IT Risk and Compliance Senior Specialist at GDIT managing security for cloud and on-premises systems. Collaborating with stakeholders and developing security documentation while ensuring compliance with regulations.
Responsibilities
Manage and/or maintain the security posture and authorization lifecycle for multiple cloud and on-premises information systems.
Collaborate with stakeholders to attain information necessary for continuous monitoring activities, including vulnerability scan analysis, audit log reviews, and supporting the SCA/ISSM during security control assessments.
Develop, maintain, and update security documentation, including System Security Plans (SSPs), Plan of Action & Milestones (POAMs), network architectures.
Collaborate with stakeholders to develop program/project cyber policies.
Support incident response, contingency planning, and disaster recovery efforts as needed by program and stakeholders.
Requirements
3+ years of related experience
Experience as an ISSO
Familiarity with GRC Tools, NIST 800-53, Risk Management Framework
Technical Training, Certification(s) or Degree
Basic understanding of ISSO duties and responsibilities
Awareness of GRC tools (eMASS or XACTA)
Comprehension of change and configuration management and security impact analysis
Knowledge of IT risk management frameworks and regulatory requirements (e.g., NIST 800-171, ISO 27001)
Knowledge of Security and privacy controls (e.g., CIS Level 2, DISA STIG)
Knowledge of DoD security authorization process
Knowledge of Security auditing practices and procedures
Benefits
Comprehensive benefits and wellness packages
401K with company match
Paid time off
Full-flex work week to own your priorities at work and at home
Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
Short and long-term disability benefits
Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance
Head of Risk & Regulatory Compliance leading risk management and compliance in Meruriyo’s Croatian entity. Ensuring alignment with EU regulatory requirements for crypto - asset services.
Regulatory Compliance Manager overseeing compliance matters for a leading international financial institution. Ensuring alignment with regulatory requirements across corporate and investment banking businesses in an international environment.
Investigator managing compliance with Oregon’s Government Ethics laws for the Oregon Government Ethics Commission. Conducting investigations, drafting reports, and providing legal advice to public officials.
Compliance Manager overseeing regulatory audits and compliance projects at Elevance Health. Ensuring adherence to regulations and managing audits while collaborating with various stakeholders.
Senior Manager guiding compliance for CVS Health's regulatory inquiries. Leading market conduct exams and driving action plans across the organization.
Director of Compliance Operations ensuring AltaLink's compliance with Alberta standards and regulations. Leading a team to manage corporate compliance activities effectively.
Manager for Portfolio Compliance overseeing investment compliance and regulatory guidance in New York at AustralianSuper. Leading compliance monitoring and governance for investment activities.
Export Compliance Manager overseeing export compliance programs and processes. Ensuring alignment with global regulatory requirements while partnering with leadership to minimize risks in international trade.
Maintenance Programs Compliance Specialist managing compliance of maintenance programs and changes for Frontier Airlines. Responsible for auditing and oversight of regulatory adherence and program revisions.