IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor
sgsconsulting
Job Description
Job Description
Job Title: IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor/ Cybersecurity Compliance Specialist /IT Security Compliance Analyst/ IT Security Auditor
Duration: 3 Years (High Possibility of Extension)
Location: Lexington, MA
Job Description:
Clearance: Interim clearance is sufficient for start
Work Location: This position will be predominantly onsite for the first 3-4 months (probably 4 days/week onsite). After the initial ramp up period, there may be an opportunity for more remote, 2-3 days/week.
Interview Process: Initial zoom interview, second round zoom
Description:
Develops and oversees compliance programs, supporting compliance efforts, governance/policy, reporting, and incident response. Ensures that the organization remains compliant with all regulations and policies as required based on the local and federal requirements, specifically FAR and DFAR regulations. Conducts internal compliance reviews and documents findings. May participate in internal or external audits. Recommends process or policy change to increase compliance or efficiencies. Generates reports and analyzes data on applicable compliance related topics. Engages with internal stakeholders and any external partners as needed. Develops presentations and collateral for compliance related topics.
Background/Need:
The SSD overall mission is to enable research and development while keeping the community safe and secure through the protection of information, network, facilities and personnel.
Other information relevant to the job requirement?
The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies: Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0.
Requirements:
· Bachelor’s degree in computer science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years’ experience conducting risk assessments.
· Experience in compliance auditing, security reviews, or vulnerability assessments.
· Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience.
· In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800-171 and Security Technical Implementation Guides (STIGs).
· The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR/DFARS Safeguarding CUI series (252.***-7012, etc.), computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF) and NIST SP 800-171.
Working experience directly related to Assessment and Authorization using at least one of the following:
· NIST 800-53/Risk Management Framework (RMF)
· Joint Special Access Program (SAP) Implementation Guide
· NIST SP 800-171 Understanding of CMMC Framework
· National Industrial Security Program Operating Manual (NISPOM) Chapter 8
Preferred:
· Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).
· Direct experience with DCSA facility compliance reviews and security audits.
\nCompany DescriptionSoftware Galaxy Systems, LLC (SGS) is an award-winning Contingent Workforce Services firm providing a broad range of integrated suite of services through a global delivery platform. SGS brings innovative talent management strategies to empower its clients to stay focused on growth of their core competencies. SGS has developed a comprehensive process-oriented methodology to manage high-volume contingent labor, payroll services and SOW’s for today’s competitive landscape.
SGS is proud of the partnerships it has built with its clients, MSP’s, and employees which has allowed it to deliver unparalleled service to its wide-ranging customer base. SGS is a certified minority owned enterprise that provides innovative yet practical solutions, from concept through execution. We combine technology with strategy and aim to deliver results today that endure tomorrow. SGS’ client centric approach delivers unparalleled value with vastly responsive, streamlined and highly process oriented workforce solutions.
SGS has been awarded and acknowledged by leading MSP’s (i.e., KellyOCG, TAPFIN, Guidant Global, etc.) for its exemplary performance in the contingent workforce space.
Company Description
Software Galaxy Systems, LLC (SGS) is an award-winning Contingent Workforce Services firm providing a broad range of integrated suite of services through a global delivery platform. SGS brings innovative talent management strategies to empower its clients to stay focused on growth of their core competencies. SGS has developed a comprehensive process-oriented methodology to manage high-volume contingent labor, payroll services and SOW’s for today’s competitive landscape.\r\n\r\nSGS is proud of the partnerships it has built with its clients, MSP’s, and employees which has allowed it to deliver unparalleled service to its wide-ranging customer base. SGS is a certified minority owned enterprise that provides innovative yet practical solutions, from concept through execution. We combine technology with strategy and aim to deliver results today that endure tomorrow. SGS’ client centric approach delivers unparalleled value with vastly responsive, streamlined and highly process oriented workforce solutions.\r\n\r\nSGS has been awarded and acknowledged by leading MSP’s (i.e., KellyOCG, TAPFIN, Guidant Global, etc.) for its exemplary performance in the contingent workforce space.
