Haystack
← Back to Jobs
Administrative
AP

Security Compliance Specialist

ApexonAustin, TX🇺🇸United StatesPosted Sep 22, 2026

Why This Role Stands Out

This hybrid role offers a fantastic opportunity to deepen your expertise in critical cybersecurity frameworks like NIST SP 800-53 and RMF, supporting vital government client systems. You'll thrive here if you possess strong analytical skills and a passion for ensuring robust security compliance, making a tangible impact on national security. Don't miss out on this chance to grow your career with a reputable company.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Austin, TX, United States
Posted
1 week ago

Job Description

Security Compliance Specialist

Location: Austin, TX

Position Overview

The ideal candidate will have strong hands-on experience with NIST SP 800-53, System Security Plans (SSPs), cybersecurity assessments, vulnerability/patch management, and cloud security compliance.

Required Skills

  • Vulnerability/Patch Management: Intermediate

  • NIST SP 800-53: Advanced

  • System Security Plans (SSPs): Advanced

  • Cybersecurity Assessments: Advanced

  • Cloud Security: Foundation

  • NIST Risk Management Framework (RMF)

  • Security Control Assessments

  • Compliance Gap Analysis

  • POA&M Management

  • ATO / Authorization Support

  • Risk Assessment and Security Documentation

  • Audit Readiness and Evidence Management

Key Responsibilities

  • Develop, update, and maintain System Security Plans (SSPs) for State Government client systems.

  • Apply NIST SP 800-53, NIST RMF, and related security frameworks to assess and document system security posture.

  • Apply applicable frameworks and requirements such as FedRAMP, StateRAMP, and CJIS, as appropriate.

  • Conduct security control assessments and compliance gap analyses, mapping findings to applicable security and regulatory requirements.

  • Prepare privacy and data protection documentation, including Privacy Impact Assessments (PIAs) and data handling policies.

  • Support Authorization to Operate (ATO) packages and coordinate with system owners, ISSOs, auditors, and other stakeholders.

  • Develop and track Plans of Action and Milestones (POA&Ms) and monitor remediation activities through completion.

  • Maintain audit-ready documentation, security artifacts, and evidence libraries for compliance reviews and assessments.

  • Review vulnerability scan results from tools such as Nessus, Qualys, Tenable, and Veracode.

  • Translate vulnerability findings into appropriate risk ratings, remediation recommendations, and POA&M entries.

  • Support cloud security compliance documentation for environments such as Azure Government and AWS GovCloud.

  • Use GitHub or similar version-control/collaboration tools to manage documentation changes and collaborate with technical teams.

  • Leverage AI tools to research, troubleshoot, and resolve technical and cybersecurity compliance issues.

  • Work with development, IT, infrastructure, and project teams to gather system information required for security and compliance documentation.

  • Clearly document security findings, procedures, remediation plans, and compliance requirements for both technical and non-technical stakeholders.

  • Participate in discovery sessions and sprint planning and provide input regarding security and compliance impacts.

  • Mentor junior team members on security compliance and documentation practices.

  • Monitor changes to NIST and other security, privacy, and regulatory frameworks and incorporate applicable updates into compliance activities.

  • Collaborate with cross-functional teams to maintain continuous compliance and audit readiness.

Preferred Qualifications

  • Experience with GitHub Copilot or similar AI-assisted development/productivity tools.

  • Experience with vulnerability scanning and application security tools such as Veracode.

  • Experience supporting State Government cybersecurity programs.

  • Experience with cloud security compliance in AWS and/or Azure Government environments.

  • Experience with FedRAMP, StateRAMP, CJIS, or comparable regulatory frameworks.

Similar jobs