System Compliance Auditor (TS/SCI #26-125)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
· Assess the effectiveness of security controls in accordance with RMF · Perform security reviews to identify gaps in system architecture and design · Conduct risk analysis and develop mitigation recommendations · Execute security authorization reviews and support ATO decisions · Validate security posture of systems, networks, and applications · Monitor and evaluate compliance across information systems · Develop Statements of Risk (SORs) and document security findings · Provide authorization recommendations to the Authorizing Official (AO)
Requirements
-
7+ years’ experience supporting compliance activities to include RMF
- Previous experience in SCA, ISSM, ISSO, or ISSE roles
- Strong working knowledge of Secure Systems & Cloud/AI/ML Environments and NIST RMF frameworks in advanced R&D portfolios
- Experience with GRC/RMF tools such as XACTA, eMASS, or ServiceNow (SNOW)
- IAM Level III certification (CISM, CISSP, or GSLC)
-
Required Certifications: IAM I (CAP, CND, Cloud+, Security+ CE)
- Ability to assess vulnerabilities, analyze risk, and document findings clearly
· Experience supporting DoD, IC, or SAP environments · Knowledge of FedRAMP and cloud security requirements · Familiarity with STIGs, SRGs, and continuous monitoring practices
Travel: Up to 50% travel required during the first year.
Clearance · Active TS/SCI w/ CI Poly or willingness to take and pass a CI Poly
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
The Overflow: Security and Privacy
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship