C Spire
GRC Analyst, Federal & Customer Programs
Boulder, Colorado, United States
No sponsorship$171k-$800kDetected 72 days ago
AlgorithmsCybersecuritySOC OperationsComplianceNegotiationAuditingSupply ChainProcurementContract ManagementCadenceLeadershipCommunicationCollaborationWritingInternal AuditCISSP
About the role
- The GRC Analyst, Federal & Customer Programs is responsible for the hands-on analysis, documentation, and operational execution of the company's security governance, risk, and compliance obligations.
- The GRC Analyst serves as the security function's primary reviewer of incoming contractual cybersecurity language and works directly with legal and sourcing on flow-down negotiation and redlines.
- Candidates who enjoy careful reading of contractual and regulatory text - and who want this to be a substantial part of their day-to-day work - will find this role a strong fit.
Responsibilities
- Governance, Policy & ISMS Support
- Support the policy and standard lifecycle, including periodic review cycles, version control, exception governance, and clarification of control owner accountability.
- Own the operational risk assessment process and the supporting risk register, including conducting periodic and event-driven risk assessments, documenting current state, identifying deficiencies, and developing risk treatment recommendations.
- Support assessment of subcontractor and supplier flow-down compliance, including coordinating with sourcing and program management on supplier security obligations and remediation.
- Audit & Assessment Support
- Support internal and external audit, assessment, and certification activities, including C3PAO engagements, ISO 27001 surveillance audits, customer assessments, and regulator inquiries.
- Coordinate evidence collection with system owners and control operators; validate that evidence is accurate, complete, and appropriately scoped before submission.
- Spire Global is a space-to-cloud analytics company that owns and operates the largest multi-purpose constellation of satellites.
Requirements
- Five or more years of progressive experience in cybersecurity governance, risk, and compliance
- Demonstrated working knowledge of NIST SP 800-171 and NIST SP 800-53, including control families, assessment procedures, and common implementation patterns.
- Experience contributing to SSP and POA&M artifacts, compliance matrices, or Requirements Traceability Matrices in a regulated environment.
- Strong technical writing skills, including the ability to produce accurate, concise, and audience-appropriate compliance documentation.
- Comfort working across multiple stakeholder groups - legal, sourcing, engineering, IT, security operations, and program management - and adjusting communication style accordingly.
- Bachelor's degree in Information Security, Information Systems, Business, a related field, or equivalent practical experience.
Nice to have
- Direct experience with CMMC 2.0 assessment preparation, including familiarity with DFARS 252.204-7012 and 48 CFR Part 204.
- Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual-use export control regimes.
- Experience handling Controlled Unclassified Information (CUI) in accordance with NARA and DoD requirements.
- Exposure to aerospace, defense, space, or other regulated technology environments.
- Experience reviewing or negotiating cybersecurity flow-down language in customer or supplier contracts.
- Working familiarity with Governance, Risk, and Compliance (GRC) tooling such as ServiceNow GRC, Archer, Hyperproof, Drata, Vanta, or equivalent.
- Active US security clearance, or eligibility to obtain one.
- Access to US export-controlled software and/or technology may be required for this role.
Compensation
- $189,000 - $225,000 USD
Benefits
- Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review, including framework coverage, finding aging, and remediation progress.
- ๐ด Generous Time Off Policy
- ๐ Education Assistance Program
- ๐ Employee Stock Purchase Program (ESPP)
- ๐ฃ Family Leave
- ๐ช Fitness Reimbursement
- In addition to its constellation, Spire's data infrastructure includes a global ground station network and 24/7 operations that provide real-time global coverage of every point on Earth.
Visa & Work Authorization
- Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual-use export control regimes
Apply directly at C Spire โCreate a free account for alerts like thisView C Spire immigration profile
This listing is sourced directly from C Spire's careers page and normalized into a canonical job model.