
Cybersecurity Compliance Specialist
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Create, revise, and uphold the WWBI Risk Management Framework authorization documentation, which includes the SSP, COOP, IRP, System Design Documents, and associated authorization artifacts.
• Oversee and document security controls and requirements specific to the program related to PII.
• Keep up-to-date documentation that defines the WWBI authorization boundary, encompassing hardware, software, ports, protocols, interfaces, and data flows.
• Facilitate cybersecurity documentation and compliance efforts for WWBI's transition to the CWBI Cloud and its eventual integration into the CWBI authorization boundary.
• Maintain compliance records for WWBI in eMASS, including RMF documentation, evidence of security controls, implementation statements, and other supporting documents.
• Assist in the continuous-monitoring program, which involves coordinating or conducting ACAS and SCAP security scans.
• Achieve and sustain a compliance score of at least 90% for relevant SCAP scans.
• Import and manage security-scan results in DISA STIG Viewer and eMASS.
• Evaluate vulnerabilities and collaborate on remediation efforts with software developers and Government technical personnel.
• Monitor Critical, High, Moderate, and Low findings in accordance with required remediation timelines.
• Record exceptions and unresolved findings in the POA&M.
• Develop, sustain, and submit quarterly POA&M reports.
• Assist with quarterly updates to the RMF documentation package.
• Provide ACAS/SCAP scan results and STIG Viewer files after required scans.
• Maintain up-to-date system security, network topology, and logical and data-flow documentation in collaboration with the development team.
• Complete and uphold security-control checklists mandated by the USACE CWBI Cloud environment.
• Monitor changes in CWBI cybersecurity requirements and coordinate the implementation of new or revised requirements.
• Support annual FISMA reporting obligations and related documentation.
• Facilitate compliance with DoD STIGs, Army cybersecurity requirements, and USACE policies throughout modernization and cloud-migration activities.
• Collaborate closely with software developers, DevSecOps personnel, technical leadership, and Government stakeholders to ensure ongoing compliance.
• U.S. Citizenship is mandatory.
• Proven experience in supporting the DoD Risk Management Framework (RMF), including the development and maintenance of RMF authorization packages and cybersecurity documentation.
• Proficiency in using Enterprise Mission Assurance Support Service (eMASS).
• Familiarity with DoD, U.S. Army, and/or USACE cybersecurity requirements and procedures.
• Experience in vulnerability management, security controls, POA&Ms, and continuous monitoring.
• Knowledge of ACAS, SCAP, DISA STIGs, and STIG Viewer.
• Ability to interpret technical vulnerability findings and coordinate remediation efforts with software development and infrastructure teams.
• Excellent technical writing, documentation, and organizational abilities.
• Capability to manage multiple recurring compliance requirements and deadlines effectively.
• Strong communication skills with technical personnel, program leadership, and Government stakeholders.
• An active federal background investigation at the Tier 1 level or higher must be completed before starting contract performance.
• Must be able to obtain and maintain CompTIA Security+ or a DoD-approved equivalent within six months of contract commencement, as applicable to the assigned DoD 8140 work role.
• Previous experience with USACE systems or applications is preferred.
• Experience with DoD ATO authorization and continuous monitoring is preferred.
• Familiarity with AWS GovCloud or other DoD-authorized cloud environments is preferred.
• Knowledge of DevSecOps, GitHub, secure software development pipelines, and application modernization is preferred.
• Experience in cloud migration for systems operating under an existing RMF authorization is preferred.
• Familiarity with FISMA reporting is preferred.
• Possession of CISSP or another advanced DoD-recognized cybersecurity certification is desirable.
• Flexible remote work arrangement.
• Full-time employment opportunity.
• Chance to contribute to national defense and intelligence missions.
• Opportunities for career advancement.
• Support for Security+ or DoD 8140-approved equivalent certification within six months, as applicable.
• Potential to obtain a CAC if required by assigned duties.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.