Job Requirements
Arlington, VA
Secret Polygraph not specified
Career Level not specified
$136,000 - $173,000
Job Description
Cybersecurity & Compliance Specialist
Overview
Join a small, highly collaborative cybersecurity team responsible for protecting a High Value Asset (HVA) supporting critical U.S. Government operations. This role focuses on Governance, Risk, and Compliance (GRC), ensuring the system maintains compliance with federal cybersecurity requirements, agency policies, and established security frameworks. The selected candidate will work closely with government stakeholders, system owners, engineers, security teams, and external partners to support authorization activities, audits, continuous monitoring, and overall cybersecurity governance.
This position is ideal for a cybersecurity professional with strong experience supporting Risk Management Framework (RMF), Assessment & Authorization (A&A), Authority to Operate (ATO) activities, and NIST-based compliance initiatives.
Key Responsibilities
Support governance, risk, and compliance activities for a mission-critical federal information system.
Coordinate cybersecurity efforts between program stakeholders, system owners, security teams, and partner organizations.
Assist with maintaining and renewing system authorization packages and supporting Authority to Operate (ATO) requirements.
Lead and support Assessment & Authorization (A&A) activities throughout the system lifecycle.
Develop, review, and maintain cybersecurity documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), policies, procedures, and supporting artifacts.
Evaluate and document implementation of NIST security controls and ensure continued compliance with federal cybersecurity requirements.
Support audits, inspections, data calls, and cybersecurity taskings from government oversight organizations.
Coordinate and manage Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), and other security-related documentation.
Conduct risk assessments and provide recommendations for mitigating identified security risks.
Monitor security control effectiveness and support Information System Continuous Monitoring (ISCM) activities.
Track remediation efforts, vulnerabilities, findings, and compliance initiatives across the environment.
Partner with technical teams to ensure security requirements are integrated into operational processes and system changes.
Prepare reports, briefings, and status updates for leadership and stakeholders regarding cybersecurity posture and compliance status.
Ensure compliance with applicable federal regulations, agency directives, and cybersecurity standards.
Required Qualifications
Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
3+ years of experience supporting cybersecurity, information assurance, compliance, or RMF-related programs.
Demonstrated experience supporting multiple phases of Information Assurance (IA), cybersecurity accreditation, or Assessment & Authorization (A&A) activities.
Experience managing and maintaining Authority to Operate (ATO) packages for federal information systems.
Strong understanding of the Risk Management Framework (RMF) and associated authorization processes.
In-depth knowledge of NIST SP 800-53 Rev. 4 and Rev. 5 security controls.
Experience assessing, documenting, and validating security control implementations.
Knowledge of continuous monitoring requirements and Information System Continuous Monitoring (ISCM) processes.
Experience performing risk assessments and developing remediation strategies.
Familiarity with security documentation including SSPs, POA&Ms, SARs, and related artifacts.
Ability to work independently with minimal supervision while managing multiple priorities.
Excellent verbal, written, and interpersonal communication skills.
Strong analytical and problem-solving abilities.
Preferred Qualifications
CISSP, Security+, CISM, CAP, or similar cybersecurity certification.
Experience supporting High Value Assets (HVAs) within federal environments.
Experience working within complex multi-stakeholder government environments.
Familiarity with eMASS, Xacta, ServiceNow GRC, or similar compliance management platforms.
Experience developing and managing MOUs and Interconnection Security Agreements (ISAs).
Knowledge of FISMA, NIST 800-37, and other federal cybersecurity regulations.
Experience supporting federal audits, inspections, and compliance reviews.
Understanding of encryption technologies and data-at-rest protection requirements.
Knowledge of cloud security compliance frameworks and authorization processes.
Technical Knowledge Areas
Risk Management Framework (RMF)
Assessment & Authorization (A&A)
Authority to Operate (ATO)
NIST SP 800-53 Rev. 4 & Rev. 5
Continuous Monitoring (ISCM)
Security Controls Assessment
Security Documentation Development
Governance, Risk & Compliance (GRC)
Information Assurance (IA)
FISMA Compliance
Risk Assessment & Mitigation
MOUs and ISAs
Vulnerability Management
Audit Readiness & Compliance Reporting
Ideal Candidate Profile
The ideal candidate is a cybersecurity compliance professional who thrives in a collaborative environment and can effectively bridge technical and compliance requirements. They possess hands-on experience navigating federal authorization processes, coordinating across multiple organizations, and maintaining the security posture of critical government systems. Success in this role requires attention to detail, strong communication skills, and the ability to proactively manage cybersecurity and compliance initiatives in support of mission objectives.
