Haystack
← Back to Jobs
Administrative
AP

Security Compliance Specialist

ApexonAustin, TX🇺🇸United StatesPosted 18 Aug 2026

Why This Role Stands Out

This hybrid role offers a fantastic opportunity to deepen your expertise in critical cybersecurity frameworks like NIST SP 800-53 and RMF, supporting vital government client systems. You'll thrive here if you possess strong analytical skills and a passion for ensuring robust security compliance, making a tangible impact on national security. Don't miss out on this chance to grow your career with a reputable company.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Austin, TX, United States
Posted
3 weeks ago
ScrumAgile

Job Description

Job Summary

We are seeking a Security Compliance Specialist with strong experience in cybersecurity compliance, risk management, vulnerability management, and security documentation. The ideal candidate will have advanced knowledge of NIST SP 800-53, System Security Plans (SSPs), Cyber Assessments, and NIST Risk Management Framework (RMF).

The candidate will support State Government client systems by developing and maintaining compliance documentation, conducting security control assessments, supporting ATO activities, managing POA&Ms, and ensuring systems remain audit-ready.

Key Responsibilities

  • Develop, update, and maintain System Security Plans (SSPs) for State Government client systems.
  • Apply NIST SP 800-53, NIST RMF, and related security frameworks such as FedRAMP, StateRAMP, and CJIS.
  • Conduct security control assessments, risk assessments, and gap analyses, mapping findings to applicable compliance requirements.
  • Prepare and maintain privacy and security documentation, including Privacy Impact Assessments (PIAs) and data-handling policies.
  • Support Authorization to Operate (ATO) packages and coordinate with System Owners, ISSOs, auditors, and other stakeholders.
  • Create, track, and maintain Plans of Action and Milestones (POA&Ms) and monitor remediation activities through closure.
  • Maintain audit-ready documentation and evidence repositories for internal and external compliance reviews.
  • Review vulnerability assessment results from tools such as Nessus, Qualys, Tenable, and Veracode.
  • Analyze vulnerability findings, determine risk ratings, and translate findings into appropriate POA&M and remediation activities.
  • Support security compliance documentation for cloud environments, including Azure Government and AWS GovCloud.
  • Use GitHub or similar version-control/collaboration tools to manage documentation changes and work with technical teams.
  • Work closely with Development, IT, Infrastructure, Security, and Project teams to gather system information and maintain accurate compliance documentation.
  • Clearly document security findings, procedures, risks, remediation plans, and compliance requirements for both technical and non-technical stakeholders.
  • Participate in discovery sessions, project meetings, and Agile/Sprint planning to assess compliance and security impacts.
  • Mentor junior team members on security compliance and documentation best practices.
  • Stay current with evolving NIST, cybersecurity, privacy, and compliance frameworks.
  • Leverage AI-assisted tools to research, troubleshoot, and support technical and compliance-related activities.

Required Qualifications

  • Strong professional experience in Cybersecurity, Security Compliance, GRC, or Information Security.
  • Advanced hands-on experience with NIST SP 800-53.
  • Advanced experience developing and maintaining System Security Plans (SSPs).
  • Strong experience with Cybersecurity Assessments and Security Control Assessments.
  • Strong understanding of NIST Risk Management Framework (RMF).
  • Experience with Vulnerability and Patch Management.
  • Experience with POA&M management, risk remediation, and compliance tracking.
  • Experience supporting ATO processes and security authorization packages.
  • Experience with security and privacy documentation, including PIAs.
  • Working knowledge of Cloud Security, preferably Azure Government or AWS GovCloud.
  • Strong technical documentation and communication skills.
  • Ability to work effectively with technical teams, business stakeholders, auditors, ISSOs, and system owners.

Preferred Qualifications

  • Experience supporting State Government / Public Sector cybersecurity programs.
  • Experience with FedRAMP, StateRAMP, and CJIS compliance.
  • Experience with vulnerability management tools such as Nessus, Qualys, Tenable, or Veracode.
  • Experience with GitHub/GitHub Copilot or similar development and collaboration tools.
  • Familiarity with Agile/Scrum environments and participation in sprint planning.
  • Experience mentoring junior security or compliance professionals.
  • Experience working with Azure Government and/or AWS GovCloud environments.

Similar jobs