IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor
sgsconsulting
Job Description
Job Description
Job Title: IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor/ Cybersecurity Compliance Specialist /IT Security Compliance Analyst/ IT Security Auditor
Duration: 36 Months (High Possibility of Extension)
Location: Lexington, MA
Job Description:
Clearance: Interim clearance is sufficient for start
Work Location: This position will be predominantly onsite for the first 3-4 months (probably 4 days/week onsite). After the initial ramp up period, there may be an opportunity for more remote, 2-3 days/week.
Interview Process: Initial zoom interview, second round zoom
Description:
- Develops and oversees compliance programs, supporting compliance efforts, governance/policy, reporting, and incident response.
- Ensures that the organization remains compliant with all regulations and policies as required based on the local and federal requirements, specifically FAR and DFAR regulations.
- Conducts internal compliance reviews and documents findings.
- May participate in internal or external audits.
- Recommends process or policy change to increase compliance or efficiencies.
- Generates reports and analyzes data on applicable compliance related topics.
- Engages with internal stakeholders and any external partners as needed.
- Develops presentations and collateral for compliance related topics.
Other information relevant to the job requirement?
The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies: Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0.
Requirements:
- Bachelor’s degree in computer science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years’ experience conducting risk assessments.
- Experience in compliance auditing, security reviews, or vulnerability assessments.
- Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA ) may be considered substitutes for education and experience.
- In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800-171 and Security Technical Implementation Guides (STIGs).
- The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR/DFARS Safeguarding CUI series (252.***-7012, etc.), computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF) and NIST SP 800-171 .
Working experience directly related to Assessment and Authorization using at least one of the following:
- NIST 800-53/Risk Management Framework (RMF)
- Joint Special Access Program (SAP) Implementation Guide
- NIST SP 800-171 Understanding of CMMC Framework
- National Industrial Security Program Operating Manual (NISPOM) Chapter 8
Preferred:
- Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).
- Direct experience with DCSA facility compliance reviews and security audits.
Software Galaxy Systems, LLC (SGS) is an award-winning Contingent Workforce Services firm providing a broad range of integrated suite of services through a global delivery platform. SGS brings innovative talent management strategies to empower its clients to stay focused on growth of their core competencies. SGS has developed a comprehensive process-oriented methodology to manage high-volume contingent labor, payroll services and SOW’s for today’s competitive landscape.
SGS is proud of the partnerships it has built with its clients, MSP’s, and employees which has allowed it to deliver unparalleled service to its wide-ranging customer base. SGS is a certified minority owned enterprise that provides innovative yet practical solutions, from concept through execution. We combine technology with strategy and aim to deliver results today that endure tomorrow. SGS’ client centric approach delivers unparalleled value with vastly responsive, streamlined and highly process oriented workforce solutions.
SGS has been awarded and acknowledged by leading MSP’s (i.e., KellyOCG, TAPFIN, Guidant Global, etc.) for its exemplary performance in the contingent workforce space.
Company Description
Software Galaxy Systems, LLC (SGS) is an award-winning Contingent Workforce Services firm providing a broad range of integrated suite of services through a global delivery platform. SGS brings innovative talent management strategies to empower its clients to stay focused on growth of their core competencies. SGS has developed a comprehensive process-oriented methodology to manage high-volume contingent labor, payroll services and SOW’s for today’s competitive landscape.\r\n\r\nSGS is proud of the partnerships it has built with its clients, MSP’s, and employees which has allowed it to deliver unparalleled service to its wide-ranging customer base. SGS is a certified minority owned enterprise that provides innovative yet practical solutions, from concept through execution. We combine technology with strategy and aim to deliver results today that endure tomorrow. SGS’ client centric approach delivers unparalleled value with vastly responsive, streamlined and highly process oriented workforce solutions.\r\n\r\nSGS has been awarded and acknowledged by leading MSP’s (i.e., KellyOCG, TAPFIN, Guidant Global, etc.) for its exemplary performance in the contingent workforce space.
