Security/Compliance SME

Posted Sep 16

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as the primary reference for policy and compliance across three System Enhancement Studies.

• Analyze and interpret Government-Furnished Information along with relevant DoD, DAF, and Federal regulatory references.

• Offer security and compliance guidance regarding CDO-L edge identity architecture, disconnected operations, break-glass access, PKI certificate validation, and synchronization methods.

• Evaluate security posture management requirements for CDO-L edge node operations.

• Review and document Authority to Operate implications for classified NIPRNet and SIPRNet edge components.

• Provide security and compliance guidance for NPE attribute schemas, governance workflows, credential management policies, and target architecture.

• Review and validate NPE credential management governance, focusing on credential rotation, secret vault storage, and hardcoded credential controls.

• Assess the alignment of NPE governance with Zero Trust Architecture, workload identity, dynamic access control, and continuous authentication.

• Define compliance requirements for NPE audit logging and monitoring, including SOC and ELICSAR integration and UEBA/AI-driven anomaly detection.

• Guide the JML transformation architecture, attribute sanitization, Microsoft Entra ID integration, event-driven group management, and administrator delegation.

• Review and validate Leaver revocation architecture, covering mailbox handling, DAF365 license reclamation, Entra ID token revocation, and Okta disablement sequencing.

• Assess delegated provisioning in relation to least-privilege, separation-of-duties, and audit-trail requirements.

• Conduct compliance gap analysis across studies and identify necessary controls, waivers, or ATO actions.

• Contribute security and compliance sections along with regulatory mappings to three Technical Study Reports.

• Advise the Program Manager and Study Lead Engineers on emerging cybersecurity policy developments from DoD and DAF.

• Assist in drafting Performance Work Statements for future implementation Task Orders.

• Ensure assigned personnel possess the required security clearances and inform the Government of any status changes.


⛳️ Requirements

• Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Systems, or a related field from an accredited institution.

• Over 7 years of experience in cybersecurity, information assurance, or security compliance within Defense or Federal government IT environments.

• Proven experience in interpreting and applying DoD and Federal cybersecurity policy frameworks, including NIST SP 800-53, NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, and related mandates to enterprise IT system design and governance.

• Experience in supporting Authority to Operate (ATO) processes for Defense information systems, including RMF package development, security control assessments, and management of accreditation timelines.

• Active Secret security clearance, with final adjudication required prior to assignment.

• Extensive knowledge of DoD and Federal cybersecurity and identity management policy frameworks.

• Strong comprehension of Zero Trust Architecture principles and their application to enterprise ICAM systems, disconnected edge environments, non-person entity governance, and identity lifecycle management.

• Familiarity with DoD Risk Management Framework (RMF) and Authority to Operate (ATO) processes.

• Knowledge of PKI-based authentication, certificate lifecycle management, DoD/DoW X.509 Certificate Policy, and Common Access Card (CAC) authentication security requirements.

• Experience with Okta and SailPoint IdentityIQ.

• Understanding of DoD audit standards and log management requirements, including CJCSI 6510.01 and SIEM/SOC integration.

• Experience in conducting compliance gap analysis and documenting findings in formal technical reports.

• Ability to interpret and apply complex and conflicting regulatory requirements.

• Experience advising technical engineers and architects on security and compliance necessities.

• Strong technical writing capabilities for compliance assessments, regulatory mappings, technical study reports, and draft Performance Work Statements.

• Ability to collaborate effectively across cross-functional technical teams.

• Excellent written and verbal communication skills in English.

• Capability to obtain and maintain a Secret security clearance.


🏝️ Benefits

• Medical, dental, and vision insurance.

• 401(k) retirement plan.

• Paid time off.

• Paid parental leave.

• Life and disability insurance.

• Flexible spending accounts.

• Commuter benefits.

• Tuition reimbursement.

People also viewed

LabConnect22 hours ago

Head of IT Governance, Risk, Compliance

US flagTennessee OnlyFull-timeCompliance
ApplyView job
Ripple Effect1 day ago

Compliance Analyst

US flagMaryland OnlyFull-timeCompliance$85.3k – $98.1k/year
ApplyView job
Binance1 day ago

Team Lead – Compliance Monitoring, Assurance & Testing

AE flagUnited Arab Emirates (UAE) OnlyFull-timeCompliance
ApplyView job
biBerk Business Insurance1 day ago

Claims Compliance Analyst – Workers' Compensation

US flagUnited States OnlyFull-timeCompliance$77k – $96.5k/year
ApplyView job
Doppel1 day ago

Director, Governance, Risk & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers