
Security and Compliance Engineer – CMMC/NIST SP 800-171
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Massachusetts.
• Engage in daily security operational activities in collaboration with clients;
• Identify and document client vulnerabilities and security risks, creating mitigation strategies;
• Oversee and verify the effectiveness of client security controls;
• Address security alerts, incidents, and concerns promptly;
• Ensure that security controls adhere to various compliance requirements and industry best practices;
• Conduct, draft, and deliver client Security and Risk Assessments utilizing recognized frameworks (such as NIST SP 800-171 and PCI DSS v3.2 or other relevant security compliance frameworks);
• Develop precise network diagrams and documentation to facilitate security-based modifications, assess network impact, and formulate resolution procedures;
• Organize and monitor security awareness training for the organizational workforce regarding information security standards, policies, and best practices;
• Regularly review applicable Cyber Security Compliance standards to inform clients about updates and changes in requirements;
• Aid in the investigation of security breaches by leading incident response efforts to reduce impact, identify the breach's cause, and assess the damage extent;
• Travel as necessary for on-site assessments and meetings at client sites; this will be limited and infrequent.
• A Bachelor's degree is preferred, ideally in Information Technology or another engineering or technical field;
• 6-8 years of IT experience, with a minimum of 4 years in Cyber Security Information;
• One or more industry-recognized security certifications are REQUIRED, such as Certified Information Systems Security Professional (CISSP), CISA Certified Information Systems Auditor (CISA), CISM Certified Information Security Manager (CISM), ISSAP Information Systems Security Architecture Professional (ISSAP), ISSEP Information Systems Security Engineering Professional (ISSEP); (OR equivalent);
• Proficiency with modern operating systems, including Windows 10/11 and Server 2016/2019, macOS, and Linux;
• Comprehensive understanding of NIST SP 800-171, CIS Controls, and/or other security compliance frameworks;
• Experience in formulating organization security policies and executing revised policies;
• Familiarity with endpoint security solutions, encompassing file integrity monitoring and data loss prevention.
• Health and Dental coverage;
• Life Insurance;
• Paid Time Off;
• Discretionary Bonus;
• Retirement Savings with Employer Matching Contribution;
• 401(k) plan;
• 401(k) matching;
• Dental insurance;
• Flexible spending account;
• Health insurance;
• Life insurance;
• Paid time off;
• Vision insurance.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.