Must Have Admin Compliance & Auditing 7 years Degree Level Bachelor's Degree Yes Experience Document audit findings, including non-compliance issues or deviations 7 years Identify potential compliance issues and recommend policy/procedure changes 7 years IT system security compliance (NIST, PCI, HIPPA, CMMC) 3 years Support preparation for audit/review activities 7 years Government Policy/Regulations STIG Compliance 3 years Security NISPOM 32 CFR Part 117 experience 3 years NIST 800-171 3 years NIST 800-53 3 years Risk Management Framework (RMF) 3 years Soft Skills Strong Verbal and Written Communication Yes Time Management Yes Software MS Suite (Excel, ppt) 7 years Nice to Have Certification Security+ CE, CASP, CISSP, or similar security certification Yes Security Cybersecurity Maturing Model Compliance (CMMC) 0 years The position is responsible for conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls (i.e. the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome) with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system and for the ability to conduct open source and internal research to identify current threat indicators, exploits, and vulnerabilities.