Job Summary We are seeking a dynamic and detail-oriented
NIST 800-171 / CMMC
Compliance Specialist to lead our organization's efforts in achieving and maintaining rigorous cybersecurity standards. In this pivotal role, you will develop, implement, and oversee compliance programs aligned with
NIST 800-171
(National Institute of Standards and Technology) standards and the Cybersecurity Maturity Model Certification (CMMC) framework. Your expertise will ensure our systems, processes, and policies meet government regulations, safeguarding sensitive information across our IT infrastructure. Join us to champion security excellence, foster a culture of continuous improvement, and support our mission to deliver secure, compliant solutions. Duties Develop and maintain comprehensive System Security Plans (SSPs) that document security controls and compliance status across organizational systems. Conduct thorough security risk assessments and investigations to identify vulnerabilities within cloud infrastructure, network architecture, and IT systems. Lead the implementation of security policies based on NIST standards such as
SP 800-53, ISO 27001, ISO
27002, and FISMA requirements to ensure robust information security management. Manage security frameworks including NIST cybersecurity framework, RMF (Risk Management Framework), and COBIT to align organizational practices with industry best practices. Perform continuous security assessments using tools like SIEM (Security Information and Event Management), vulnerability management solutions, and intrusion detection systems (IDS). Oversee network security measures involving firewalls (Cisco ASA), VPNs, IPsec protocols, IDS/IPS solutions, and network protocols to protect LAN/WAN environments. Coordinate incident response activities, including threat detection & response, incident recovery, and disaster recovery planning to minimize operational impact. Collaborate with cross-functional teams on IT risk management initiatives, identity & access management solutions (IAM), system hardening procedures, and compliance audits. Qualifications Proven experience in developing and managing system security plans within government or regulated environments. Strong knowledge of computer networking concepts including LAN/WAN architecture, routing protocols (OSPF/EIGRP), network installation & support, and network management tools. Hands-on expertise with Cisco ISE, Cisco routers/firewalls (ASA), Juniper devices, AWS cloud infrastructure, VMware virtualization platforms, and related network security technologies. Familiarity with cybersecurity standards such as
NIST SP 800-171/53, ISO 27001/27002/27000
series, PCI DSS, Fed
RAMP, DIACAP
; experience applying these frameworks is highly desirable. Skilled in using GRC software for governance and compliance tracking; experience with vulnerability assessment tools like Nmap or Burp Suite is a plus. Strong understanding of encryption methods including PKI (Public Key Infrastructure), FIPS standards, SSL/TLS protocols; experience with system hardening on various operating systems such as Windows, Linux, macOS is essential. Excellent analytical skills in security analysis, threat intelligence gathering, vulnerability research & assessment; ability to interpret complex data into actionable insights. Effective team leadership capabilities combined with excellent communication skills to coordinate cybersecurity initiatives across technical teams and executive stakeholders. Join us to be at the forefront of cybersecurity excellence! Your expertise will help us uphold the highest standards of government information & network security while advancing your career in a fast-paced environment committed to innovation and integrity.
Pay:
$50,929.98 - $85,000.00 per year
Work Location:
In person
Review key factors to help you decide if the role fits your goals.