Compliance Officer Sr.

4 weeks ago


Arlington, Virginia, United States Zermount, Inc Full time
Job Title: Compliance Officer Sr.

We are seeking a highly skilled Compliance Officer Sr. to join our team at Zermount, Inc. in Arlington, VA.

Job Summary:

The Compliance Officer Sr. will be responsible for performing complex risk analyses and ensuring systems and technologies satisfy Information Assurance (IA) and Cybersecurity requirements. This includes providing Plan of Actions and Milestones (POA&M) management, conducting FISMA Compliance meetings, and working with Information Systems Security Officers (ISSO), System Owners (SO), stakeholders, and leadership to meet performance and scorecard metrics.

Key Responsibilities:
  • Perform Compliance reviews and analyses to verify compliance with federal requirements.
  • Conduct daily, weekly, monthly compliance monitoring of assigned systems for all RMF steps.
  • Conduct compliance assessments of assigned systems, based on the Zermount approved Compliance Support Services Framework.
  • Execute day-to-day FISMA compliance monitoring, ensuring that all FISMA activities, including Information Security Continuous Monitoring (ISCM), Continuous Diagnostic and Mitigation (CDM), and FISMA program activities assigned are prioritized correctly, completed on schedule, and are in accordance with Agency and organizations policies.
  • Research major obstacles related to the ever-changing FISMA requirements, which customers will need to overcome and provide recommendations.
  • Track system ATO status, security documentation expirations, Information Security Vulnerability Management (ISVM) compliance, DHS Performance Plan requirements, audit efforts, and CDM support efforts.
  • Conduct analysis of system level POA&Ms and provide guidance and recommendations on potential mitigation to close current or delayed POA&Ms.
  • Track and report on whether assigned systems have mitigated their weaknesses on time using the appropriate processes and reporting timelines.
  • Track and report on whether mandated FISMA activities are being executed in accordance with the current DHS Information Security Performance Plan (ISPP) for the fiscal year.
  • Provide compliance monitoring metrics and reporting to Agency leadership.
  • Review the DHS Scorecard, for each assigned system, conduct analysis, and generate "Get to Green" reports.
  • Conduct Get-to-green meetings with SOs and ISSOs, provide status, deficiencies, recommendations, and document action items with estimated completion dates (ECDs) with the goal of improving system scores within the DHS Scorecard.
  • Manage ISVM alerts and bulletins for TSA systems to include tracking, distributing, and providing reports.
  • Support systems of responsibility to ensure all ISCM and CDM requirements are met and mitigations for failing requirements are identified and discussed to ensure a plan is established to meet all requirements defined. Provide monthly reports with action items for stakeholders and leadership.
  • Create briefings and reports, as required for, but not limited to the following items: high-valued assets, ISVMs, POA&Ms, system scores (FISMA & ISCM).
  • Provide input into the GRC presentations for monthly ISSO Townhall training, as required by management or the Communications & Training Team Lead.
  • Provide updates and input to the GRC SharePoint sites to include document uploads, page updates, access requests, permissions, etc. on an ongoing basis.
  • Create or update existing templates for memos, risk assessments, disposal packages, to standardize and simplify the process.
  • Conduct system compliance assessment to identify progress on ATO conditions, develop extension packages as required annotating analysis of system data / progress.
  • Conduct POA&M management activities, to include processing, reviewing, verifying, and validating creation and closures.
  • Report on expiring and overdue POA&Ms and ensure compliance with all DHS POA&M metrics and requirements as outlined in agency policy and the DHS ISPP.
  • Review waiver and risk acceptance requests for compliance with the Agency's Policies and Procedures.
  • Provide Quality Reviews of security documentation to ensure accuracy and compliance throughout the RMF process.
  • Support systems of responsibility to ensure all Ongoing Authorization (OA), requirements are met, and any deficiencies are identified and tracked. Monitor activities and ensure all deficiencies exceeding 30 days are identified as requiring a POA&M.
  • Assist with conducting review and analysis of Requests for Change (RFC) and providing recommendations to conduct risk assessment (as applicable) based on the change and/or Security Impact Assessment (SIA).
  • Support Security Control Assessors (SCAs) as required for assigned systems.
  • Provide input and assist with all audits, data calls, and queries relating to assigned systems.
  • Stay current with the latest developments in cybersecurity, information assurance, GRC, and related cybersecurity trends.
  • Create or update existing templates such as memos, risk assessments, disposal packages, to standardize and simplify GRC processes.
  • Assist in completing customer's Management Control Objectives Program (MCOP) reporting requirements.
  • Provide Weekly status reporting to leadership.
  • Assist and support other team members as required by the Program Manager.
  • Provide Leadership and Mentoring 2-3 compliance officers.
Qualifications:
  • Experience and expert knowledge on NIST guidelines, FISMA, Cybersecurity principles and methodologies, Executive Orders (EO's), Office of Management and Budget (OMB) Memorandums, Federal, DoD and CISA Technical Reference Architectures, Maturity Models, Risk Management Framework (RMF), Cybersecurity Framework (CSF), technical knowledge of IT systems, and cloud security (is preferred).
  • Knowledge of and experience using relevant cybersecurity and analysis tools such as Archer, Nessus Security Center, Splunk, etc.
  • Experience with cloud-based environments and technologies is preferred.
  • Knowledge of cybersecurity threats, risks, and vulnerabilities and how to mitigate them.
  • Excellent communication skills (written and verbal), with the ability to explain complex concepts in a clear, concise manner.
  • Strong problem-solving skills, proactive, ability to adapt to changes in priorities, attention to detail and organization skills, and possesses good problem-solving and decision-making skills.
  • Must be able to conduct system analysis and quality reviews to detect performance issues.
  • Well-versed in developing compliance solutions to resolve weaknesses or challenges.
  • Ability to work independently and as part of a team.
  • An analytical mind with excellent problem-solving ability is required.
Education and/or Experience:
  • Minimum of a Bachelor of Science (or higher) in one of the following: computer engineering, computer science, IT, cyber security, or a related field and 7 years of IT Cybersecurity experience including direct support of the US government and 4 years acting as an ISSO, Assessor, or Compliance Analyst.
  • Without a B.S. degree, a minimum of 10 years of IT cybersecurity experience including direct support for the US Government will be accepted.
Certifications:
  • A minimum of at least one of the following certifications is required: Certified Authorization Professional (CAP), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Chief Information Security Officer (CCISO) OR equivalent according to the DOD 8570 approved certification list.
Clearance level:
  • Minimum of active Secret Clearance.
Work Location:
  • Primarily Remote. (Required onsite work at the client location in Springfield, VA and Zermount HQ in Arlington, VA., may be occasionally required.)
Hours of Operation:
  • Business Hours: 8:00 am EST - 4:30 pm EST.

