Senior Security and Compliance Specialist
- Salary
- $150K–$170K
- Hiring from
- United States
- Work type
- Remote
- Posted
507,569 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Senior Security and Compliance Specialist
This is a remote position.
JOB ID #980
Ad Hoc is a technology company that empowers organizations to deliver scalable, impactful digital services. Using modern, agile methods, our team creates products that meet people’s needs and transform their experience of government.
Work on things that matter
Our collaborations have shaped some of the defining moments in public-sector service delivery. We’ve helped build products that connect Veterans to tailored services, help millions access affordable health care, and support important programs like Head Start. As we work with agencies to deliver critical services, we’re also changing how the government approaches technology.
Built for a remote life
Our culture, communications, and tools are built for remote work, enabling us to bring together top talent nationwide. At Ad Hoc, remote life empowers our teams to design work environments that fit their lives and that foster flexibility and collaboration to achieve positive outcomes for our customers.
Committed to high expectations and a welcoming culture
Ad Hoc values acceptance, accountability, and humility. We aren’t heroes. We learn from our mistakes and improve the process for the next time. We build small, inclusive teams to collaborate closely with our partners to solve the right problems and deliver software that works.
The Veterans Affairs business unit helps transform the VA into a modern digital services organization where Veteran outcomes are at the center of every effort. We partner with the VA to design and deliver seamless user experiences for Veterans, their families and caregivers, and VA employees. By applying better practices in service design, product management, and technology, we enable the VA to increase the use, quality, and reliability of services and decrease the time Veterans spend waiting for outcomes.
Primary Responsibilities
As a Senior Security and Compliance Specialist, you will serve as an experienced individual contributor responsible for supporting security, risk management, and regulatory compliance across complex federal technology programs.
Working with minimal oversight, you will collaborate with technical teams, program leadership, and government stakeholders to ensure systems meet security and compliance requirements while supporting successful program delivery.
You will contribute to the development and implementation of security and compliance strategies, provide subject matter expertise, and help identify opportunities to strengthen security practices and processes. You may serve as a primary security and compliance point of contact for program stakeholders, providing technical guidance and supporting cross-functional teams.
Primary expectations of a Senior Security and Compliance Specialist include:
- Serve as a subject matter expert on security and compliance requirements, providing guidance and recommendations to internal teams, external partners, and government stakeholders.
- Apply expertise in the NIST Risk Management Framework (RMF), Federal Information Security Modernization Act (FISMA), and NIST SP 800-53 security and privacy controls.
- Evaluate how system changes, technical decisions, and development activities may impact security, privacy, and regulatory compliance.
- Support the implementation and continuous improvement of security and compliance processes across the program.
- Execute security and compliance activities, prioritize tasks, identify and resolve blockers, and collaborate with development teams to support secure software delivery.
- Support Authorization to Operate (ATO) preparation, maintenance, and continuous monitoring activities while balancing security requirements with program delivery objectives.
- Maintain security and compliance documentation, Plans of Action and Milestones (POA&Ms), and system artifacts within the organization's Governance, Risk, and Compliance (GRC) tools.
- Interpret applicable cybersecurity laws, regulations, frameworks, and standards, translating requirements into actionable guidance for cross-functional teams.
- Develop and maintain formal security documentation, compliance reports, and supporting artifacts for internal reviews, external audits, and regulatory requirements.
- Collaborate with program leadership, technical teams, and external partners to identify security risks, recommend mitigation strategies, and improve compliance practices.
- Provide technical guidance and mentorship to colleagues, helping strengthen security and compliance knowledge across the team.
- Support recruiting activities, including reviewing technical assessments and participating in candidate interviews as needed.
Basic Qualifications
- Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, or a related field, with 7+ years of relevant professional experience. Additional relevant experience may be considered in lieu of a degree.
- At least 4 years of hands-on cybersecurity experience and at least 2 years of experience working with security and compliance frameworks.
- Strong knowledge of NIST RMF, FISMA, and NIST SP 800-53 security controls.
- CompTIA Security+ certification and either CISSP or CISM certification.
- Must be legally authorized to work in the United States and be able to successfully complete and maintain all required federal Public Trust background investigations and suitability/fitness determinations within the required customer onboarding timelines.
- Previous favorable Public Trust determination or federal customer suitability approval preferred.
Preferred Qualifications
- Certificate of Competence in Zero Trust (CCZT).
- CompTIA SecurityX (formerly CASP+) certification.
- Experience with ServiceNow Continuous Authorization and Monitoring (SNOWCAM).
- Familiarity with Kubernetes and Amazon Web Services Elastic Kubernetes Service (AWS EKS).
To learn more about working at Ad Hoc, please visit:https://adhocteam.us/join
Benefits:
- Company-subsidized health, dental, and vision insurance
- Flexible PTO
- 401K with employer match
- Paid parental leave after one year of service
- Employee Assistance Program
Ad Hoc LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, ancestry, sex, sexual orientation, gender identity or expression, religion, age, pregnancy, disability, work-related injury, covered veteran status, political ideology, marital status, or any other factor that the law protects from employment discrimination.
We value the unique skills gained through military service and encourage veterans and transitioning service members to apply.
In support of various state and city equal pay transparency laws, Ad Hoc job descriptions feature the starting range we reasonably expect to pay to candidates who would join our team with little to no need for training on the responsibilities we've outlined above. Actual compensation is influenced by a wide range of factors including but not limited to skill set, level of experience, and responsibility. The range of starting pay for this role is $150,000 - $170,000. Our recruiters will be happy to answer any questions you may have, and we look forward to learning more about your salary requirements.
job reference:
https://adhoc.team/