> Markdown version of [/jobs/ext/3363832-it-compliance-manager](https://www.wearedevelopers.com/jobs/ext/3363832-it-compliance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Compliance Manager - **Company:** Mantech International Corporation - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Software Documentation, Cyber Security, Information Systems, Information Technology Audit, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Information Technology, Plan of Action and Milestones - **Published:** September 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ae3607a1d3fd7601 ## About the Role * Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Business Management, or a related discipline, or equivalent work experience. * 5+ years of progressive experience in cybersecurity compliance, IT auditing, or Risk Management Framework (RMF) execution. * Demonstrated experience conducting deep-dive FISMA reviews and evaluating compliance against NIST SP 800-53, NIST SP 800-53A, and federal cybersecurity standards. * Possess at least one of the following DoD 8140.03 Intermediate proficiency certifications: CCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, or GSNA. * Proven experience reviewing enterprise security documentation, preparing audit response packages, and managing POA&M lifecycles. * Strong technical writing skills with experience developing defensible compliance justifications for federal auditors. Clearance Requirements: * An active Top Secret clearance with SCI eligibility is required. Preferred Qualifications: * Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Security Professional (CISSP) certification. * Experience supporting Department of Justice (DOJ) or Federal Bureau of Investigation (FBI) FISMA audits, Inspector General (IG) reviews, or OMB Circular A-123 assessments. * Familiarity with government Governance, Risk, and Compliance (GRC) tools such as Joint Cybersecurity Authorization Management (JCAM) or Telos Xacta. * Demonstrated track record of resolving pre-audit findings and achieving minimal or zero audit findings. Physical Requirements: * Must be able to remain in a stationary position 50% of the time. * Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. * Frequently communicates with co-workers, management, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations. ## Description * Serving as a dedicated IT Compliance Manager exclusively assigned to conduct deep-dive audit readiness assessments and FISMA compliance quality reviews for assigned information systems. * Evaluating system documentation, technical security controls, access controls, and Plan of Action and Milestones (POA&M) tracking against FISMA, NIST SP 800-53, and FBI policy standards. * Conducting deep-dive reviews of enterprise-level FISMA artifacts, including security plans, risk assessments, and contingency plans, to ensure control mapping accuracy and completeness. * Preparing defensible, audit-ready response packages, compliance statements, and supporting evidence to minimize findings during federal audit engagements. * Communicating identified gaps, weaknesses, and remediation progress directly to Enterprise Cybersecurity Section leadership. * Developing and tracking corrective action plans and POA&Ms to ensure pre-audit findings are resolved within required timelines. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) ## Related Articles - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)