RESPONSIBILITIES
Compliance program operation
- Track all 110 NIST SP 800-171 requirements across the 14 control families; keep the SPRS score current and defensible.
- Maintain the SSP, POA&M, and supporting documents: policies, procedures, data flow diagrams, asset inventories.
- Run internal 800-171A and gap assessments; propose remediation owners and dates; track findings to closure.
- Verify controls technically: run 800-171A objectives as tests against the systems (MFA enforcement, session lock, audit retention, encryption), not as document review.
- Keep an audit-ready evidence repository mapped to controls that an assessor can follow without coaching; build repeatable collection with scripts, saved queries, and scheduled exports.
- Prepare the annual Affirming Official affirmation package; support DFARS 7012, DIBCAC, and CMMC Level 2 assessments.
Risk management
- Maintain the security risk register; translate technical findings into likelihood, impact, and options leadership can act on.
- Fold CISA and DoD threat advisories into the risk picture.
- Flag boundary changes (new CUI contract, new system, enclave change); draft risk acceptances for sign-off.
Legal and contract liaison
- Review contracts and flowdowns for CUI, ITAR, NNPI, and cybersecurity obligations; define the controls and evidence needed.
- Act as point of contact for Legal and Contracts: answer can we truthfully attest to this? with control status and evidence.
- Coordinate supplier security reviews where CUI or export-controlled data flows down; track flowdown compliance.
- Escalate any gap that creates legal or contractual exposure to the Cybersecurity Manager and Legal, in writing.
- Support voluntary disclosure and incident reporting with timeline reconstruction, evidence collection, and documentation.
Policy, training, monitoring, and reporting
- Write and maintain policies, SOPs, and control narratives in SRC house style; update on DoD, DFARS, or NIST changes and record why.
- Deliver security awareness and role-based training; track completion across the workforce.
- Triage SIEM alerts for the CUI enclave, tune noisy rules, compare deployed configurations to CIS or STIG baselines, and open remediation items.
- Administer the vulnerability scanner, SIEM rule content, and the GRC and evidence tooling.
- Support incident response evidence and timelines, including DFARS 7012 reporting to DoD when CUI is involved.
- Report control status, open risks, and remediation progress on a set cadence; produce readiness summaries on request.
QUALIFICATIONS
Required
- 3 to 5 years in cybersecurity, with a background in systems administration, security operations, or security engineering before or alongside compliance work.
- Working knowledge of NIST SP 800-171 and DFARS 252.204-7012.
- Built or maintained an SSP and POA&M; maps controls to evidence.
- Can pull the configuration, log, or report that proves a control is implemented in Entra ID, Intune, Windows, and firewalls, and explain what it shows.
- Basic PowerShell or Python for exporting evidence (MFA status, patch compliance, account inventories) rather than assembling screenshots by hand.
- Working knowledge of Windows and Microsoft 365 administration, Active Directory and Entra ID, and network fundamentals: VLANs, firewall rules, remote access.
- Strong policy writing; explains controls to non-technical owners.
- Bachelor's in cybersecurity or IT, or equivalent experience.
- U.S. Person status under ITAR (22 CFR 120.62), given access to export-controlled technical data. Preferred
- Prior help desk, systems administration, or SOC time.
- Azure Government or GCC High administration; Palo Alto or equivalent firewall exposure; STIG or CIS benchmark work.
- Exposure to CMMC Level 2 readiness, SPRS scoring, or a prior C3PAO or DIBCAC assessment.
- Experience with Legal or Contracts on clause interpretation, flowdown, or disclosure obligations.
- Experience with a manufacturing environment and operational technology (OT).
- Familiarity with ITAR and NNPI handling requirements.
- Hands-on time with a GRC or compliance tracking tool, and with Jira or Jira Service Management.
- Security+, CySA+, SC-200, AZ-500 or SC-300, CISSP.