Search Remote Jobs

Cybersecurity Compliance Specialist

đź•’ August 20

🇺🇸 United States – Remote

⏰ Full Time

🟡 Mid-level

đźź  Senior

👮‍♂️ Cybersecurity / Security Engineer

đź‘» Ghost score 34%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Lucayan Technology Solutions LLC

Lucayan Technology Solutions LLC

51 - 200 employees

Founded 2015

đź’Ľ Consulting

📦 Logistics

🎖️ Defense

Consulting • Logistics • Defense

Lucayan Technology Solutions LLC is a CVE-certified, veteran-owned small business that provides integrated information technology and staffing services to U. S. government agencies (including Department of Defense) and commercial clients. The firm delivers cloud (AWS IaaS/SaaS) migrations, network and converged infrastructure (SDN, NFV, VMware), consolidated help desk/support, and cybersecurity solutions, and holds multiple federal contract vehicles (GSA, STARS III, SeaPort-NxG, 8(a), HubZone, SDVOSB). Lucayan emphasizes mission-driven, agile engineering with Cisco, VMware, and Microsoft certified staff to support classified and unclassified mission-critical initiatives.

đź“‹ Description

• Develop, update, and maintain WWBI Risk Management Framework authorization documentation, including the SSP, COOP, IRP, System Design Documents, and related authorization artifacts • Manage and document program-specific security controls and requirements associated with PII • Maintain documentation defining the WWBI authorization boundary, including hardware, software, ports, protocols, interfaces, and data flows • Coordinate cybersecurity documentation and compliance activities for WWBI's migration into the CWBI Cloud and eventual incorporation into the CWBI authorization boundary • Maintain WWBI compliance records in eMASS, including RMF documentation, security-control evidence, implementation statements, and supporting artifacts • Support the continuous-monitoring program, including coordinating or performing ACAS and SCAP security scans • Maintain a compliance score of at least 90% for applicable SCAP scans • Import and maintain security-scan results in DISA STIG Viewer and eMASS • Analyze vulnerabilities and coordinate remediation with software developers and Government technical personnel • Track Critical, High, Moderate, and Low findings according to required remediation timelines • Document exceptions and outstanding findings in the POA&M • Develop, maintain, and submit quarterly POA&M reports • Support quarterly updates to the RMF documentation package • Provide ACAS/SCAP scan results and STIG Viewer files following required scans • Maintain current system security, network topology, logical, and data-flow documentation with the development team • Complete and maintain security-control checklists required by the USACE CWBI Cloud environment • Monitor CWBI cybersecurity requirement changes and coordinate implementation of new or modified requirements • Support annual FISMA reporting requirements and associated documentation • Support compliance with DoD STIGs, Army cybersecurity requirements, and USACE policies during modernization and cloud-migration activities • Work closely with software developers, DevSecOps personnel, technical leadership, and Government stakeholders to maintain continuous compliance

🎯 Requirements

• U.S. Citizenship required • Demonstrated experience supporting the DoD Risk Management Framework (RMF), including developing and maintaining RMF authorization packages and cybersecurity documentation • Experience using Enterprise Mission Assurance Support Service (eMASS) • Knowledge of DoD, U.S. Army, and/or USACE cybersecurity requirements and processes • Experience with vulnerability management, security controls, POA&Ms, and continuous monitoring • Experience with ACAS, SCAP, DISA STIGs, and STIG Viewer • Ability to interpret technical vulnerability findings and coordinate remediation with software-development and infrastructure teams • Strong technical writing, documentation, and organizational skills • Ability to manage multiple recurring compliance requirements and deadlines • Ability to communicate effectively with technical personnel, program leadership, and Government stakeholders • Active federal background investigation at the Tier 1 level or higher prior to beginning contract performance • Ability to obtain and maintain CompTIA Security+ or a DoD-approved equivalent within six months of contract start, as applicable to the assigned DoD 8140 work role • Previous USACE systems or applications experience preferred • DoD ATO authorization and continuous-monitoring experience preferred • AWS GovCloud or other DoD-authorized cloud-environment experience preferred • Familiarity with DevSecOps, GitHub, secure software-development pipelines, and application modernization preferred • Cloud-migration experience for systems operating under an existing RMF authorization preferred • FISMA reporting experience preferred • CISSP or another advanced DoD-recognized cybersecurity certification desired

🏖️ Benefits

• Remote work arrangement • Full-time employment • Opportunity to support national defense and intelligence missions • Career-building opportunities • Security+ or DoD 8140-approved equivalent certification support/eligibility within six months, as applicable • Opportunity to obtain a CAC if required by duties

Apply Now

Similar Jobs

đź•’ August 19

Corteva Agriscience

10,000+ employees

🍽️ Food & Beverage

đź’Ľ Consulting

🏥 Healthcare

Email Security Engineer securing Corteva’s Exchange, email authentication, and messaging infrastructure. Supporting reliable, compliant communications for the global agriscience company.

đź•’ August 19

Corteva Agriscience

10,000+ employees

🍽️ Food & Beverage

đź’Ľ Consulting

🏥 Healthcare

Email Security Engineer architecting and securing Corteva’s Exchange, Microsoft 365, and enterprise messaging infrastructure. Supporting mail flow, authentication, incident response, and compliance for a global agriscience company.

đź•’ August 19

Baker Tilly US

5001 - 10000

🏗️ Construction

🏥 Healthcare

📦 Logistics

PCI-focused IT risk consultant conducting audits, cybersecurity assessments, and control reviews for Baker Tilly advisory clients. Developing recommendations, reports, and client relationships.

đź•’ August 19

FastSpring

51 - 200

đź’Ľ Consulting

📦 Logistics

📣 Marketing

Sr. Security Engineer securing FastSpring’s global payments platform and AWS infrastructure. Shaping application security practices for AI-assisted software development.

đź•’ August 19

Avertium

201 - 500

đź”’ Cybersecurity

🏢 Enterprise

Senior LogRhythm Engineer/Architect securing customer information and administering dedicated SIEM systems. Building and optimizing cloud-based LogRhythm deployments for Avertium’s enterprise security customers.