Overview
Join a small, highly collaborative cybersecurity team responsible for protecting a High Value Asset (HVA) supporting critical U.S. Government operations. This role focuses on Governance, Risk, and Compliance (GRC), ensuring the system maintains compliance with federal cybersecurity requirements, agency policies, and established security frameworks. The selected candidate will work closely with government stakeholders, system owners, engineers, security teams, and external partners to support authorization activities, audits, continuous monitoring, and overall cybersecurity governance.
This position is ideal for a cybersecurity professional with strong experience supporting Risk Management Framework (RMF), Assessment & Authorization (A&A), Authority to Operate (ATO) activities, and NIST-based compliance initiatives.
Key Responsibilities
Support governance, risk, and compliance activities for a mission-critical federal information system.
Coordinate cybersecurity efforts between program stakeholders, system owners, security teams, and partner organizations.
Assist with maintaining and renewing system authorization packages and supporting Authority to Operate (ATO) requirements.
Lead and support Assessment & Authorization (A&A) activities throughout the system lifecycle.
Develop, review, and maintain cybersecurity documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), policies, procedures, and supporting artifacts.
Evaluate and document implementation of NIST security controls and ensure continued compliance with federal cybersecurity requirements.
Support audits, inspections, data calls, and cybersecurity taskings from government oversight organizations.
Coordinate and manage Memorandums of Understanding (MOUs), Interconnection Security Agreements (ISAs), and other security-related documentation.
Conduct risk assessments and provide recommendations for mitigating identified security risks.
Monitor security control effectiveness and support Information System Continuous Monitoring (ISCM) activities.
Track remediation efforts, vulnerabilities, findings, and compliance initiatives across the environment.
Partner with technical teams to ensure security requirements are integrated into operational processes and system changes.
Prepare reports, briefings, and status updates for leadership and stakeholders regarding cybersecurity posture and compliance status.
Ensure compliance with applicable federal regulations, agency directives, and cybersecurity standards.
Required Qualifications
Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
3+ years of experience supporting cybersecurity, information assurance, compliance, or RMF-related programs.
Demonstrated experience supporting multiple phases of Information Assurance (IA), cybersecurity accreditation, or Assessment & Authorization (A&A) activities.
Experience managing and maintaining Authority to Operate (ATO) packages for federal information systems.
Strong understanding of the Risk Management Framework (RMF) and associated authorization processes.
In-depth knowledge of NIST SP 800-53 Rev. 4 and Rev. 5 security controls.
Experience assessing, documenting, and validating security control implementations.
Knowledge of continuous monitoring requirements and Information System Continuous Monitoring (ISCM) processes.
Experience performing risk assessments and developing remediation strategies.
Familiarity with security documentation including SSPs, POA&Ms, SARs, and related artifacts.
Ability to work independently with minimal supervision while managing multiple priorities.
Excellent verbal, written, and interpersonal communication skills.
Strong analytical and problem-solving abilities.
Preferred Qualifications
CISSP, Security+, CISM, CAP, or similar cybersecurity certification.
Experience supporting High Value Assets (HVAs) within federal environments.
Experience working within complex multi-stakeholder government environments.
Familiarity with eMASS, Xacta, ServiceNow GRC, or similar compliance management platforms.
Experience developing and managing MOUs and Interconnection Security Agreements (ISAs).
Knowledge of FISMA, NIST 800-37, and other federal cybersecurity regulations.
Experience supporting federal audits, inspections, and compliance reviews.
Understanding of encryption technologies and data-at-rest protection requirements.
Knowledge of cloud security compliance frameworks and authorization processes.
Technical Knowledge Areas
Risk Management Framework (RMF)
Assessment & Authorization (A&A)
Authority to Operate (ATO)
NIST SP 800-53 Rev. 4 & Rev. 5
Continuous Monitoring (ISCM)
Security Controls Assessment
Security Documentation Development
Governance, Risk & Compliance (GRC)
Information Assurance (IA)
FISMA Compliance
Risk Assessment & Mitigation
MOUs and ISAs
Vulnerability Management
Audit Readiness & Compliance Reporting
Ideal Candidate Profile
The ideal candidate is a cybersecurity compliance professional who thrives in a collaborative environment and can effectively bridge technical and compliance requirements. They possess hands-on experience navigating federal authorization processes, coordinating across multiple organizations, and maintaining the security posture of critical government systems. Success in this role requires attention to detail, strong communication skills, and the ability to proactively manage cybersecurity and compliance initiatives in support of mission objectives.
group id: kforcecx
We offer roles across all three clearance levels: Confidential, Secret and Top Secret. With a Top Secret Facilities clearance, a proven subcontractor track record and a deep understanding of agencies across Defense, Intelligence, Homeland, Justice and Federal Civilian Sectors, Kforce brings more than 20 years of experience to supporting critical missions at federal, state and local levels.