> Markdown version of [/jobs/ext/2675755-it-compliance-manager](https://www.wearedevelopers.com/jobs/ext/2675755-it-compliance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Compliance Manager - **Company:** Mantech International Corporation - **Location:** Quantico, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Software Documentation, Cyber Security, Information Systems, Information Technology Audit, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Information Technology, Plan of Action and Milestones - **Published:** September 1, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9131488/it-compliance-manager ## About the Role * Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Business Management, or a related discipline, or equivalent work experience. * Minimum of 5 years of progressive experience in cybersecurity compliance, IT auditing, or Risk Management Framework (RMF) execution. * Demonstrated experience conducting deep-dive FISMA reviews and evaluating compliance against NIST SP 800-53, NIST SP 800-53A, and federal cybersecurity standards. * Possess at least one of the following DoD 8140.03 Intermediate proficiency certifications: CCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, or GSNA. * Proven experience reviewing enterprise security documentation, preparing audit response packages, and managing POA&M lifecycles. * Strong technical writing skills with experience developing defensible compliance justifications for federal auditors. Clearance Requirements: * An active Top Secret clearance with SCI eligibility is required. Preferred Qualifications: * Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Security Professional (CISSP) certification. * Experience supporting Department of Justice (DOJ) or Federal Bureau of Investigation (FBI) FISMA audits, Inspector General (IG) reviews, or OMB Circular A-123 assessments. * Familiarity with government Governance, Risk, and Compliance (GRC) tools such as Joint Cybersecurity Authorization Management (JCAM) or Telos Xacta. * Demonstrated track record of resolving pre-audit findings and achieving minimal or zero audit findings. Physical Requirements: * Must be able to remain in a stationary position 50% of the time. * Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. * Frequently communicates with co-workers, management, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations. ## Description MANTECH seeks a motivated, career and customer-oriented IT Compliance Manager to join our team in Washington, D.C. This is an onsite position. The IT Compliance Manager will leverage their technical background and compliance expertise to support the Federal Bureau of Investigation (FBI) Enterprise Cybersecurity Section (ECS) with audit preparation and quality reviews for FISMA compliance. You will help conduct deep-dive readiness assessments, evaluate enterprise security artifacts, and ensure system audit readiness across the enterprise. Responsibilities include but are not limited to: * Serving as a dedicated IT Compliance Manager exclusively assigned to conduct deep-dive audit readiness assessments and FISMA compliance quality reviews for assigned information systems. * Evaluating system documentation, technical security controls, access controls, and Plan of Action and Milestones (POA&M) tracking against FISMA, NIST SP 800-53, and FBI policy standards. * Conducting deep-dive reviews of enterprise-level FISMA artifacts, including security plans, risk assessments, and contingency plans, to ensure control mapping accuracy and completeness. * Preparing defensible, audit-ready response packages, compliance statements, and supporting evidence to minimize findings during federal audit engagements. * Communicating identified gaps, weaknesses, and remediation progress directly to Enterprise Cybersecurity Section leadership. * Developing and tracking corrective action plans and POA&Ms to ensure pre-audit findings are resolved within required timelines. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)