Description Position Summary: As a Security Compliance Analyst III, you will serve as a senior compliance professional responsible for assessing, implementing, and maintaining security and regulatory compliance programs …
Description Position Summary The AI Solutions Engineer will play a crucial role in delivering AI-powered automation solutions for our Clients and internal operations. The AI Solutions Engineer will be responsible for des…
Skills: AI Development, Prompt Engineering, LLM Platforms, Azure Services, Business Analysis
Description Position Summary The Technical Account Manager (TAM) serves as the primary technology advisor, relationship manager, and strategic partner for an assigned portfolio of clients. Acting as a trusted advisor and…
Description Company Overview: Bridgehead IT is a leading provider of innovative technology solutions dedicated to guaranteed outcomes that bring peace of mind and improve its clients’ bottom line. With a commitment to op…
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
professional certificate
Posted 20d ago
~40 hrs/week
Responsibilities
Lead security and regulatory compliance programs for clients by performing risk assessments and coordinating audits across various frameworks. Manage compliance requests and remediation efforts through a ticketing system while mentoring junior analysts.
Requirements
Requires 5-7 years of experience in cybersecurity GRC or IT auditing with deep knowledge of frameworks like NIST and ISO. Proficiency in cloud environments (Azure, AWS) and strong technical writing skills are essential.
Full job description
Description
Position Summary:
As a Security Compliance Analyst III, you will serve as a senior compliance professional responsible for assessing, implementing, and maintaining security and regulatory compliance programs for client environments. You will lead compliance initiatives, perform risk assessments, coordinate audits, and work directly with clients to ensure compliance with industry standards and regulatory requirements.
This role requires a strong understanding of cybersecurity frameworks, governance, risk management, and technical security controls. You will work primarily out of a ticketing system to manage compliance requests, audit activities, remediation efforts, and client deliverables while collaborating closely with security engineers, system administrators, cloud engineers, and executive stakeholders. You will also mentor junior compliance analysts and assist in developing internal compliance processes and best practices.
Participation in after-hours work may be required to support audit deadlines, security incidents, or client engagements.
Key Responsibilities:
Work within a structured ticketing system to manage compliance requests, audit activities, remediation tasks, client communications, and documentation.
Lead compliance assessments across client environments using frameworks such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, CMMC, SOC 2, HIPAA, PCI DSS, and other applicable standards.
Conduct formal security and compliance gap assessments and develop remediation plans to address identified deficiencies.
Perform technical and administrative reviews of security controls to validate compliance with applicable frameworks.
Lead and facilitate client readiness assessments for regulatory audits and certification initiatives.
Coordinate internal and external audits, including evidence collection, documentation, interviews, and audit response activities.
Conduct formal cybersecurity risk assessments and document identified risks, mitigation strategies, and residual risk.
Review security policies, standards, procedures, and technical documentation to ensure regulatory alignment.
Work closely with cloud, infrastructure, networking, and security engineering teams to validate technical control implementation.
Monitor remediation activities and verify corrective actions have been successfully completed.
Develop compliance reports, executive summaries, dashboards, and client deliverables.
Assist clients with security governance initiatives, including policy development, security awareness recommendations, and compliance roadmaps.
Maintain detailed documentation including risk registers, assessment reports, audit evidence, and compliance matrices.
Research changes to regulatory requirements and recommend updates to internal processes and client security programs.
Mentor Security Compliance Analyst I and II team members by providing guidance on assessment methodologies, framework interpretation, and documentation standards.
Participate in client meetings to present assessment findings, explain compliance requirements, and provide remediation guidance.
Support security incident response activities when compliance reporting or regulatory notification requirements are involved.
Perform additional duties as assigned.
Skills and Qualifications:
5-7 years of experience in cybersecurity, governance, risk management, compliance, IT auditing, or information security.
Strong working knowledge of cybersecurity frameworks including ISO 27001, NIST CSF, NIST 800-53, CIS Controls, CMMC, SOC 2, HIPAA, and PCI DSS.
Understanding of Microsoft 365, Azure, AWS, Active Directory, identity management, networking, endpoint security, vulnerability management, and cloud security concepts.
Experience interpreting regulatory requirements and translating them into practical technical and administrative controls.
Excellent technical writing, documentation, and report development skills.
Strong communication and presentation skills with the ability to communicate effectively with technical teams, executive leadership, auditors, and clients.
Experience working in ticketing systems such as ConnectWise, ServiceNow, Autotask, or similar service management platforms.
Strong analytical, organizational, and project coordination skills.
Ability to manage multiple client engagements simultaneously while meeting deadlines.
Preferred certifications include ISC2 Certified Information Systems Security Professional (CISSP), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), CompTIA Security+, CompTIA CySA+, ISO 27001 Lead Implementer or Lead Auditor, Certified in Risk and Information Systems Control (CRISC), or CMMC Certified Professional (CCP).
