Data First Jobs

Praxis

Security Analyst – NIST CSF 2.0 Program

Full Time · In Office · USA

Posted Sep 16, 2026

Work Options
Cloud Stack
Job Type
Position Group
  • About the Role
  • We are seeking a hands-on Security Analyst to help to drive the implementation and maturity of its NIST Cybersecurity Framework (CSF) 2.0 program. This role combines cybersecurity, governance, risk, compliance (GRC), and project management responsibilities.
  • The ideal candidate will execute remediation activities, develop security documentation, implement and validate controls, manage risk-related activities, and coordinate efforts across technical and business stakeholders. Success in this role is measured by completed tasks, documented evidence, and measurable program progress.
  • Responsibilities
  • Develop, update, and maintain security policies, procedures, and standards aligned with NIST CSF 2.0.
  • Implement, validate, and document security controls across cloud and SaaS environments.
  • Collect, organize, and maintain audit-ready evidence and compliance documentation.
  • Manage and maintain NIST CSF Current and Target Profiles and control mappings.
  • Perform vendor and third-party risk assessments and track remediation activities.
  • Support customer security questionnaires, due diligence requests, and RFP responses.
  • Create and manage project plans, timelines, dependencies, and remediation roadmaps.
  • Track risks, exceptions, and remediation efforts through closure.
  • Deliver weekly status reports and executive-level program updates.
  • Establish repeatable processes and operational governance practices for long-term sustainability.
  • Required Qualifications
  • 3–6 years of experience in Information Security, IT Risk, or GRC.
  • Experience supporting security framework implementations or audit programs such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or similar.
  • Working knowledge of NIST CSF 2.0, including Functions, Categories, Subcategories, Organizational Profiles, and Implementation Tiers.
  • Hands-on experience securing cloud and SaaS environments.
  • Experience with AWS, Azure, or GCP.
  • Experience implementing and documenting security controls, including access management, logging and monitoring, configuration management, and data protection.
  • Experience conducting vendor risk assessments and maintaining risk registers.
  • Strong project management and stakeholder coordination skills.
  • Excellent technical writing and documentation skills.
  • Ability to work independently and drive initiatives with minimal supervision.
  • Preferred Qualifications
  • Certifications such as CISSP, CISA, CISM, CRISC, Security+, CCSP, CCSK, AWS Security Specialty, or Azure SC-100.
  • PMP, CAPM, or similar project management certification.
  • Experience responding to customer security reviews and vendor due diligence assessments.
  • Familiarity with GRC platforms and compliance management tools.
  • Experience with automation or scripting for evidence collection.

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Security Analyst – NIST CSF 2.0 Program

Praxis

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.