Lynk (lynk.world)

Lynk (lynk.world)

Security Analyst / ISSO

Chevy Chase, MD · Full-time

No sponsorship$171k-$800kDetected 21 days ago
PythonBashAWSCybersecuritySIEMSOC OperationsComplianceBusiness DevelopmentZero Trust

About the role

  • You'll be ISSO for CUI-scoped systems: authoring SSPs, maintaining POA&Ms, running control assessments, and leading C3PAO engagement.
  • Lynk has a functioning security toolset in place including SIEM/log management, EDR, MDM, vulnerability management and IT asset management

Responsibilities

  • Own and maintain the System Security Plan (SSP) and Plan of Action & Milestones (POA&M) for all CUI-scoped systems
  • map existing controls (Wazuh, ThreatDown, Tenable, ManageEngine, AD GPOs, SnipeIT) to CMMC requirements, identify gaps, and drive remediation.
  • Maintain the organizational risk register
  • support ongoing Risk Management Framework (RMF) processes and report risk posture to the CISO.
  • Lead preparation for CMMC Level 2 assessments - build evidence packages, coordinate with the C3PAO, and manage assessor requests and findings.
  • Develop and maintain cybersecurity policies, procedures, and standards aligned to CMMC, DFARS, SOC 2, and GDPR
  • Support contract teams with DFARS clause requirements, cybersecurity representations, and customer security questionnaires.
  • maintain supplier risk documentation.

Requirements

  • US citizenship or Lawful Permanent Resident status required.
  • no security clearance required.
  • Deep, working knowledge of NIST SP 800-171 and DFARS 7012.

Nice to have

  • CMMC Registered Practitioner (RP) or Professional (CCP)
  • CISSP / CISM / Security+
  • RMF / ATO experience
  • FedRAMP familiarity
  • Space / satellite industry background
  • Telecom or critical infrastructure security
  • Prior C3PAO assessment experience
  • GRC platform experience (Vanta, Drata, Archer, ServiceNow)

Skills

  • 3-6 years in cybersecurity with a strong GRC or compliance focus; prior ISSO experience or equivalent accountability preferred.
  • Deep, working knowledge of NIST SP 800-171 and DFARS 7012. Able to assess, gap-analyze, and evidence all 110 controls independently.
  • Demonstrated experience authoring SSPs and POA&Ms for government-facing or regulated environments.
  • Familiarity with the CMMC Level 2 assessment process and C3PAO engagement.

Compensation

  • Competitive salary and equity in a company building genuinely novel global infrastructure.

Benefits

  • Competitive salary and equity in a company building genuinely novel global infrastructure.
  • Learning and certification budget.

Visa & Work Authorization

  • US citizenship or Lawful Permanent Resident status required

This listing is sourced directly from Lynk (lynk.world)'s careers page and normalized into a canonical job model.