$75k - $107k
...solutions, backed by targeted risk control and claims services.... ...have an opportunity for an IT Risk & Compliance Analyst to join our... ..., remediation tracking, and security metrics. This is a hands-on... ...across internal and external auditors in multiple geographic regions...SuggestedFull timeWork at officeFlexible hours$90k - $200k
...Investigations Kroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is... ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters...SuggestedTemporary workFlexible hours- IT Security Compliance AnalystA large, highly regulated healthcare organization is seeking an experienced IT Security Compliance Analyst to support its Security Governance, Risk, and Compliance (GRC) program. This individual will help ensure information systems, security...Suggested
$70k - $150k
...InvestigationsKroll's North American Investigations, Diligence and Compliance - Specialist practice is seeking an Associate Manager based in the U.S.... ...and effectiveness of internal controls, performing insider risk compliance assessments, managing projects and resources,...SuggestedTemporary workInterim roleFlexible hours- ...Environmental Health & Safety professional to assess work environments for hazards, recommend improvements, and ensure regulatory compliance in manufacturing operations. The role involves submitting reports to federal/state offices, interpreting OSHA/EPA standards, and...SuggestedWork at office
- ...Harvard’s Office of Research and Academic Compliance (ORAC) within the Office of the Vice... ...operational expertise, including proactive risk assessment, consultation, and mitigation... ...and mitigation, compliance, research security, operations, and education/training in the...Work at office
$90k - $110k
...is looking for a talented Global Trade Compliance Specialist to support our Logistics team. You will... ...carriers, and customs brokers to ensure secure, timely shipment of sensitive hardware.... ...to advise internal stakeholders on risk mitigation.Trade Declarations: Prepare...Full timeContract workVisa sponsorship$110.7k - $218.3k
Position Summary Senior Consultant - Regulatory & Compliance - Enterprise Operations & Risk Our Deloitte Regulatory, Risk & Forensic team helps client leaders translate multifaceted risk and an evolving regulatory environment into defensible actions that strengthen...Local areaVisa sponsorship- Security, Risk and Compliance Consultant WHO WE LOOK FOR An SEI-er is amaster communicator and active listenerwho understands how to navigate an audience... ..., internal or external audits, or experience as an auditor Projects or roles requiring coordination across lines of defense...Permanent employmentWork experience placement
- ...Chief Information Security Officer (CISO) About the Company Leading... ...postmerger integration risk management strategy sustainability... ...risk governance, and federal compliance. The CISO will be the primary... ...and approving the federal IT security boundary, managing...
- ...Corporation is seeking a Certified Coding Analyst to perform medical claim reviews for waste and error, ensuring coding accuracy and compliance with CPT/HCPCS, ICD-10, and modifiers. You will audit medical records, discuss cases with Medical Directors, and support provider...
$100k - $140k
...inspire performance for life.WHOOP is seeking a Governance, Risk, and Compliance Analyst II, to lead the day-to-day operation and support the... ...AI risk assessments, exceptions management,SDLC reviews and security compliance process ownership. The role will partner closely...Full timeWork at officeRelocation$94.14k - $150.62k
...identifies and manages technology and business risk as the company scales. Reporting directly... ...spanning SOX, system implementations, security, and data governance, giving you exposure... ...recommendations.Partner with external auditors to facilitate reliance on Corporate Audit...Work experience placement$99.8k - $131k
...Information Technology Auditor Corporate Audit Team... ...information technology risk and control expert,... ...management while championing compliance with standards for... ...focusing on helping people secure financial freedom and... ...review of enterprise IT audit projects that includes...Full timeWork experience placementWorldwide- ...IT Internal Audit Contractor The IT Internal Audit Contractor will work closely with Internal Audit management and... ...contribute to a variety of concurrent audits, including risk-based assessments and compliance, regulatory and Sarbanes-Oxley reviews. Under the general...For contractors
$99.5k - $119.5k
General Information Job Title Manager, IT Auditor Job ID 110041 Work Areas... ..., which reports directly into the Chief Risk Officer and the Board Risk Subcommittee.... ...covering vulnerability and patch management, security monitoring and threat detection,...Permanent employmentFull timeWork at officeLocal area1 day per week- CVS Health is seeking a Senior Analyst in IT Compliance & Risk focused on IAM. You will develop governance, support application teams, and ensure... ...reporting. The position emphasizes collaboration with security, infrastructure, and product teams, plus a strong focus on risk...
