Haystack
← Back to Jobs
Administrative

Security Compliance Specialist

ApexonAustin, TX🇺🇸United StatesPosted 18 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Summary

We are seeking a Security Compliance Specialist with strong experience in cybersecurity compliance, risk management, vulnerability management, and security documentation. The ideal candidate will have advanced knowledge of NIST SP 800-53, System Security Plans (SSPs), Cyber Assessments, and NIST Risk Management Framework (RMF).

The candidate will support State Government client systems by developing and maintaining compliance documentation, conducting security control assessments, supporting ATO activities, managing POA&Ms, and ensuring systems remain audit-ready.

Key Responsibilities

  • Develop, update, and maintain System Security Plans (SSPs) for State Government client systems.
  • Apply NIST SP 800-53, NIST RMF, and related security frameworks such as FedRAMP, StateRAMP, and CJIS.
  • Conduct security control assessments, risk assessments, and gap analyses, mapping findings to applicable compliance requirements.
  • Prepare and maintain privacy and security documentation, including Privacy Impact Assessments (PIAs) and data-handling policies.
  • Support Authorization to Operate (ATO) packages and coordinate with System Owners, ISSOs, auditors, and other stakeholders.
  • Create, track, and maintain Plans of Action and Milestones (POA&Ms) and monitor remediation activities through closure.
  • Maintain audit-ready documentation and evidence repositories for internal and external compliance reviews.
  • Review vulnerability assessment results from tools such as Nessus, Qualys, Tenable, and Veracode.
  • Analyze vulnerability findings, determine risk ratings, and translate findings into appropriate POA&M and remediation activities.
  • Support security compliance documentation for cloud environments, including Azure Government and AWS GovCloud.
  • Use GitHub or similar version-control/collaboration tools to manage documentation changes and work with technical teams.
  • Work closely with Development, IT, Infrastructure, Security, and Project teams to gather system information and maintain accurate compliance documentation.
  • Clearly document security findings, procedures, risks, remediation plans, and compliance requirements for both technical and non-technical stakeholders.
  • Participate in discovery sessions, project meetings, and Agile/Sprint planning to assess compliance and security impacts.
  • Mentor junior team members on security compliance and documentation best practices.
  • Stay current with evolving NIST, cybersecurity, privacy, and compliance frameworks.
  • Leverage AI-assisted tools to research, troubleshoot, and support technical and compliance-related activities.

Required Qualifications

  • Strong professional experience in Cybersecurity, Security Compliance, GRC, or Information Security.
  • Advanced hands-on experience with NIST SP 800-53.
  • Advanced experience developing and maintaining System Security Plans (SSPs).
  • Strong experience with Cybersecurity Assessments and Security Control Assessments.
  • Strong understanding of NIST Risk Management Framework (RMF).
  • Experience with Vulnerability and Patch Management.
  • Experience with POA&M management, risk remediation, and compliance tracking.
  • Experience supporting ATO processes and security authorization packages.
  • Experience with security and privacy documentation, including PIAs.
  • Working knowledge of Cloud Security, preferably Azure Government or AWS GovCloud.
  • Strong technical documentation and communication skills.
  • Ability to work effectively with technical teams, business stakeholders, auditors, ISSOs, and system owners.

Preferred Qualifications

  • Experience supporting State Government / Public Sector cybersecurity programs.
  • Experience with FedRAMP, StateRAMP, and CJIS compliance.
  • Experience with vulnerability management tools such as Nessus, Qualys, Tenable, or Veracode.
  • Experience with GitHub/GitHub Copilot or similar development and collaboration tools.
  • Familiarity with Agile/Scrum environments and participation in sprint planning.
  • Experience mentoring junior security or compliance professionals.
  • Experience working with Azure Government and/or AWS GovCloud environments.

Skills

Scrum
Agile

Similar jobs