  • Compliance Officer

    3 weeks ago


    Arlington, Virginia, United States Kerecis LLC Full time

    Job OverviewKerecis LLC is seeking a highly skilled Compliance Analyst to support the Finance team in ensuring the company's compliance with regulatory requirements and internal policies.The ideal candidate will have a strong understanding of financial regulations and a keen eye for detail.Key Responsibilities:Audit employee expense reports to ensure...


  • Arlington, Virginia, United States International Development Group Advisory Services LLC Full time

    Job Title: Human Resources and Office CoordinatorThe Human Resources and Office Coordinator will support the Human Resources department in various HR and office operations functions, including coordinating new hire orientation, employee relations, benefits administration, training and development, compliance, and general office management/support. This role...


  • Arlington, Virginia, United States International Development Group Advisory Services LLC Full time

    Job Title: Human Resources and Office CoordinatorJob Summary:We are seeking a highly organized and detail-oriented Human Resources and Office Coordinator to support the Human Resources department at International Development Group Advisory Services LLC. The successful candidate will provide administrative support for various HR and office operations...

  • Compliance Officer

    4 weeks ago


    Arlington, Virginia, United States Zermount, Inc Full time

    Job DescriptionZermount, Inc. is seeking a highly skilled Compliance Officer to join our team. The ideal candidate will have expertise in risk management, cybersecurity, and information assurance.Key Responsibilities:Perform complex risk analyses to ensure systems and technologies meet Information Assurance (IA) and Cybersecurity requirements.Develop and...


  • Arlington, Virginia, United States Lockheed Martin Corporation Full time

    Job SummaryWe are seeking a highly skilled Manufacturing Engineer, Sr. to join our PAC-3 Program Manufacturing Engineering team. As a key member of our team, you will be responsible for leading proposal efforts, building proposals, MESOWs, and BOEs, and presenting proposal packages to executive audiences. You will also collaborate with other Manufacturing...


  • Arlington, Virginia, United States Two Six Technologies Full time

    Job Summary: We are seeking an experienced Information System Security Officer (ISSO) to join our Corporate team at Two Six Technologies. As an ISSO, you will play a vital role in ensuring compliance for assigned classified programs and working closely with the Information System Security Manager.Key Responsibilities:Assist the Information System Security...


  • Arlington, Virginia, United States RedMatter Solutions Full time

    Job OverviewRedMatter Solutions is seeking a highly experienced and dedicated Senior Cybersecurity Information Security Officer to oversee the implementation and maintenance of information security measures to protect our organization's data, systems, and networks.Key ResponsibilitiesSecurity Strategy and Planning: Develop and implement comprehensive...


