Security Compliance Specialist
Contract W2
12 Months
75% Travel Required
Hybrid
$65 - $70/hr


SECURE RPO LLC
Fitment
Dice Job Match Score™
👤 Reviewing your profile...
Job Details
Skills
- Auditing
- Cyber Security
- DoD
- HIPAA
- Information Security
- Industrial Security
- Microsoft Excel
- NIST SP 800 Series
- Risk Assessment
- System Security
- Security Controls
Summary
Job Title: IT Security Compliance Specialist
Project Duration: 24+ Months
Location: Lexington, MA (Hybrid)
Location: Lexington, MA (Hybrid)
Position Overview
The IT Security Risk Auditor performs audits of classified and unclassified Information Systems (IS) to ensure that they are maintained in a compliant manner and are following applicable laws and government regulations, including National Industrial Security Program Operating Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM), and Laboratory Information System Security Procedures.
The position is responsible for maintaining and auditing programs to validate compliance with government regulations and Laboratory Information Security policies. The role includes conducting comprehensive assessments of management, operational, monitoring, and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls in meeting Authorization to Operate (ATO), government regulatory, and contractual security requirements.
The candidate will also conduct open-source and internal research to identify current threat indicators, exploits, and vulnerabilities.
Responsibilities
- Conduct audits of classified and unclassified Information Systems (IS).
- Document audit findings, including non-compliance issues and deviations.
- Identify potential compliance issues and recommend policy and procedure changes.
- Support preparation for audit and review activities.
- Maintain and audit programs to validate compliance with government regulations and Laboratory Information Security policies.
- Conduct comprehensive assessments of management, operational, monitoring, and technical security controls.
- Evaluate the effectiveness of security controls in support of Authorization to Operate (ATO) requirements.
- Perform compliance auditing, security reviews, risk assessments, and vulnerability assessments.
- Conduct open-source and internal research to identify threat indicators, exploits, and vulnerabilities.
Required Qualifications
- Bachelor''s degree in Computer Science, Information Technology, Computer Information Systems, or a related field.
- Minimum seven (7) years of experience conducting risk assessments.
- Minimum seven (7) years of experience in compliance auditing.
- Experience with security reviews or vulnerability assessments.
- Technical experience, coursework completed toward a degree, and industry IT certifications may be considered substitutes for education and experience.
- Strong verbal and written communication skills.
- Strong time management skills.
- Minimum seven (7) years of experience with Microsoft Office Suite, including Excel and PowerPoint.
Required Technical Skills
- IT system security compliance (NIST, PCI, HIPAA, CMMC)
- Security Technical Implementation Guides (STIGs)
- NIST SP 800-53 / Risk Management Framework (RMF)
- NIST SP 800-171
- NISPOM (32 CFR Part 117)
- CNSSI 1253
- DOD Manual 5205.07 Volumes 1–4
- FAR/DFARS Safeguarding CUI requirements , etc.)
- DCSA Assessment and Authorization Process Manual (DAAPM 2.0)
Assessment & Authorization Experience
Experience with one or more of the following:
- NIST SP 800-53 / Risk Management Framework (RMF)
- Joint Special Access Program (SAP) Implementation Guide
- NIST SP 800-171
- Cybersecurity Maturity Model Certification (CMMC) Framework
- National Industrial Security Program Operating Manual (NISPOM) Chapter 8
Preferred Qualifications
- Security+ CE
- CASP
- CISSP
- CISA
- CCP/CCA or other industry-recognized cybersecurity certification
- Direct experience with DCSA facility compliance reviews and security audits.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 91099714
- Position Id: 9024856
- Posted 7 days ago
Company Info
About SECURE RPO LLC
Secure RPO LLC is an offshore recruitment service provider with headquartered in Noida, India and US Office in New Castle, Delaware, USA.
Secure RPO LLC is a pioneer in providing the recruitment solutions to the companies based in US & Canada, by providing them dedicated resources and manpower in a cost effective way.
We empower business reach their goals with the help of our guaranteed Return on Investment Model
Create job alert
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs