Haystack
← Back to Jobs
Technology
KE

IT Compliance Specialist

KelltonMelville, NY🇺🇸United StatesPosted Sep 25, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Melville, NY, United States
Posted
17 hours ago
EncryptionIoTPenetration Testing

Job Description

Kellton Tech is a full-service software development company, offering end-to-end IT solutions, strategic technology consulting and product development services in Web, SMAC (Social, Mobile, Analytics, Cloud), ERP-BPM, and IoT space Our methodology of inventing infinite possibilities with technology helps us develop best in-class and cost effective solutions for our clients

Currently Kellton Tech is looking for talented resources for one of their listed clients
Below are further details on the position:

Position: IT Compliance Specialist

Location: Melville, NY

Rate: All Inclusive

Duration: 6 months+

Job Description:

We are seeking an experienced IT Compliance Specialist to oversee, maintain, and strengthen compliance across PCI-DSS, SOX (ITGC), and CMMC / NIST SP 800-171.

You will act as the primary SME designing controls, managing audits, driving remediation, and translating regulatory requirements into engineering practices.

Key Responsibilities

PCI-DSS Compliance

Lead annual PCI-DSS 4.0 compliance, scoping, gap assessments, and AOC/ROC or SAQ coordination.

Partner with engineering and operations to enforce payment data segmentation, tokenization, and encryption standards.

Oversee quarterly vulnerability scans, penetration testing schedules, and log monitoring.

SOX (Sarbanes-Oxley) ITCompliance

Own execution and testing of ITand ITAC controls supporting SOX 404. Audit access management, change management, SDLC, and IT operations controls.

Serve as primary liaison to financial auditors for walkthroughs, evidence collection, and remediation tracking.

CMMC & Defence Compliance

Lead readiness and maintenance for CMMC 2.0 (Level 2+) and NIST SP 800-171/800-172. Maintain critical documentation, including SSP, POA&M, and scoping architecture.

Track SPRS scores and prepare the organization for C3PAO third-party assessments.

Governance, Audit & Risk Management

Perform cross-framework mapping to minimize control redundancy.

Track control gaps and manage corrective action plans (CAPs) to closure.

Utilize automated GRC tools for continuous monitoring and provide executive status reporting.


For more information, please contact Sam Chary @ 6.3.0.7.2.9.0.3.7.3 Thank you for all your time!

Similar jobs