
Security/Compliance SME
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in United States.
• Act as the primary reference for policy and compliance across three System Enhancement Studies.
• Analyze and interpret Government-Furnished Information along with relevant DoD, DAF, and Federal regulatory references.
• Offer security and compliance guidance regarding CDO-L edge identity architecture, disconnected operations, break-glass access, PKI certificate validation, and synchronization methods.
• Evaluate security posture management requirements for CDO-L edge node operations.
• Review and document Authority to Operate implications for classified NIPRNet and SIPRNet edge components.
• Provide security and compliance guidance for NPE attribute schemas, governance workflows, credential management policies, and target architecture.
• Review and validate NPE credential management governance, focusing on credential rotation, secret vault storage, and hardcoded credential controls.
• Assess the alignment of NPE governance with Zero Trust Architecture, workload identity, dynamic access control, and continuous authentication.
• Define compliance requirements for NPE audit logging and monitoring, including SOC and ELICSAR integration and UEBA/AI-driven anomaly detection.
• Guide the JML transformation architecture, attribute sanitization, Microsoft Entra ID integration, event-driven group management, and administrator delegation.
• Review and validate Leaver revocation architecture, covering mailbox handling, DAF365 license reclamation, Entra ID token revocation, and Okta disablement sequencing.
• Assess delegated provisioning in relation to least-privilege, separation-of-duties, and audit-trail requirements.
• Conduct compliance gap analysis across studies and identify necessary controls, waivers, or ATO actions.
• Contribute security and compliance sections along with regulatory mappings to three Technical Study Reports.
• Advise the Program Manager and Study Lead Engineers on emerging cybersecurity policy developments from DoD and DAF.
• Assist in drafting Performance Work Statements for future implementation Task Orders.
• Ensure assigned personnel possess the required security clearances and inform the Government of any status changes.
• Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Systems, or a related field from an accredited institution.
• Over 7 years of experience in cybersecurity, information assurance, or security compliance within Defense or Federal government IT environments.
• Proven experience in interpreting and applying DoD and Federal cybersecurity policy frameworks, including NIST SP 800-53, NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, and related mandates to enterprise IT system design and governance.
• Experience in supporting Authority to Operate (ATO) processes for Defense information systems, including RMF package development, security control assessments, and management of accreditation timelines.
• Active Secret security clearance, with final adjudication required prior to assignment.
• Extensive knowledge of DoD and Federal cybersecurity and identity management policy frameworks.
• Strong comprehension of Zero Trust Architecture principles and their application to enterprise ICAM systems, disconnected edge environments, non-person entity governance, and identity lifecycle management.
• Familiarity with DoD Risk Management Framework (RMF) and Authority to Operate (ATO) processes.
• Knowledge of PKI-based authentication, certificate lifecycle management, DoD/DoW X.509 Certificate Policy, and Common Access Card (CAC) authentication security requirements.
• Experience with Okta and SailPoint IdentityIQ.
• Understanding of DoD audit standards and log management requirements, including CJCSI 6510.01 and SIEM/SOC integration.
• Experience in conducting compliance gap analysis and documenting findings in formal technical reports.
• Ability to interpret and apply complex and conflicting regulatory requirements.
• Experience advising technical engineers and architects on security and compliance necessities.
• Strong technical writing capabilities for compliance assessments, regulatory mappings, technical study reports, and draft Performance Work Statements.
• Ability to collaborate effectively across cross-functional technical teams.
• Excellent written and verbal communication skills in English.
• Capability to obtain and maintain a Secret security clearance.
• Medical, dental, and vision insurance.
• 401(k) retirement plan.
• Paid time off.
• Paid parental leave.
• Life and disability insurance.
• Flexible spending accounts.
• Commuter benefits.
• Tuition reimbursement.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.