  • Arlington, Virginia, United States Software Engineering Institute Full time

    Job SummaryWe are seeking a highly skilled IT Compliance Specialist to join our team at the Software Engineering Institute. The successful candidate will be responsible for ensuring that our organization adheres to all relevant IT compliance standards and regulations, with a focus on NIST 800-171 and Cybersecurity Maturity Model Certification (CMMC).Key...


  • Arlington, Virginia, United States System High Corp Full time

    Job OverviewThe Export Compliance Specialist plays a critical role in facilitating export-related policy activities and supporting the F-35 Lighting II Joint Program Office (JPO) Export Compliance Office. This includes preparation and coordination of presentations for committee review, interacting with applicable interagency partners, and...

  • Compliance Manager

    3 weeks ago


    Arlington, Virginia, United States Pikemann Full time

    Compliance Manager Job DescriptionPikemann is seeking a highly skilled Compliance Manager to join our team. As a Compliance Manager, you will be responsible for ensuring that our organization is in compliance with all relevant laws and regulations.Key Responsibilities:Develop, implement, and ensure compliance with all Tribal, Federal and State regulations,...


  • Arlington, Virginia, United States System High Corp Full time

    Job SummaryThe Export Compliance Specialist plays a critical role in facilitating export-related policy activities and supporting the F-35 Lighting II Joint Program Office (JPO) Export Compliance Office. This includes preparation and coordination of presentations for committee review, interaction with applicable interagency partners, and...

  • Compliance Specialist

    4 weeks ago


    Arlington, Virginia, United States Kerecis LLC Full time

    Job SummaryThe Compliance Analyst will support the Finance team at Kerecis LLC by auditing employee expense reports, educating employees about expense policies and processes, enforcing company finance policies, and performing internal audits. This role is part of the Finance team and will work in a Kerecis office, reporting directly to the Director of U.S....


  • Arlington, Virginia, United States DT Institute Full time

    Job SummaryThe Grants and Compliance Manager will provide administrative and technical guidance and support to BIPS program leadership, staff, and partners on the design of grant applications, guidelines, and regulations for the small grants' mechanism. The Grants and Compliance Manager will work closely with program staff to manage program sub-grantees, and...


  • Arlington, Virginia, United States DT Institute Full time

    The DT Institute is seeking a highly skilled Grants and Compliance Manager to support the Building Inclusive Peace in Sudan (BIPS) program.This role involves extensive coordination with field offices and sub-grantees to ensure adherence to financial and legal standards.The Grants and Compliance Manager will provide administrative and technical guidance and...


  • Arlington, Virginia, United States System High Corp Full time

    Job Title: Export Compliance SpecialistSystem High Corporation is seeking an experienced Export Compliance Specialist to join our team. As an Export Compliance Specialist, you will assist the government in facilitating export-related policy activities and support the F-35 Lighting II Joint Program Office (JPO) Export Compliance Office.Key...


  • Arlington, Virginia, United States DT Institute Full time

    Job Title: Grants and Compliance ManagerThe DT Institute is seeking a highly skilled Grants and Compliance Manager to join our team in Sudan. As a key member of our program team, you will be responsible for providing administrative and technical guidance and support to our program leadership, staff, and partners on the design of grant applications,...


  • Arlington, Virginia, United States Dexis Consulting Group Full time

    About Dexis Consulting GroupDexis Consulting Group is a professional services firm dedicated to solving complex social challenges in global environments. Our mission is to create a world where all people are safe and prosperous.Job DescriptionWe are seeking a highly skilled Procurement and Export Compliance Manager to join our team. This role will be...


  • Arlington, Virginia, United States Dexis Consulting Group Full time

    About the PositionDexis Consulting Group is seeking a highly skilled Procurement and Export Compliance Manager to support corporate procurement activities and export compliance administration for USG clients. The successful candidate will be responsible for ensuring Dexis' compliance with United States export compliance regulations, managing the export...


  • Arlington, Virginia, United States RedMatter Solutions Full time

    Job DescriptionRedMatter Solutions is seeking a highly experienced and dedicated Senior Cybersecurity Information Security Officer to oversee the implementation and maintenance of information security measures. The ideal candidate will have at least 6 years of experience in cybersecurity and information security management, and will play a key role in...


  • Arlington, Virginia, United States OBXtek Full time

    OverviewOBXtek is seeking a highly skilled Acquisition Program Analyst Sr to support the Secretary of the Air Force for Acquisition (SAF/AQ). The ideal candidate will provide specialized expertise to complement the organization's inherent resources for effective and efficient mission accomplishment and continuity, introduction of innovation, and enhancement...