C Spire

C Spire

GRC Analyst, Federal & Customer Programs

Boulder, Colorado, United States

No sponsorship$171k-$800kDetected 72 days ago
AlgorithmsCybersecuritySOC OperationsComplianceNegotiationAuditingSupply ChainProcurementContract ManagementCadenceLeadershipCommunicationCollaborationWritingInternal AuditCISSP

About the role

  • The GRC Analyst, Federal & Customer Programs is responsible for the hands-on analysis, documentation, and operational execution of the company's security governance, risk, and compliance obligations.
  • The GRC Analyst serves as the security function's primary reviewer of incoming contractual cybersecurity language and works directly with legal and sourcing on flow-down negotiation and redlines.
  • Candidates who enjoy careful reading of contractual and regulatory text - and who want this to be a substantial part of their day-to-day work - will find this role a strong fit.

Responsibilities

  • Governance, Policy & ISMS Support
  • Support the policy and standard lifecycle, including periodic review cycles, version control, exception governance, and clarification of control owner accountability.
  • Own the operational risk assessment process and the supporting risk register, including conducting periodic and event-driven risk assessments, documenting current state, identifying deficiencies, and developing risk treatment recommendations.
  • Support assessment of subcontractor and supplier flow-down compliance, including coordinating with sourcing and program management on supplier security obligations and remediation.
  • Audit & Assessment Support
  • Support internal and external audit, assessment, and certification activities, including C3PAO engagements, ISO 27001 surveillance audits, customer assessments, and regulator inquiries.
  • Coordinate evidence collection with system owners and control operators; validate that evidence is accurate, complete, and appropriately scoped before submission.
  • Spire Global is a space-to-cloud analytics company that owns and operates the largest multi-purpose constellation of satellites.

Requirements

  • Five or more years of progressive experience in cybersecurity governance, risk, and compliance
  • Demonstrated working knowledge of NIST SP 800-171 and NIST SP 800-53, including control families, assessment procedures, and common implementation patterns.
  • Experience contributing to SSP and POA&M artifacts, compliance matrices, or Requirements Traceability Matrices in a regulated environment.
  • Strong technical writing skills, including the ability to produce accurate, concise, and audience-appropriate compliance documentation.
  • Comfort working across multiple stakeholder groups - legal, sourcing, engineering, IT, security operations, and program management - and adjusting communication style accordingly.
  • Bachelor's degree in Information Security, Information Systems, Business, a related field, or equivalent practical experience.

Nice to have

  • Direct experience with CMMC 2.0 assessment preparation, including familiarity with DFARS 252.204-7012 and 48 CFR Part 204.
  • Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual-use export control regimes.
  • Experience handling Controlled Unclassified Information (CUI) in accordance with NARA and DoD requirements.
  • Exposure to aerospace, defense, space, or other regulated technology environments.
  • Experience reviewing or negotiating cybersecurity flow-down language in customer or supplier contracts.
  • Working familiarity with Governance, Risk, and Compliance (GRC) tooling such as ServiceNow GRC, Archer, Hyperproof, Drata, Vanta, or equivalent.
  • Active US security clearance, or eligibility to obtain one.
  • Access to US export-controlled software and/or technology may be required for this role.

Compensation

  • $189,000 - $225,000 USD

Benefits

  • Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review, including framework coverage, finding aging, and remediation progress.
  • ๐ŸŒด Generous Time Off Policy
  • ๐ŸŽ“ Education Assistance Program
  • ๐Ÿ“ˆ Employee Stock Purchase Program (ESPP)
  • ๐Ÿ‘ฃ Family Leave
  • ๐Ÿ’ช Fitness Reimbursement
  • In addition to its constellation, Spire's data infrastructure includes a global ground station network and 24/7 operations that provide real-time global coverage of every point on Earth.

Visa & Work Authorization

  • Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual-use export control regimes

This listing is sourced directly from C Spire's careers page and normalized into a canonical job model.