Summary
DEFTEC Corporation delivers mission critical solutions through skillfully delivered services and innovative products. The IT Security & Compliance Analyst supports the day-to-day execution of DEFTEC's information technology and cybersecurity operations, serving as a primary operational coordinator and contributing to compliance program activities.
Responsibilities
- Serves as the day-to-day point of contact with DEFTEC's managed service provider for service requests, ticket tracking, and escalation
- Coordinates account provisioning, license assignment, and deprovisioning requests with the MSP under established authorization thresholds
- Executes established onboarding and offboarding procedures to ensure timely creation and deprovisioning of user accounts, coordinated with the MSP, HR, and program management
- Maintains the account retention log, including Controlled Unclassified Information (CUI) access determinations and record retention timelines, in accordance with CMMC Level 2 and NIST SP 800-171 requirements
- Performs cadenced security reviews, including monthly audit log reviews in accordance with DEFTEC security policy, compiling reports and flagging anomalies
- Supports maintenance of compliance artifacts, including POA&M tracking, evidence collection, and System Security Plan updates
- Assists in preparation for third-party (C3PAO) assessments and customer compliance inquiries
- Develops and maintains asset refresh schedules, standard asset package definitions, and asset inventory records; coordinates procurement of compliant hardware through approved channels
- Develops training plans and cybersecurity course content; administers training assignments and certification tracking through DEFTEC's HR platform, tracking completion to closure
- Supports the design, development, and maintenance of internal data pipelines, reporting tools, and business process automations using the Microsoft Power Platform
- Supports the evaluation and implementation of enterprise business systems, including requirements analysis, data migration, validation, and reporting
- Documents procedures and contributes to DEFTEC's internal policy and SOP library
Skills
- Must be a US citizen (required for work supporting Department of Defense contracts and the handling of Controlled Unclassified Information)
- Bachelor's degree in cybersecurity, information technology, or a related field, or an equivalent combination of education and experience
- Working knowledge of core cybersecurity principles, including access control, audit logging, and incident response
- Strong analytical and data-management skills, with the ability to compile, interpret, and present security reporting
- Strong written documentation skills and attention to detail
- Demonstrated ability to manage recurring, deadline-driven tasks independently
- Familiarity with Microsoft 365 administration and security tools (Entra ID, Intune, Microsoft Defender, Microsoft Purview)
- Familiarity with NIST SP 800-171, CMMC, and DFARS 252.204-7012 requirements
- Experience with the Microsoft Power Platform (Power Automate, Power BI) or comparable workflow automation tools
- Scripting or data analysis experience (e.g., Python, PowerShell, SQL)
- Experience coordinating with managed service providers or third-party technology vendors
- Current or prior U.S. government security clearance, or eligibility to obtain one
Qualifications
Must Haves
- Must be a US citizen (required for work supporting Department of Defense contracts and the handling of Controlled Unclassified Information)
- Bachelor's degree in cybersecurity, information technology, or a related field, or an equivalent combination of education and experience
- Working knowledge of core cybersecurity principles, including access control, audit logging, and incident response
- Strong analytical and data-management skills, with the ability to compile, interpret, and present security reporting
- Strong written documentation skills and attention to detail
- Demonstrated ability to manage recurring, deadline-driven tasks independently
Nice to Haves
- Familiarity with Microsoft 365 administration and security tools (Entra ID, Intune, Microsoft Defender, Microsoft Purview)
- Familiarity with NIST SP 800-171, CMMC, and DFARS 252.204-7012 requirements
- Experience with the Microsoft Power Platform (Power Automate, Power BI) or comparable workflow automation tools
- Scripting or data analysis experience (e.g., Python, PowerShell, SQL)
- Experience coordinating with managed service providers or third-party technology vendors
- Current or prior U.S. government security clearance, or eligibility to obtain one