Why This Role Stands Out
This Compliance Specialist role offers significant growth within a reputable company and the chance to develop expertise in critical areas like NIST and CMMC. You'll thrive here if you have a keen eye for detail and a passion for ensuring regulatory adherence. Apply to leverage your skills in a dynamic, full-time contract position.
Quick Overview
Seniority
Mid Senior
Work mode
Remote
Location
Lexington, MA, United States
Posted
22 hours ago
AuditingComplianceHIPAARisk ManagementSAP
Job Description
Job Title: Compliance Specialist
Project Duration: 36 Months
Location: Lexington, MA (Onsite )
Duration: Full-Time Contract
Location: Lexington, MA (Onsite )
Duration: Full-Time Contract
Job Description
Position Overview
The IT Security Risk Auditor performs audits of classified and unclassified Information Systems (IS) to ensure that they are maintained in a compliant manner and follow applicable laws and government regulations, including National Industrial Security Program Operating Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM), and Laboratory Information System Security Procedures.
The position is responsible for maintaining and auditing programs to validate compliance with various government regulations and Laboratory Information Security policies. The role conducts comprehensive assessments of the management, operation, monitoring, and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls, including whether controls are implemented correctly, operating as intended, and producing the desired outcome, with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system.
The position also requires the ability to conduct open-source and internal research to identify current threat indicators, exploits, and vulnerabilities.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field.
- Minimum of seven (7) years of experience conducting risk assessments.
- Minimum of seven (7) years of experience documenting audit findings, including non-compliance issues or deviations.
- Minimum of seven (7) years of experience identifying potential compliance issues and recommending policy/procedure changes.
- Minimum of seven (7) years of experience supporting preparation for audit/review activities.
- Minimum of seven (7) years of experience with MS Suite, including Excel and PowerPoint.
- Minimum of three (3) years of experience with IT system security compliance, including NIST, PCI, HIPAA, and CMMC.
- Minimum of three (3) years of STIG compliance experience.
- Minimum of three (3) years of NISPOM 32 CFR Part 117 experience.
- Minimum of three (3) years of NIST SP 800-171 experience.
- Minimum of three (3) years of NIST SP 800-53 experience.
- Minimum of three (3) years of Risk Management Framework (RMF) experience.
- Experience in compliance auditing, security reviews, or vulnerability assessments.
- In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by NIST, NIST SP 800-171, and Security Technical Implementation Guides (STIGs).
- Ability to read, understand, and apply government regulations, policies, and procedures such as NISPOM, 32 CFR Part 117, FAR/DFARS Safeguarding CUI series , etc.), STIGs, NIST 800-53/RMF, and NIST SP 800-171.
- Working experience directly related to Assessment and Authorization using at least one of the following:
- NIST 800-53/Risk Management Framework (RMF)
- Joint Special Access Program (SAP) Implementation Guide
- NIST SP 800-171 / Understanding of CMMC Framework
- National Industrial Security Program Operating Manual (NISPOM) Chapter 8
- Knowledge of fundamental computer security principles and policies, including:
- Security Technical Implementation Guides (STIGs)
- NIST 800-53/Risk Management Framework (RMF)
- CNSSI 1253
- DOD Manual 5205.07 Volumes 1-4
- NIST SP 800-171
- DAAPM 2.0
- Strong verbal and written communication skills.
- Strong time management skills.
Nice to have
- Security+ CE, CASP, CISSP, CISA, or similar security certification.
- Information Assurance certifications such as CISSP/CISA, CCP/CCA, or other industry-recognized certification that validates knowledge in cybersecurity frameworks or equivalent.
- Direct experience with DCSA facility compliance reviews and security audits.
- Experience with Cybersecurity Maturity Model Compliance (CMMC).
Responsibilities
- Conduct audits of classified and unclassified Information Systems.
- Maintain and audit programs to validate compliance with government regulations and Laboratory Information Security policies.
- Conduct comprehensive assessments of management, operation, monitoring, and technical security controls.
- Determine the overall effectiveness of security controls and whether they are implemented correctly, operating as intended, and producing the desired outcome.
- Validate compliance with ATO security requirements and other government regulations or contractual requirements.
- Document audit findings, including non-compliance issues and deviations.
- Identify potential compliance issues and recommend policy and procedure changes.
- Support preparation for audit and review activities.
- Conduct open-source and internal research to identify current threat indicators, exploits, and vulnerabilities.
Work Arrangement
- Hybrid.
- Position will be predominantly onsite for the first 3–4 months, probably 4 days per week onsite.
- After the initial ramp-up period, there may be an opportunity for more remote work, approximately 2–3 days per week.
- Long term, the candidate must be comfortable being onsite at least 2+ days per week and as needed for project work.
Clearance
- Interim clearance is sufficient to start.
- Candidate will need to clear up to the Top Secret level.
Interview Process
- 2 rounds of Zoom interviews.
Similar jobs
- MG
Regulatory Affairs Associate
NewMedinext Global LLC
United States🇺🇸Remote22 hours ago - BN
Vice President, Markets Compliance Manager - Financial Services
NewBNY
Lake Mary, Florida🇺🇸Hybrid1 hour agoRegulatory ReportingFinance - VE
Associate, Financial Crimes Compliance
NewVestwell
New York🇺🇸Hybrid4 hours agoComplianceJiraLexisNexis+3Finance - BI
-Compliance Officer W2
NewBURGEON IT SERVICES LLC
Tallahassee, FL🇺🇸$38/hrOn-site22 hours agoComplianceLegal - TA
Compliance Engineer III
NewTrue Anomaly
Denver🇺🇸Hybrid5 hours agoAWSAzureBusiness Development+3Engineering - MA
Licensing and Regulatory Affairs Associate
NewMajority
United States🇺🇸Hybrid5 hours agoCompliance