{"id":1917446,"url":"https://alion.io/job/knox-systems-compliance-analyst-cloud-security","title":"Compliance Analyst - Cloud Security","company":{"id":679210,"name":"Knox Systems","domain":"knoxsystems.com","url":"https://alion.io/company/knoxsystems","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":null},"role":"Legal","role_family":"Legal","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Arlington, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":100000,"max":115000,"currency":"USD","period":"year","gross":null,"usd_annual":115000},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"FedRAMP","optional":false},{"name":"GCP","optional":false},{"name":"IAM","optional":false},{"name":"NIST 800-171","optional":false},{"name":"NIST 800-53","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"SOC 2","optional":false},{"name":"SIEM","optional":true}],"status":"live","first_seen_at":"2026-10-05T15:21:00Z","employer_posted_date":"2026-10-05","last_verified_at":"2026-10-08T02:40:56Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"About Knox\nKnox runs the largest Federal & DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions - from national security and public safety to essential public services. Our customers rely on Knox to deploy production systems that meet the highest standards for security, reliability, and compliance.\nWork at Knox is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.\nKnox is seeking a Compliance Analyst with strong technical and regulatory expertise to help ensure Knox and its customers continuously meet federal and commercial compliance requirements. This role is responsible for driving ongoing compliance across FedRAMP, FISMA, NIST 800-53, IL4, IL5, CMMC, SOC 2, StateRamp, and GovRAMP environments while partnering closely with Security, DevOps, Operations, and customer teams.\nThis is not a point-in-time audit support role. This position is expected to operate as a technical compliance lead who can validate controls in cloud environments, track remediation and POA&M performance, enforce compliance SLAs, support audits and assessments, and provide clear risk visibility to internal leadership and customers.\nKey Responsibilities\nAssist with continuous compliance oversight for Knox and assigned customer environments across FedRAMP, FISMA, NIST 800-53, IL4, IL5, CMMC, SOC 2, StateRamp, GovRAMP, and related frameworks.\nTrack and enforce compliance obligations, remediation deadlines, POA&M milestones, vulnerability remediation timelines, and continuous monitoring requirements.\nReview and validate technical control implementation across AWS, Azure, and GCP environments, including logging, monitoring, IAM, incident response, vulnerability management, endpoint security, network segmentation, and change management.\nPartner with Sr. Compliance specialists and Security Operations, Compliance, DevOps, Engineering, and customer teams to ensure required controls are implemented and operating effectively.\nSupport FedRAMP authorization and ongoing assessment activities, including SSP updates, evidence collection, ConMon support, 3PAO coordination, audit preparation, and customer artifact reviews.\nEvaluate findings and weaknesses using both compliance requirements and operational risk, including exploitability, exposure, compensating controls, and customer responsibility boundaries.\nMaintain visibility into customer compliance posture and ensure customers meet shared-responsibility obligations and required service-level timelines.\nAssist with customer-facing compliance activities, including coordinating Continuous Monitoring (ConMon) submissions, leading POA&M reviews, managing Security Change Requests/Notifications (SCR/SCN) with customers, and acting as a primary liaison for agency communication.\nPrepare dashboards, metrics, and executive reporting for overdue findings, POA&Ms, control gaps, remediation status, audit readiness, and overall compliance posture.\nEscalate material compliance gaps, SLA misses, and recurring customer issues to Knox leadership with clear recommendations and risk context.\nAssist with documentation of Knox’s compliance processes, templates, playbooks, and automation capabilities, leveraging compliance-as-code and KnoxAI, to support scalable, repeatable, and audit-ready operations.\nQualifications\n3-5 years of experience in cybersecurity compliance, GRC, cloud security, or related security assurance roles.\nExperience with FedRAMP and NIST SP 800-53 in cloud or SaaS environments.\nWorking knowledge of FISMA, SOC 2, StateRamp, GovRAMP, and at least one of the following: IL4, IL5, CMMC, NIST 800-171.\nExperience supporting audits, assessments, or authorization activities in regulated cloud environments.\nUnderstanding of cloud platforms such as AWS, Azure, and/or GCP and how security controls are implemented within them.\nExperience partnering with technical teams such as DevOps, SOC, SRE, Engineering, or IT Operations to validate control implementation and drive remediation.\nAbility to assist with and manage multiple customers, priorities, deadlines, and dependencies in a fast-paced environment.\nStrong written and verbal communication skills, including the ability to explain compliance requirements, technical findings, and risk decisions clearly to both technical and non-technical stakeholders.\nExperience with shared responsibility models in managed cloud or regulated SaaS environments.\nCertifications such as CISSP, CISA, CAP, Security+, CCSP, or cloud security certifications.\nExperience in a high-growth cloud company, managed services provider, or regulated SaaS provider.\nSuccess in This Role\nKnox and assigned customers maintain strong compliance posture with minimal overdue remediation items.\nAudit and assessment artifacts are complete, accurate, and ready when needed.\nControl gaps are identified early and driven to closure.\nCustomers clearly understand what they own, what Knox owns, and what deadlines must be met.\nLeadership has accurate, timely visibility into compliance health, risk, and SLA performance.\nPreferred Qualifications\nExperience with FedRAMP High and/or DoD IL4 / IL5 environments.\nExperience working with continuous monitoring, POA&M governance, vulnerability remediation tracking, and customer audit readiness.\nFamiliarity with cloud/security tooling such as CSPM, SIEM, EDR/XDR, ticketing/GRC platforms, and evidence automation workflows.\nCompensation Range: $100-$115k, variable annual bonus, and equity\nBenefits & Perks\nKnox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PTO, and an employee funded 401k plan. Please note, benefits are subject to change.\nWe are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other legally protected status.\nKnox is proud to support veteran hiring - we encourage veterans and transitioning service members to apply and welcome the unique skills and experience you bring.\nHiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.\nAny offer of employment is contingent upon the successful completion of all required pre-employment screenings, including a background check, in accordance with applicable laws and government contract requirements.","description_format":"text","description_chars":7230,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["401k plan","Equity","Unlimited PTO"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cloud Security","Security Compliance"],"lifecycle":[{"event":"open","at":"2026-10-05T16:49:57Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":34,"reasons":["conf:0","velocity","win:early"],"computed_at":"2026-10-07T05:47:15Z"},"pay":{"stated_usd_annual":115000,"is_top_pay":false},"html_url":"https://alion.io/job/knox-systems-compliance-analyst-cloud-security","json_url":"https://alion.io/job/knox-systems-compliance-analyst-cloud-security.json","meta":{"generated_at":"2026-10-08T02:49:30Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4935,"day_limit":5000,"remaining_today":65,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":679210},"rest":"https://alion.io/mcp/rest/get_company?id=679210"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fknox-systems-compliance-analyst-cloud-security"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fknox-systems-compliance-analyst-cloud-security"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fknox-systems-compliance-analyst-cloud-security"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/knox-systems-compliance-analyst-cloud-security\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fknox-systems-compliance-analyst-cloud-security"}]}