Disclaimer:
The duties and responsibilities described in this job description are not a comprehensive list and additional tasks may be assigned to the employee from time to time. This job description in no way states or implies that these are the only duties to be performed by the employee(s) in this position. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. All duties and responsibilities are essential functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities. To perform this job successfully, the employees will possess the skills, aptitudes, and abilities to perform each duty proficiently. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities.
Related keywords
ISO 27001NIST CSFNIST 800-53CIS ControlsCMMCSOC 2HIPAAPCI DSSCISSPCISACISMSecurity+CySA+CRISCAzureAWS
We deliver guaranteed outcomes that bring peace of mind and improve your business' bottom line.
Industry
IT Services and IT Consulting
Company size
51-200 employees
Founded
1999
Headquarters
San Antonio, Texas
LinkedIn followers
2,489
At Bridgehead IT, we believe technology should empower—not overwhelm—your business. Since 1999, we’ve built a culture rooted in Heart, Authenticity, and Simplicity, delivering customized, end-to-end solutions that align with your goals and elevate your operations. Our team of on-demand experts is obsessed with solving real problems through thoughtful strategy, not quick fixes. We take a holistic approach to IT, blending deep technical expertise with a partnership mindset that puts your vision first. Whether you're scaling, securing, or streamlining, Bridgehead is your trusted ally in building smarter, more profitable outcomes. That’s the Bridgehead Way.
Bridgehead IT isn’t just a technology firm—it’s a place where people thrive. Recognized as a Top Workplace by the San Antonio Express News for four consecutive years (2022–2025), Bridgehead fosters a culture of integrity, collaboration, and growth. Employees enjoy competitive pay, generous benefits including 401k matching, PTO, tuition reimbursement, and flexible work arrangements. But it’s the little things—birthday gift cards mailed to team members’ homes, monthly celebrations with cake, and outings to Top Golf, Andretti’s, and pedicure days—that make Bridgehead feel like home. The company’s commitment to community shines through initiatives like Bridgehead Cares, support for local nonprofits, and active participation in cybersecurity education programs. Whether it’s video game nights, holiday parties with big prizes, or remote-friendly perks like dinner delivery, Bridgehead invests in its people and celebrates their contributions every step of the way
Offices: 1355 Central Pkwy S, Suite 100, San Antonio, Texas 78232, US · 1919 Decatur St, Houston, Texas 77007, US
Managed IT SupportCloud ComputingVirtualization and Consolidation SolutionsDisaster Recovery and Business Continuity SolutionsIdentity ManagementSecurity Risk Analysis & Penetration TestingCustom Application Developmentand IT Cost Control ServicesElectronicsInformation Technology
We deliver guaranteed outcomes that bring peace of mind and improve your business' bottom line.
Industry
IT Services and IT Consulting
Company size
51-200 employees
Founded
1999
Headquarters
San Antonio, Texas
LinkedIn followers
2,489
At Bridgehead IT, we believe technology should empower—not overwhelm—your business. Since 1999, we’ve built a culture rooted in Heart, Authenticity, and Simplicity, delivering customized, end-to-end solutions that align with your goals and elevate your operations. Our team of on-demand experts is obsessed with solving real problems through thoughtful strategy, not quick fixes. We take a holistic approach to IT, blending deep technical expertise with a partnership mindset that puts your vision first. Whether you're scaling, securing, or streamlining, Bridgehead is your trusted ally in building smarter, more profitable outcomes. That’s the Bridgehead Way.
Bridgehead IT isn’t just a technology firm—it’s a place where people thrive. Recognized as a Top Workplace by the San Antonio Express News for four consecutive years (2022–2025), Bridgehead fosters a culture of integrity, collaboration, and growth. Employees enjoy competitive pay, generous benefits including 401k matching, PTO, tuition reimbursement, and flexible work arrangements. But it’s the little things—birthday gift cards mailed to team members’ homes, monthly celebrations with cake, and outings to Top Golf, Andretti’s, and pedicure days—that make Bridgehead feel like home. The company’s commitment to community shines through initiatives like Bridgehead Cares, support for local nonprofits, and active participation in cybersecurity education programs. Whether it’s video game nights, holiday parties with big prizes, or remote-friendly perks like dinner delivery, Bridgehead invests in its people and celebrates their contributions every step of the way
Offices: 1355 Central Pkwy S, Suite 100, San Antonio, Texas 78232, US · 1919 Decatur St, Houston, Texas 77007, US
Managed IT SupportCloud ComputingVirtualization and Consolidation SolutionsDisaster Recovery and Business Continuity SolutionsIdentity ManagementSecurity Risk Analysis & Penetration TestingCustom Application Developmentand IT Cost Control ServicesElectronicsInformation Technology