> Markdown version of [/jobs/ext/1434404-system-compliance-auditor-ts-sci-26-125](https://www.wearedevelopers.com/jobs/ext/1434404-system-compliance-auditor-ts-sci-26-125). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # System Compliance Auditor (TS/SCI #26-125) - **Company:** Strategic Inc - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $200,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Artificial Intelligence, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Identity and Access Management, Systems Architecture, Trusted Systems, SAPBasis, Servicenow - **Published:** July 25, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9031081/system-compliance-auditor-tssci-26-125 ## About the Role * 7+ years' experience supporting compliance activities to include RMF * Previous experience in SCA, ISSM, ISSO, or ISSE roles * Strong working knowledge of Secure Systems & Cloud/AI/ML Environments and NIST RMF frameworks in advanced R&D portfolios * Experience with GRC/RMF tools such as XACTA, eMASS, or ServiceNow (SNOW) * IAM Level III certification (CISM, CISSP, or GSLC) * Required Certifications: IAM I (CAP, CND, Cloud+, Security+ CE) * Ability to assess vulnerabilities, analyze risk, and document findings clearly · Experience supporting DoD, IC, or SAP environments · Knowledge of FedRAMP and cloud security requirements · Familiarity with STIGs, SRGs, and continuous monitoring practices Travel: Up to 50% travel required during the first year. Clearance · Active TS/SCI w/ CI Poly or willingness to take and pass a CI Poly ## Description · Assess the effectiveness of security controls in accordance with RMF · Perform security reviews to identify gaps in system architecture and design · Conduct risk analysis and develop mitigation recommendations · Execute security authorization reviews and support ATO decisions · Validate security posture of systems, networks, and applications · Monitor and evaluate compliance across information systems · Develop Statements of Risk (SORs) and document security findings · Provide authorization recommendations to the Authorizing Official (AO) ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)