
Cybersecurity Compliance Lead
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in United States.
• Take ownership and enhance the organization's cybersecurity compliance program in alignment with NIST 800-171 and NIST 800-53 standards.
• Act as the main point of contact for government cybersecurity teams, assessors, and sponsors.
• Represent the organization during audits and evaluations.
• Lead the creation, upkeep, and ongoing enhancement of System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and related compliance documentation.
• Establish and uphold protocols for the handling, storage, and transmission of Controlled Unclassified Information (CUI).
• Ensure adherence to EAR and ITAR export-control requirements across systems, data, and personnel.
• Perform security control assessments, gap analyses, and risk evaluations.
• Drive remediation efforts to completion.
• Collaborate with IT, Security, Engineering, and Legal teams to integrate compliance requirements into systems and processes.
• Prepare the organization for third-party evaluations and government accreditation initiatives, such as CMMC.
• Assist with RMF/ATO packages for sponsor-accredited systems.
• Support compliance for classified information systems in ISSM/ISSO-type roles, coordinating with the facility security officer.
• Over 8 years of experience in cybersecurity compliance, information assurance, or a related field.
• Proven experience working with government cybersecurity teams and for organizations that must comply with government security standards.
• Practical experience in implementing and evaluating NIST 800-171 and NIST 800-53 controls.
• Experience in managing and safeguarding Controlled Unclassified Information (CUI).
• Thorough understanding of EAR and ITAR export-control regulations.
• Experience in developing and maintaining System Security Plans (SSPs) and POA&Ms.
• Active U.S. security clearance; TS/SCI is preferred.
• Hands-on experience with RMF, including ATO package development.
• Familiarity with NISPOM / 32 CFR Part 117.
• Relevant certifications such as CISSP, CISM, and CAP are advantageous.
• Must fulfill applicable U.S. export-control eligibility criteria for access to export-controlled information: be a U.S. person, be eligible for access without export authorization, or be eligible and reasonably likely to secure required export authorization.
• Competitive equity grant.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• 401k retirement plan.
• Short-term disability insurance.
• Long-term disability insurance.
• Life insurance.
• Three weeks of paid vacation for new employees.
• 12 paid holidays.
• Unlimited sick time.
• Paid parental leave.
GuidePoint Security
Gravie
Your Software Supplier
Dragonfli Group
Get handpicked remote jobs straight to your inbox weekly.