

  • Interprets and operationalizes cybersecurity, regulatory, contractual, and customer requirements with business, legal, and technology stakeholders.
  • Maintains cybersecurity governance artifacts including policies, standards, control documentation, mappings, ownership records, and assurance schedules.
  • Evaluates control design, operating effectiveness, evidence sufficiency, exceptions, and residual risk and recommends corrective actions or escalation.
  • Supports sustainable CMMC Level 2, NIST SP 800‑171, DFARS, and Controlled Unclassified Information (CUI) obligations through assessment, evidence validation, remediation, and monitoring.
  • Maintains the Enterprise System Security Plan (SSP), Controlled Site Addenda, system boundaries, inventories, and supporting evidence across regulated environments.
  • Coordinates contractual, regulatory, and CAGE-code traceability, ensuring accurate alignment among obligations, boundaries, sites, and assessment records.
  • Supports Sarbanes‑Oxley (SOX) Information Technology General Controls (ITGC) through narrative development, testing coordination, evidence quality, exception identification, and remediation tracking.
  • Governs cybersecurity risks, exceptions, remediation plans, compensating controls, and acceptance records and prepares leadership-ready materials that translate issues into decisions and business impact.
  • Oversees identity, access, and vulnerability governance, including coverage, aging, remediation performance, exceptions, and validation of closure across responsible teams.
  • Coordinates cybersecurity reviews for third-party services, Software-as-a-Service (SaaS), artificial intelligence (AI) tools, suppliers, and M\&A activities, ensuring security, privacy, data-handling, and evidence requirements are met.

Required Qualifications

  • Bachelor’s degree in cybersecurity, information technology, information systems, business, risk management, accounting, audit, or a related field; equivalent relevant experience may be considered.
  • 5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.
  • Experience assessing control design, operating effectiveness, and evidence sufficiency and translating findings into practical remediation and leadership reporting.
  • Working knowledge of CMMC Level 2, NIST SP 800‑171, DFARS, CUI, SOX ITGC, or comparable regulated control environments.
  • Experience maintaining cybersecurity policies, control narratives, SSPs or equivalent system documentation, evidence repositories, risk registers, Plans of Action and Milestones (POA\&Ms), and remediation trackers.
  • Ability to exercise independent judgment, challenge unsupported conclusions, organize complex requirements, and escalate material risk appropriately.
  • Strong written, analytical, presentation, and stakeholder-management skills across technical teams, business owners, auditors, assessors, vendors, sites, and executives.
  • Proficiency with Microsoft 365 tools, including Excel, PowerPoint, Word, Teams, SharePoint, and Outlook.

Preferred Qualifications

  • Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
  • Experience supporting CMMC Level 2 readiness, NIST SP 800‑171 assessments, DFARS compliance, CUI governance, Supplier Performance Risk System (SPRS) requirements, or defense‑contractor cybersecurity needs.
  • Experience with SOX ITGC, internal or external audit, control testing, information technology risk, and remediation governance.
  • Experience with SSPs, site-specific control documentation, specialized‑asset scoping, CUI flows, system boundaries, evidence validation, and POA\&M management.
  • Experience with supplier cyber risk, SaaS and AI governance, M\&A due diligence, international operations, export controls, or cross-border access risk.
  • Experience using Governance, Risk, and Compliance (GRC) or audit platforms such as ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, or Hyperproof.
  • Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Governance, Risk and Compliance (CGRC), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Cybersecurity Maturity Model Certification Certified CMMC Professional (CMMC CCP), or comparable certification.

This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off
  • Health Savings Account (HSA) with company contribution
  • Flexible Spending Accounts (FSA)
  • Company‑paid life and AD\&D insurance
  • Short‑ and long‑term disability coverage
  • Tuition reimbursement

Karman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.

HQ

Karman Space & Defense Huntington Beach, California, USA Office

5351 Argosy Ave, Huntington Beach, California, United States, 92649 1036

Similar Jobs

7 Minutes Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
170K-260K Annually
Entry level
170K-260K Annually
Entry level
Healthtech • Information Technology • Software • Telehealth
Lead product design direction across complex, multi-team healthcare platform areas. Shape product strategy, experience architecture, design systems, and scalable experiences for patients, providers, and practices. Partner with product, engineering, data, and leadership to resolve ambiguity, guide execution, mentor designers, and raise quality. Establish AI-native design and engineering workflows using emerging tools such as Cursor and Claude Code.
Top Skills: Ai-Native WorkflowsClaude CodeCursor
13 Minutes Ago
Remote or Hybrid
United States
Senior level
Senior level
Cloud • Enterprise Web • Healthtech • Mobile • Software
Manage strategic enterprise healthcare accounts as a trusted advisor, driving adoption, retention, expansion, advocacy, and measurable business value. Develop success plans, conduct business reviews, analyze usage data, support onboarding and training, resolve issues, identify growth opportunities, and collaborate with Sales, Product, Support, Marketing, Implementation, and Professional Services teams.
Top Skills: Data AnalyticsEhrsGainsightSaas PlatformsSalesforce
18 Minutes Ago
In-Office or Remote
81K-101K Annually
Senior level
81K-101K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Leads sales and use tax compliance, planning, controversy, and optimization while managing state and federal credits and incentives. Prepares tax analyses, calculations, filings, memoranda, audit responses, and executive summaries. Coordinates cross-functional initiatives with Finance, Legal, Infrastructure, and business teams, monitors tax law developments, supports process improvements, and liaises with tax advisors and authorities.
Top Skills: CchHeinLexisRia

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account