Security and Compliance Engineer, IT - CMMC/NIST SP 800-171

The Technical
United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$110,000.0 - $130,000.0
Working hours
Shift work
Languages
English
Job source

Tech stack

Multitier Architecture Wireless LAN Active Directory Apple Mac Systems Cyber Security Information Systems System Configuration Information Leak Prevention Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Hyper-V
+31 more
Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Information Systems Security Architecture Professional Information Systems Security Engineering Professional Network Security Microsoft Office Windows Servers Networking Basics Network Diagrams Network Segmentation PCI Data Security Standards Remote Access Technology Security Information and Event Management TCP/IP Virtualization Technology Data Logging Network Routers Cloud Platform System Computer Network Technologies Sonicwall Malware Firewalls (Computer Science) Falcon Platform Information Technology SolarWinds (Software) CIS Benchmarks Splunk Cisco Vulnerability Analysis Vmware

Job description

The Security and Compliance Engineer will be a key member within the security division and possess a comprehensive skill set in network security operations, cyber security tools, intrusion detection, and secured networks. This role will work to improve clients’ security posture.

This position will write security assessments as well as develop policies to address problems and security emergencies and make recommendations to clients. This position requires analyzing the environment, coordinating data gathering, and generating solutions on a day-to-day basis, and assisting with projects and investigations related to threat management and security breaches for clients.

Primary Responsibilities

  • Consult and participate in day-to-day security operational activities with clients;
  • Confirm and document client vulnerability and security risks and develop mitigation plans;
  • Monitor and validate client security controls;
  • Respond to security alerts, incidents, and issues;
  • Ensure security controls meet multiple compliance needs and best practices;
  • Conduct, write, and present client Security and Risk Assessments using recognized frameworks (NIST SP 800-171 and PCI DSS v3.2 or other security compliance frameworks);
  • Create accurate network diagrams and documentation for planning security-based changes, investigating network impact, and issuing resolution procedures;
  • Coordinates and tracks security awareness training to the organizational workforce on information security standards, policies, and best practices;
  • Consistently review relevant Cyber Security Compliances to educate clients on revisions and changes in requirements;
  • Assist in investigating security breaches by leading the incident response to minimize impact, determine the cause of the breach, and ascertain the extent of the damage;
  • Travel as needed for on-site assessments and meetings at client locations; limited and infrequent.
  • Other duties as necessary and required.

Requirements

  • Experience with network/cyber security engineering: design, implementation, optimization, monitoring, and troubleshooting of LAN, WAN, WLAN, and DR networks;
  • Demonstrated best practice usage of security technologies and policy administration: Firewalls, IDS/IPS, DLP, Proxy, Endpoint, Vulnerability scanning and management, SIEM / logging, security groups, and network segmentation, system hardening, incident response, and malware/virus prevention;
  • Experience with network security technologies including Rapid Fire, SolarWinds, Sophos, BlueCoat, SonicWALL, Cisco, CrowdStrike, and Splunk;
  • Documenting security controls, monitoring, and alerting around these controls;
  • Clear understanding of virtualization technologies such as VMWare and Hyper-V;
  • Knowledge of multi-tier application architecture on infrastructure and cloud environments;
  • Demonstrated skill securing sensitive data in production environments;
  • Self-starter with a strong work ethic willing to identify issues and lead them to conclusion;
  • Ability to see the big picture and present ideas clearly with demonstrated thought leadership to clients;
  • Capable of meeting with clients to discuss cyber security solutions and recommendations., * Bachelor’s degree preferable in Information Technology or other engineering or technical discipline; PLUS
  • 6-8 years IT experience and minimum 4 years Cyber Security Information experience;
  • One or more Industry security certifications REQUIRED, Certified Information Systems Security Professional (CISSP), CISA Certified Information Systems Auditor (CISA), CISM Certified Information Security Manager (CISM), ISSAP Information Systems Security Architecture Professional (ISSAP), ISSEP Information Systems Security Engineering Professional (ISSEP); (OR equivalent)
  • Experience with modern operating systems including Windows 10/11 and Server 2016/2019, macOS, and Linux;
  • In-depth understanding of NIST SP 800-171, CIS Controls, and/or other security compliance frameworks;
  • Experience in developing organization security policies and implementation of revised policies;
  • Experience with endpoint security solutions, including file integrity monitoring and data loss prevention.

Personal Attributes

  • Excellent analytical and problem-solving skills;
  • Ability to work independently on multiple projects;
  • Collaborates and assumes a technical leadership role when required;
  • Ability to mentor coworkers on network security best practices;
  • Ability to explain network concepts to both fellow technical staff and clients;
  • Is effective in prioritizing tasks within a high-pressure competing environment;
  • Highly self-motivated and directed, with keen attention to detail;
  • Demonstrates excellent oral and written communication skills, fluency in English language;
  • Demonstrates an interest in working hard in a fast-paced environment;
  • Excels in customer-facing environments and enjoys challenges;
  • Strong organizational skills;

Minimum Technical Requirements

  • Knowledge of current networking technologies;
  • Strong knowledge of configuring and troubleshooting modern operating systems;
  • Knowledge of Microsoft Office/ Office 365;
  • Knowledge of TCP/IP, DNS, DHCP, and Active Directory;
  • Knowledge of LAN/WAN technologies;
  • Understanding of firewalls, routers, and VPN/remote access solutions;
  • Demonstrated experience with IT Security and Compliance;
  • Knowledge of installing and configuring Windows Servers 2008-2012 a PLUS;
  • MAC and LINUX experience a PLUS., * The essential job duties include writing technical documents in the English language with business proficiency and fluency. Do you meet these requirements?

Education:

  • Bachelor’s (Required)

Experience:

  • Cybersecurity: 6 years (Required)
  • CMMC: 5 years (Required)
  • NIST 800-171: 5 years (Required)

Language:

  • English (Required)

License/Certification:

  • CISSP (Preferred)

Benefits & conditions

5.05.0 out of 5 stars Remote $110,000 - $130,000 a year - Full-time, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Flexible spending account
  • Health insurance
  • Life insurance
  • Paid time off
  • Vision insurance

Compensation Package:

  • Base pay;
  • Profit sharing (discretionary)

Schedule:

  • 8 hour shift

Work Location: Remote

We are located in MA with clients throughout the US. Qualified candidates will be reviewed and scheduled for initial interview with Human Resources.

REQUIRED: Applicants living in the US, near Massachusetts, NE, or nearby Northeast, EST only.

Job Type: Full-time

Pay: $110,000.00 - $130,000.00 per year, * 401(k)

  • 401(k) matching
  • Dental insurance
  • Flexible spending account
  • Health insurance
  • Life insurance
  • Paid time off
  • Retirement plan

About the company

We are a provider of outsourced IT and cyber security services for small and medium-sized businesses in New England offering of remote support, field support, managed and security services (MSP/MSSP) as well as project management for our clients.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all