Compliance Specialist

Lexington, MA, US • Posted 10 hours ago • Updated 10 hours ago
Contract W2
Contract Corp To Corp
3 Years
On-site
$60 - $70/hr
Fitment

Dice Job Match Score™

🔗 Matching skills to job...

Job Details

Skills

  • Auditing
  • CISSP
  • Cyber Security
  • DoD
  • IT Security
  • Compliance Specialist
  • Risk Assessment
  • NIST 800-53
  • RMF (Risk Management Framework)
  • NIST SP 800-171
  • STIGs
  • NISPOM
  • FAR
  • DFARS
  • CMMC
  • DAAPM
  • Security Reviews
  • Vulnerability Assessments
  • Security Controls
  • DCSA
  • CUI
  • CISA
  • Security Governance
  • Information Assurance
  • Incident Response
  • Security Compliance
  • Internal Audits

Summary

Job Title:

Compliance Specialist

Duration:

3 Years (High Possibility of Extension)

Location:

Lexington, MA

Job Description:

Clearance:

An interim clearance is sufficient for start

Work Location:

This position will be predominantly onsite for the first 3-4 months (probably 4 days/wk onsite). After the initial ramp up period, there may be an opportunity for more remote, 2-3 days/week.

Interview Process:

Initial zoom interview, second round zoom

DESCRIPTION:

Develops and oversees compliance programs, supporting compliance efforts, governance/policy, reporting, and incident response. Ensures that the organization remains compliant with all regulations and policies as required based on the local and federal requirements, specifically FAR and DFAR regulations. Conducts internal compliance reviews and documents findings. May participate in internal or external audits. Recommends process or policy change to increase compliance or efficiencies. Generates reports and analyzes data on applicable compliance related topics. Engages with internal stakeholders and any external partners as needed. Develops presentations and collateral for compliance related topics.

Background/Need:

The Security Services Department s (SSD) overall mission is to enable research and development while keeping the Lincoln Laboratory community safe and secure through the protection of information, network, facilities and personnel.

Other information relevant to the job requirement?

The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies: Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0.

Responsible for maintaining and auditing programs to validate compliance with various government regulations and Laboratory Information Security policies. The position is responsible for conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls (i.e. the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome) with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system and for the ability to conduct open source and internal research to identify current threat indicators, exploits, and vulnerabilities.

Requirements:

  • Bachelor s degree in computer science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years experience conducting risk assessments.
  • Experience in compliance auditing, security reviews, or vulnerability assessments.
  • Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience.
  • In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800-171 and Security Technical Implementation Guides (STIGs).
  • The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR/DFARS Safeguarding CUI series , etc.), computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF) and NIST SP 800-171.

Working experience directly related to Assessment and Authorization using at least one of the following:

  • NIST 800-53/Risk Management Framework (RMF)
  • Joint Special Access Program (SAP) Implementation Guide
  • NIST SP 800-171 Understanding of CMMC Framework
  • National Industrial Security Program Operating Manual (NISPOM) Chapter 8

Preferred:

  • Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).
  • Direct experience with DCSA facility compliance reviews and security audits.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10123373
  • Position Id: SUC_SYE2043
  • Posted 10 hours ago
Contact the job poster
SC

Sucharita Chokakula

Recruiter @ SGS Consulting
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Lexington, Massachusetts

14d ago

Easy Apply

Contract

Depends on Experience

Hybrid in Lexington, Massachusetts

7d ago

Easy Apply

Contract

65 - 70

Hybrid in Boston, Massachusetts

6d ago

Easy Apply

Contract

25 - 60

Natick, Massachusetts

Today

Full-time

USD 118,400.00 - 183,600.00 per year

Search all similar jobs