Cybersecurity & Compliance Specialist

Zolon Tech

  • White Oak, MD
  • 3 days ago
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Access Authorizationunmatched
    • Access Controlunmatched
    • Amazon Web Services (AWS)unmatched
    • Auditingunmatched
    • Authenticationunmatched
    • Best Practicesunmatched
    • Biologyunmatched
    • Biotech and Pharmaceuticalunmatched
    • Center For Drug Evaluation and Research (CDER)unmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Code of Federal Regulationsunmatched
    • Computer Securityunmatched
    • Computer Systemsunmatched
    • Continuous Improvementunmatched
    • Corrective Actionunmatched
    • Cryptographyunmatched
    • Data Processingunmatched
    • Data Qualityunmatched
    • Documentationunmatched
    • FDA (Food and Drug Administration)unmatched
    • FDA Requirementsunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Governmentunmatched
    • GxPunmatched
    • Healthcareunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Knowledge Managementunmatched
    • Maintain Complianceunmatched
    • Mentoringunmatched
    • Microsoft Windows Azureunmatched
    • Operational Strategyunmatched
    • Privacy Regulationsunmatched
    • Quality Managementunmatched
    • Regulatory Complianceunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Salesforce.comunmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Auditingunmatched
    • Security Monitoringunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Strategic Planningunmatched
    • Support Documentationunmatched
    • System Validationunmatched
    • Technical Strategyunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vendor/Supplier Managementunmatched

    Description

    To acquire the advantage, Zolon PCS is seeking a Cybersecurity & Compliance Specialist. This program will replace multiple decentralized and legacy quality management environments with a single, enterprise-wide platform that supports quality, compliance, training, audits, risk management, equipment management, supplier management, and corrective action processes across FDA Centers and Offices. The solution will support FDA organizations, including the Center for Biologics Evaluation and Research (CBER), Center for Drug Evaluation and Research (CDER), Office of Pharmaceutical Quality (OPQ), Human Food Program (HFP), Office of the Chief Scientist (OCS), Office of Inspections and Investigations (OII), and other FDA quality organizations.

    Job Description:
    Ensure ComplianceQuest, Salesforce GovCloud, and integrated solutions comply with applicable federal cybersecurity, privacy, regulatory, and compliance requirements throughout implementation and operations and maintenance (O&M).
    Support implementation, assessment, and continuous monitoring of security controls aligned with FedRAMP, FISMA, NIST Risk Management Framework (RMF), NIST 800-53, FDA cybersecurity policies, and agency-specific requirements.
    Conduct vulnerability management, security reviews, access control assessments, security impact analyses, risk analysis, and compliance evaluations to maintain a secure operating environment.
    Support Authority to Operate (ATO), security authorization, security documentation, audit support, compliance reporting, and corrective action activities.
    Collaborate with architects, developers, administrators, quality teams, and security stakeholders to integrate security and compliance requirements throughout the system development lifecycle (SDLC).
    Support implementation and oversight of Identity, Credential, and Access Management (ICAM), role-based access controls (RBAC), multi-factor authentication (MFA), least-privilege principles, encryption, audit logging, and data protection controls.
    Ensure compliance with FDA regulatory requirements, GxP expectations, 21 CFR Part 11 controls, Computer System Validation (CSV) processes, and data integrity requirements.
    Monitor and track security findings, Plan of Action and Milestones (POA&M) items, audit observations, compliance risks, and remediation activities through resolution.
    Serve as a corporate advisor for Salesforce GovCloud security, FedRAMP compliance, ATO strategies, cloud security architecture, and federal cybersecurity best practices.
    Support cybersecurity solutioning, technical strategy development, and compliance approaches for new federal business opportunities, proposals, oral presentations, and customer engagements.
    Develop reusable security documentation templates, compliance accelerators, security artifacts, and organizational knowledge assets to improve delivery consistency and operational efficiency.
    Present cybersecurity lessons learned, compliance best practices, cloud security guidance, Zero Trust concepts, and authorization strategies to internal and external stakeholders.
    Support corporate initiatives involving cloud security, Zero Trust Architecture (ZTA), continuous monitoring, security modernization, and federal authorization programs.
    Mentor junior cybersecurity personnel and contribute to organizational capability development, knowledge management, and continuous improvement initiatives.

    Requirements:
    Minimum 8 years of cybersecurity and compliance experience.
    Salesforce GovCloud ATO experience strongly preferred.
    Experience supporting FedRAMP-authorized cloud platforms.
    Experience in preparing and maintaining ATO packages.
    Minimum 5 years of cybersecurity, compliance, information assurance, or risk management experience.
    Experience supporting FedRAMP, FISMA, RMF, NIST 800-53, or federal cybersecurity compliance programs.
    Experience supporting ATO packages, security assessments, continuous monitoring, vulnerability management, and audit activities.
    Experience with Salesforce GovCloud, AWS GovCloud, Azure Government, or other FedRAMP-authorized cloud environments preferred.
    Knowledge of ICAM, RBAC, MFA, Zero Trust Architecture, cloud security, and security governance practices.
    Experience working in FDA-regulated, Healthcare, Life Sciences, or other highly regulated environments preferred.
    Knowledge of GxP, 21 CFR Part 11, CSV, and data integrity requirements preferred.
    Prior FDA experience is highly desirable.
    Security+, CISSP, CAP, CISM, CCSP, or equivalent cybersecurity certifications preferred.
    Bachelor's degree desired.

    Clearance: Ability to obtain Public Trust tier 2
    Location: White Oak, Maryland (Hybrid)

    Numbers & Facts

    LocationWhite Oak, MD

    Similar Jobs

    See more jobs