$95k - $120k
...Description Job Summary The Security Advisor (Senior Cybersecurity Compliance Consultant) delivers... ...relationship ownership, risk management, and ongoing... ...remediation with client IT teams and internal engineers... ...directly to auditors, third-party assessors, or...Remote jobPermanent employmentContract workFixed term contract$110k - $130k
...seeking a motivated, detail-oriented, and proactive Senior Compliance Specialist to join our dynamic in-house legal and compliance team! This... ...smooth operation of our Compliance & Ethics, Financial Crime Risk Management, and Regulatory programs. We are looking for an upbeat...Work at officeFlexible hours3 days per week$64.4k - $128.7k
...type: RegularCategory: Legal, Compliance & RiskIndustry: Real... ...the Compliance team at MMA Securities and MMA Asset Management ,... ...As a Senior Compliance Specialist , you will contribute your expertise... ...area and assist in managing risk across applicable product lines...Minimum wageWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week- The Compliance Specialist provides support for projects, manufacturing execution, computer systems (GP, EBR, OpCenter APS), quality systems (deviations, change controls, CAPAs) and implementation of lean/continuous improvement initiatives within the Manufacturing department...Work at officeWeekend workAfternoon shift
- ...Compliance Specialist Compliance Boston, MA JO-1602-201 Responsible for providing the independent monitoring of investment compliance... ...concerns, present solutions and identify ways to mitigate risk exposure. Train: Work with the Investment...Work experience placement
- ...Senior Compliance Specialist Needed for Inusurance Company in Downtown Boston, MA The Legal Department of an insurance company is seeking an experienced Senior Compliance Specialist who has demonstrated the ability to multi-task, work independently and in team settings...
$33 - $35 per hour
...Job Description Job Description Corporate Compliance Specialist Location: Boston, MA Job Type: Full-Time Work Arrangement: Hybrid – 3 Days Onsite / 2 Days Remote Compensation: $33-$35/hr + Sign On Bonus: $1,000 Reports To: Senior Director of Compliance...Full timeWork at officeRemote workRelocation package- ...who enjoys working independently and being out in the field? We’re looking for a Compliance Consultant to conduct operational audits of independent title agents, identify potential risks, communicate findings, and recommend improvements. This role requires up to 25% travel...Work at officeLocal areaMonday to Friday
- ...of Cambridge is seeking an Assistant Public Records Access Officer to coordinate responses to public records requests and support compliance with Massachusetts public records laws. The role works under the City Law Department, while coordinating with the Police...
- ...looking for an experienced and dynamic Permitting & Regulatory Compliance Specialist II to join our growing team. In this role you will... ...project timelines and ensure all deadlines are met. Identify risks early and implement solutions to keep projects on track....Work at officeImmediate startRemote workFlexible hours
- ...Job Description Job Description Food Safety and Regulatory Compliance Specialist About ColdSnap ColdSnap® is a rapid freezing appliance that produces single servings of frozen confections and frozen beverages in about 120 seconds from shelf-stable, ambient temperature...Full timeWork at officeLocal areaRelocation package
$29 per hour
...Job Description Job Description Logistics and Compliance Specialist I Location: Onsite in Wilmington MA Onsite, Hybrid or Fully Remote Status Reports To : Logistics Manager FLSA Status Management Position: No Compensation Min $29.00 Compensation...Temporary workRemote workFlexible hours- Audax Group is seeking an Information Security Risk Analyst to own risk assessment activities... ...and internal systems. You will lead SOC 1 IT control evidence gathering, coordinate... ...tracking. You will partner with IT, Legal, Compliance, IR, and business stakeholders to...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor. Be the first to apply!
- technology risk Lexington, MA
- risk adjustment Lexington, MA
- risk assurance Lexington, MA
- risk Lexington, MA
- high risk Lexington, MA
- IT security Lexington, MA
- information technology and services consultant Lexington, MA
- remote health information technology Lexington, MA
- IT infrastructure Lexington, MA
- IT analyst Lexington, MA



