Full Time
$4.00/hr USD
40
Mar 12, 2026
About Cadra
Cadra is a cybersecurity and compliance consulting firm that helps organizations in the defense industrial base, healthcare, and federal sectors navigate complex regulatory landscapes. We partner with our clients to achieve and maintain compliance with frameworks including CMMC, FedRAMP, FISMA, and HIPAA, while strengthening their overall security posture. Our team combines deep technical expertise with practical business insight to deliver outcomes that matter.
Role Overview
We are looking for a mid-level Cybersecurity Compliance Analyst who can lead and support compliance assessments across multiple regulatory frameworks while bringing strong business acumen to risk management engagements. This role bridges the gap between technical security controls and business-level risk analysis, making you a critical player on our delivery team. You will conduct assessments, perform Business Impact Analyses (BIAs), and deliver risk assessments that inform client decision-making.
Key Responsibilities
• Conduct cybersecurity compliance assessments for client organizations against CMMC, FedRAMP, FISMA, HIPAA, and NIST frameworks
• Perform gap analyses and develop remediation roadmaps to guide clients toward compliance readiness
• Lead and facilitate Business Impact Analyses (BIAs) to identify critical business processes, dependencies, and acceptable downtime thresholds
• Conduct risk assessments using established methodologies (NIST 800-30, NIST CSF, HIPAA) and produce actionable risk registers and treatment plans
• Develop and review System Security Plans (SSPs), Plan of Action & Milestones (POA&Ms), and other assessment documentation
• Collaborate with client stakeholders, including IT teams, executives, and compliance officers, to gather evidence and communicate findings
• Translate technical security findings into business-relevant recommendations that support executive decision-making
• Support continuous monitoring activities and assist clients in maintaining ongoing compliance
• Contribute to internal process improvement and methodology development across the Cadra team
Required Qualifications
• 3–5 years of experience in cybersecurity compliance, GRC, or IT auditing
• Demonstrated hands-on experience with at least two of the following: CMMC, FedRAMP, FISMA, or HIPAA assessments
• Experience conducting Business Impact Analyses and enterprise risk assessments
• Strong working knowledge of NIST 800-53, NIST
• Ability to interpret technical controls and communicate their business implications clearly
• Excellent written and verbal communication skills in English
• Self-motivated and comfortable working independently in a fully remote, distributed team environment
Preferred Qualifications
• CISA (Certified Information Systems Auditor) or CISSP (Certified Information Systems Security Professional) certification strongly preferred
• Additional relevant certifications such as CRISC, CISM, Security+, or CCSP are a plus
• Experience working with GRC platforms (e.g., RegScale, eMASS, CSAM, or similar)
• Familiarity with cloud security frameworks and assessment of AWS, Azure, or GCP environments
• Prior consulting experience, especially in the GovCon or defense industrial base sectors
• Exposure to SOC 2, ISO 27001, or other industry frameworks is a bonus
Work Schedule & Location
This is a fully remote, contract position. However, candidates must be available to work during U.S. Eastern Standard Time (EST) business hours (approximately 9:00 AM – 5:00 PM EST, Monday through Friday). This is required to ensure real-time collaboration with our U.S.-based team and clients. Please only apply if you can commit to this schedule.
What We Offer
• Opportunity to work on meaningful engagements with defense, federal, and healthcare clients
• A collaborative, supportive team that values professional development and growth
• Exposure to a wide variety of compliance frameworks and cutting-edge security challenges
• Flexible remote work environment with a team that respects work-life balance
• Competitive contract compensation
How to Apply
Interested candidates should submit their resume along with a brief cover letter highlighting their relevant compliance assessment experience and certifications. Please include your availability for EST working hours and your expected contract rate.