Demo

IT Security Risk Auditor/Compliance Specialist

Acro
Lexington, MA Full Time
POSTED ON 1/16/2025
AVAILABLE BEFORE 4/15/2025

Must be a US Citizen.

The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies : Security Technical Implementation Guides (STIGs), NIST 800-53 / Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0.

The IT Security Risk Auditor is responsible for maintaining and auditing programs to validate compliance with various government regulations and Laboratory Information Security policies. The position is responsible for conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls (i.e. the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome) with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system and for the ability to conduct open source and internal research to identify current threat indicators, exploits, and vulnerabilities.

Requirements :

Bachelor's degree in Computer Science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years' experience conducting risk assessments.

Experience in compliance auditing, security reviews, or vulnerability assessments.

Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience.

Candidate must possess an in-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800-171 and Security Technical Implementation Guides (STIGs).

The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR / DFARS Safeguarding CUI series (252.204-7012, etc.), computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF) and NIST SP 800-171.

Working experience directly related to Assessment and Authorization using any of the following :

o NIST 800-53 / Risk Management Framework (RMF)

o Joint Special Access Program (SAP) Implementation Guide

o NIST SP 800-171 Understanding of CMMC Framework

o National Industrial Security Program Operating Manual (NISPOM) Chapter 8

Preferred :

Information Assurance Certifications preferred (CISSP / CISA, Security , CCP / CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a IT Security Risk Auditor/Compliance Specialist?

Sign up to receive alerts about other jobs on the IT Security Risk Auditor/Compliance Specialist career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Acro

Acro
Hired Organization Address Boise, ID Full Time
Job title : Data Migration Field Support Technician Duration : 12 Months Location : Boise, ID 83702, USA Pay rate : $30 ...
Acro
Hired Organization Address Bowling Green, KY Temporary
Data Coordinator Location : Bowling Green - KY ( Onsite ) 12 Months Contract Job Description Assist in organizing and ex...
Acro
Hired Organization Address Phoenix, AZ Full Time
Qualifications : Must have vulnerability remediation experience in a Microsoft Windows environment and work with vendors...
Acro
Hired Organization Address Baton Rouge, LA Full Time
Seeks resources to provide maintenance and operational support for its SAP Enterprise Resource Planning (ERP) system. Fu...

Not the job you're looking for? Here are some other IT Security Risk Auditor/Compliance Specialist jobs in the Lexington, MA area that may be a better fit.

IT Security RIsk Auditor

Top Secret Clearance Jobs, Lexington, MA

AI Assistant is available now!

Feel free to start your new journey!