GRC Specialist


Apexon
Dice Job Match Score™
🎯 Assessing qualifications...
Job Details
Skills
- NIST SP 800 Series
- Patch Management
- Risk Assessment
- Risk Management Framework
- System Security
- Security Controls
- Vulnerability Assessment
- Vulnerability Management
- Information Security
- Auditing
- Cyber Security
- Document Management
- Data Security
- FedRAMP
- Regulatory Compliance
Summary
We are seeking an experienced Security Compliance Specialist to support security, privacy, risk, and compliance activities for State Government client systems. The ideal candidate will have strong expertise in NIST SP 800 53, System Security Plans, security assessments, vulnerability management, and compliance documentation. The candidate will work closely with system owners, ISSOs, auditors, development teams, and IT stakeholders to maintain security authorization and compliance requirements.
Key Responsibilities:
• Develop, update, and maintain System Security Plans (SSPs) for State Government systems
• Apply NIST SP 800 53, NIST Risk Management Framework, and applicable regulatory frameworks to assess and document security posture
• Conduct security control assessments, gap analyses, and compliance reviews
• Map assessment findings to applicable security and compliance requirements
• Prepare privacy documentation including Privacy Impact Assessments and data handling policies
• Support Authorization to Operate packages and coordinate with system owners, ISSOs, and auditors
• Track Plans of Action and Milestones and monitor remediation activities
• Maintain audit ready compliance documentation and evidence repositories
• Review vulnerability assessment results and translate findings into risk ratings and remediation actions
• Support security compliance documentation for cloud environments such as Azure Government and AWS GovCloud
• Use GitHub or similar collaboration tools to manage documentation changes
• Leverage AI tools to research and troubleshoot technical and compliance issues
• Work with development, IT, and project teams to gather information required for compliance documentation
• Document findings, procedures, risks, and remediation plans for technical and nontechnical stakeholders
• Participate in discovery sessions and provide compliance input during sprint planning
• Mentor junior team members on security compliance documentation practices
• Stay current with evolving security, privacy, and compliance frameworks
Required Skills:
• Advanced knowledge of NIST SP 800 53
• Advanced experience developing and maintaining System Security Plans
• Advanced experience conducting cyber security assessments and gap analyses
• Intermediate experience with vulnerability and patch management
• Foundation level knowledge of cloud security concepts
• Experience with NIST Risk Management Framework and security authorization processes
• Experience developing compliance and privacy documentation
• Experience supporting ATO packages, POA&Ms, and audit activities
• Strong understanding of security controls, risk assessment, remediation tracking, and compliance evidence
• Excellent technical writing, documentation, communication, and stakeholder management skills
Preferred Skills:
• Experience with FedRAMP, StateRAMP, or CJIS compliance frameworks
• Experience supporting Azure Government or AWS GovCloud environments
• Experience with vulnerability assessment platforms such as Nessus, Qualys, Tenable, or Veracode
• Experience using GitHub for documentation management and technical collaboration
• Experience with GitHub Copilot or similar AI assisted development tools
• Experience supporting State Government or public sector security programs
• Experience working with privacy assessments and data protection requirements
• Security or compliance certifications are a plus
Education Requirement:
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related field preferred. Equivalent professional experience may be considered.
- Dice Id: tecnos
- Position Id: 9058232
- Posted 12 hours ago
Company Info
Apexon is a digital technology services and platform solutions company that partners with clients to improve their digital experience and insight. With more than 25 years of experience, our 5000+ Apexers in more than 10 offices worldwide are helping companies enhance their digital experience with their customers.
We work in the areas of digital experience, analytics, AI and cloud to unlock the power of technology for our clients to empower humans with intelligent and experiential solutions. We enable #HumanFirstDigital.

Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs