Compliance Specialist
Contract W2
36 Months
Travel Required
On-site
$70 - $75/yr


SECURE RPO LLC
Fitment
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- Auditing
- CISA
- CISSP
- Cyber Security
- DoD
- IT Security
- Industrial Security
- Information Security
- Information Technology
- NISP
- NIST 800-53
- NIST SP 800 Series
- RMF
- Regulatory Compliance
- STIG
- Security Clearance
- System Security
- Security Controls
- Risk Management Framework
- Risk Assessment
- Microsoft PowerPoint
Summary
Job Title: Compliance Specialist
Project Duration: 36 Months
Location: Lexington, MA (Onsite )
Duration: Full-Time Contract
Location: Lexington, MA (Onsite )
Duration: Full-Time Contract
Job Description
Position Overview
The IT Security Risk Auditor performs audits of classified and unclassified Information Systems (IS) to ensure that they are maintained in a compliant manner and follow applicable laws and government regulations, including National Industrial Security Program Operating Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM), and Laboratory Information System Security Procedures.
The position is responsible for maintaining and auditing programs to validate compliance with various government regulations and Laboratory Information Security policies. The role conducts comprehensive assessments of the management, operation, monitoring, and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls, including whether controls are implemented correctly, operating as intended, and producing the desired outcome, with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system.
The position also requires the ability to conduct open-source and internal research to identify current threat indicators, exploits, and vulnerabilities.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field.
- Minimum of seven (7) years of experience conducting risk assessments.
- Minimum of seven (7) years of experience documenting audit findings, including non-compliance issues or deviations.
- Minimum of seven (7) years of experience identifying potential compliance issues and recommending policy/procedure changes.
- Minimum of seven (7) years of experience supporting preparation for audit/review activities.
- Minimum of seven (7) years of experience with MS Suite, including Excel and PowerPoint.
- Minimum of three (3) years of experience with IT system security compliance, including NIST, PCI, HIPAA, and CMMC.
- Minimum of three (3) years of STIG compliance experience.
- Minimum of three (3) years of NISPOM 32 CFR Part 117 experience.
- Minimum of three (3) years of NIST SP 800-171 experience.
- Minimum of three (3) years of NIST SP 800-53 experience.
- Minimum of three (3) years of Risk Management Framework (RMF) experience.
- Experience in compliance auditing, security reviews, or vulnerability assessments.
- In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by NIST, NIST SP 800-171, and Security Technical Implementation Guides (STIGs).
- Ability to read, understand, and apply government regulations, policies, and procedures such as NISPOM, 32 CFR Part 117, FAR/DFARS Safeguarding CUI series , etc.), STIGs, NIST 800-53/RMF, and NIST SP 800-171.
- Working experience directly related to Assessment and Authorization using at least one of the following:
- NIST 800-53/Risk Management Framework (RMF)
- Joint Special Access Program (SAP) Implementation Guide
- NIST SP 800-171 / Understanding of CMMC Framework
- National Industrial Security Program Operating Manual (NISPOM) Chapter 8
- Knowledge of fundamental computer security principles and policies, including:
- Security Technical Implementation Guides (STIGs)
- NIST 800-53/Risk Management Framework (RMF)
- CNSSI 1253
- DOD Manual 5205.07 Volumes 1-4
- NIST SP 800-171
- DAAPM 2.0
- Strong verbal and written communication skills.
- Strong time management skills.
Nice to have
- Security+ CE, CASP, CISSP, CISA, or similar security certification.
- Information Assurance certifications such as CISSP/CISA, CCP/CCA, or other industry-recognized certification that validates knowledge in cybersecurity frameworks or equivalent.
- Direct experience with DCSA facility compliance reviews and security audits.
- Experience with Cybersecurity Maturity Model Compliance (CMMC).
Responsibilities
- Conduct audits of classified and unclassified Information Systems.
- Maintain and audit programs to validate compliance with government regulations and Laboratory Information Security policies.
- Conduct comprehensive assessments of management, operation, monitoring, and technical security controls.
- Determine the overall effectiveness of security controls and whether they are implemented correctly, operating as intended, and producing the desired outcome.
- Validate compliance with ATO security requirements and other government regulations or contractual requirements.
- Document audit findings, including non-compliance issues and deviations.
- Identify potential compliance issues and recommend policy and procedure changes.
- Support preparation for audit and review activities.
- Conduct open-source and internal research to identify current threat indicators, exploits, and vulnerabilities.
Work Arrangement
- Hybrid.
- Position will be predominantly onsite for the first 3–4 months, probably 4 days per week onsite.
- After the initial ramp-up period, there may be an opportunity for more remote work, approximately 2–3 days per week.
- Long term, the candidate must be comfortable being onsite at least 2+ days per week and as needed for project work.
Clearance
- Interim clearance is sufficient to start.
- Candidate will need to clear up to the Top Secret level.
Interview Process
- 2 rounds of Zoom interviews.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 91099714
- Position Id: 9094732
- Posted 16 hours ago
Company Info
About SECURE RPO LLC
Secure RPO LLC is an offshore recruitment service provider with headquartered in Noida, India and US Office in New Castle, Delaware, USA.
Secure RPO LLC is a pioneer in providing the recruitment solutions to the companies based in US & Canada, by providing them dedicated resources and manpower in a cost effective way.
We empower business reach their goals with the help of our guaranteed Return on Investment Model
Create job alert
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs