> Markdown version of [/jobs/ext/1424605-security-and-compliance-engineer-it-cmmc-nist-sp-800-171](https://www.wearedevelopers.com/jobs/ext/1424605-security-and-compliance-engineer-it-cmmc-nist-sp-800-171). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security and Compliance Engineer, IT - CMMC/NIST SP 800-171 - **Company:** The Technical - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $110,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Multitier Architecture, Wireless LAN, Active Directory, Apple Mac Systems, Cyber Security, Information Systems, System Configuration, Information Leak Prevention, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Hyper-V, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Network Security, Microsoft Office, Windows Servers, Networking Basics, Network Diagrams, Network Segmentation, PCI Data Security Standards, Remote Access Technology, Security Information and Event Management, TCP/IP, Virtualization Technology, Data Logging, Network Routers, Cloud Platform System, Computer Network Technologies, Sonicwall, Malware, Firewalls (Computer Science), Falcon Platform, Information Technology, SolarWinds (Software), CIS Benchmarks, Splunk, Cisco, Vulnerability Analysis, Vmware - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e18c93c757596ec1 ## About the Role * Experience with network/cyber security engineering: design, implementation, optimization, monitoring, and troubleshooting of LAN, WAN, WLAN, and DR networks; * Demonstrated best practice usage of security technologies and policy administration: Firewalls, IDS/IPS, DLP, Proxy, Endpoint, Vulnerability scanning and management, SIEM / logging, security groups, and network segmentation, system hardening, incident response, and malware/virus prevention; * Experience with network security technologies including Rapid Fire, SolarWinds, Sophos, BlueCoat, SonicWALL, Cisco, CrowdStrike, and Splunk; * Documenting security controls, monitoring, and alerting around these controls; * Clear understanding of virtualization technologies such as VMWare and Hyper-V; * Knowledge of multi-tier application architecture on infrastructure and cloud environments; * Demonstrated skill securing sensitive data in production environments; * Self-starter with a strong work ethic willing to identify issues and lead them to conclusion; * Ability to see the big picture and present ideas clearly with demonstrated thought leadership to clients; * Capable of meeting with clients to discuss cyber security solutions and recommendations., * Bachelor's degree preferable in Information Technology or other engineering or technical discipline; PLUS * 6-8 years IT experience and minimum 4 years Cyber Security Information experience; * One or more Industry security certifications REQUIRED, Certified Information Systems Security Professional (CISSP), CISA Certified Information Systems Auditor (CISA), CISM Certified Information Security Manager (CISM), ISSAP Information Systems Security Architecture Professional (ISSAP), ISSEP Information Systems Security Engineering Professional (ISSEP); (OR equivalent) * Experience with modern operating systems including Windows 10/11 and Server 2016/2019, macOS, and Linux; * In-depth understanding of NIST SP 800-171, CIS Controls, and/or other security compliance frameworks; * Experience in developing organization security policies and implementation of revised policies; * Experience with endpoint security solutions, including file integrity monitoring and data loss prevention. Personal Attributes * Excellent analytical and problem-solving skills; * Ability to work independently on multiple projects; * Collaborates and assumes a technical leadership role when required; * Ability to mentor coworkers on network security best practices; * Ability to explain network concepts to both fellow technical staff and clients; * Is effective in prioritizing tasks within a high-pressure competing environment; * Highly self-motivated and directed, with keen attention to detail; * Demonstrates excellent oral and written communication skills, fluency in English language; * Demonstrates an interest in working hard in a fast-paced environment; * Excels in customer-facing environments and enjoys challenges; * Strong organizational skills; Minimum Technical Requirements * Knowledge of current networking technologies; * Strong knowledge of configuring and troubleshooting modern operating systems; * Knowledge of Microsoft Office/ Office 365; * Knowledge of TCP/IP, DNS, DHCP, and Active Directory; * Knowledge of LAN/WAN technologies; * Understanding of firewalls, routers, and VPN/remote access solutions; * Demonstrated experience with IT Security and Compliance; * Knowledge of installing and configuring Windows Servers 2008-2012 a PLUS; * MAC and LINUX experience a PLUS., * The essential job duties include writing technical documents in the English language with business proficiency and fluency. Do you meet these requirements? Education: * Bachelor's (Required) Experience: * Cybersecurity: 6 years (Required) * CMMC: 5 years (Required) * NIST 800-171: 5 years (Required) Language: * English (Required) License/Certification: * CISSP (Preferred) ## Description The Security and Compliance Engineer will be a key member within the security division and possess a comprehensive skill set in network security operations, cyber security tools, intrusion detection, and secured networks. This role will work to improve clients' security posture. This position will write security assessments as well as develop policies to address problems and security emergencies and make recommendations to clients. This position requires analyzing the environment, coordinating data gathering, and generating solutions on a day-to-day basis, and assisting with projects and investigations related to threat management and security breaches for clients. Primary Responsibilities * Consult and participate in day-to-day security operational activities with clients; * Confirm and document client vulnerability and security risks and develop mitigation plans; * Monitor and validate client security controls; * Respond to security alerts, incidents, and issues; * Ensure security controls meet multiple compliance needs and best practices; * Conduct, write, and present client Security and Risk Assessments using recognized frameworks (NIST SP 800-171 and PCI DSS v3.2 or other security compliance frameworks); * Create accurate network diagrams and documentation for planning security-based changes, investigating network impact, and issuing resolution procedures; * Coordinates and tracks security awareness training to the organizational workforce on information security standards, policies, and best practices; * Consistently review relevant Cyber Security Compliances to educate clients on revisions and changes in requirements; * Assist in investigating security breaches by leading the incident response to minimize impact, determine the cause of the breach, and ascertain the extent of the damage; * Travel as needed for on-site assessments and meetings at client locations; limited and infrequent. * Other duties as necessary and required. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)