- ...opportunity for an IT Third Party and Compliance Analyst in the Technology... ...Summary The IT Risk and Compliance Analyst... ...firms’ Information Security Program. This position... ...employees, external auditors or internal auditors... ..., etc. As a specialist on complex technical...SuggestedFull timeWork experience placementWork at office
$90k - $200k
...InvestigationsKroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is... ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters...SuggestedTemporary work$111.2k - $139k
...Yours As a Senior Technical Compliance Analyst, you’ll strengthen our... ...Working across Engineering, Security, Legal, Compliance, Internal... ..., validate controls, address risks, and provide clear guidance to... ...Internal Audit, and external auditors to assess control design and...SuggestedFull timeImmediate start- ...community impact, Vitra Health is seeking a Compliance Analyst who is passionate about... ...deserve. The Opportunity As a Compliance Specialist with Vitra Health’s, you will support the... ...internal audits, regulatory reporting, risk management activities, and compliance training...SuggestedWork at officeMonday to Friday
$70k - $150k
...InvestigationsKroll's North American Investigations, Diligence and Compliance - Specialist practice is seeking an Associate Manager based in the U.S.... ...and effectiveness of internal controls, performing insider risk compliance assessments, managing projects and resources,...SuggestedTemporary workInterim roleFlexible hours$90k - $110k
...is looking for a talented Global Trade Compliance Specialist to support our Logistics team. You will... ...carriers, and customs brokers to ensure secure, timely shipment of sensitive hardware.... ...to advise internal stakeholders on risk mitigation.Trade Declarations: Prepare...Full timeContract workVisa sponsorship$110.7k - $218.3k
Position Summary Senior Consultant - Regulatory & Compliance - Enterprise Operations & Risk Our Deloitte Regulatory, Risk & Forensic team helps client leaders translate multifaceted risk and an evolving regulatory environment into defensible actions that strengthen...Local areaVisa sponsorship- Security, Risk and Compliance Consultant WHO WE LOOK FOR An SEI-er is amaster communicator and active listenerwho understands how to navigate an audience... ..., internal or external audits, or experience as an auditor Projects or roles requiring coordination across lines of defense...Permanent employmentWork experience placement
- ...leading international economics consulting firm is seeking a Compliance & Client Response Analyst to join its Boston-based team.... ...firm’s capabilities, projects, policies and practices, and IT/data security infrastructure. Key Responsibilities Coordinate with...Work at officeFlexible hoursShift work
- ...Harvard’s Office of Research and Academic Compliance (ORAC) within the Office of the Vice... ...operational expertise, including proactive risk assessment, consultation, and mitigation... ...and mitigation, compliance, research security, operations, and education/training in the...Work at officeShift work
$74k - $104k
IT Internal Auditor Location: Wilmington, Massachusetts Job ID 2605094... ..., IT operational audits, IT compliance audits, and system development... ...to strengthen governance and risk management practices, and... ...computer operations, logical security, and other key technology controls...Work experience placementWork at office$27.4 per hour
...seeking a Field Operations Associate in Woburn, MA. You will manage onboarding documents, maintain the Candidate Tracker, and ensure compliance with background checks and drug tests. You will provide front desk service, organize office supplies, and support a seamless...Hourly pay$99.5k - $119.5k
General Information Job Title Manager, IT Auditor Job ID 110041 Work Areas... ..., which reports directly into the Chief Risk Officer and the Board Risk Subcommittee.... ...covering vulnerability and patch management, security monitoring and threat detection,...Permanent employmentFull timeWork at officeLocal area1 day per week$99.8k - $131k
...Information Technology Auditor Corporate Audit Team... ...information technology risk and control expert,... ...management while championing compliance with standards for... ...focusing on helping people secure financial freedom and... ...review of enterprise IT audit projects that includes...Full timeWork experience placementWorldwide$95k - $120k
...Description Job Summary The Security Advisor (Senior Cybersecurity Compliance Consultant) delivers... ...relationship ownership, risk management, and ongoing... ...remediation with client IT teams and internal engineers... ...directly to auditors, third-party assessors, or...Remote jobPermanent employmentContract workFixed term contract$110k - $130k
...seeking a motivated, detail-oriented, and proactive Senior Compliance Specialist to join our dynamic in-house legal and compliance team! This... ...smooth operation of our Compliance & Ethics, Financial Crime Risk Management, and Regulatory programs. We are looking for an upbeat...Work at officeFlexible hours3 days per week- The IT Internal Audit Contractor will work closely with Internal Audit management and will use IT audit knowledge and... ...contribute to a variety of concurrent audits, including risk-based assessments and compliance, regulatory and Sarbanes-Oxley reviews. Under the general...For contractors
- ...The Governance, Risk, and Compliance (GRC) Analyst is responsible for identifying... ..., Information Technology (IT), cybersecurity, audit, and... .... Enterprise & Information Security Risk Management Conduct comprehensive... ...between business units, auditors, and Information Security to...
- ...Job Summary The Governance, Risk, and Compliance (GRC) Analyst is responsible... ...units, Information Technology (IT), cybersecurity, audit, and... ...Enterprise & Information Security Risk Management Conduct comprehensive... ...between business units, auditors, and Information Security to...Full timePart timeInternshipLocal areaImmediate startRemote workAll shifts
$64.4k - $128.7k
...Senior Compliance Specialist Marsh & McLennan Companies, Inc. ("Marsh") is seeking a talented... ...individual to join the Compliance team at MMA Securities and MMA Asset Management, collectively... ...assigned area and assist in managing risk across applicable product lines. You...Minimum wageWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week$33 - $35 per hour
...Job Description Job Description Corporate Compliance Specialist Location: Boston, MA Job Type: Full-Time Work Arrangement: Hybrid – 3 Days Onsite / 2 Days Remote Compensation: $33-$35/hr + Sign On Bonus: $1,000 Reports To: Senior Director of Compliance...Full timeWork at officeRemote workRelocation package$22 - $25 per hour
...Investigation Diligence & Compliance (Specialist) - Intern Join Kroll's Global Investigation Diligence & Compliance Team and gain hands-on... ...help deliver clarity to our clients’ most complex governance, risk, and transparency challenges. Apply now to join One team, One...Temporary workInternshipWork at officeLocal areaRemote work- City of Somerville is seeking a skilled ADA/EEO administrator to manage citywide programs and investigations, ensuring compliance with federal, state, and local laws. The role collaborates with the Commission for Persons with Disabilities and multiple city departments...Local area
- ...promise and power of diversity. We value independent and critical thinking. This role is part of the compliance team, contributing to the core function of mitigating risk and ensuring the company's adherence to applicable laws and regulations. The primary focus is...
- Trinity Management LLC is seeking a Corporate Compliance Specialist to join our Boston team, ensuring compliance across LIHTC, Section 8, HOME, Public Housing, and related programs. This role partners with property management to maintain regulatory compliance and operational...
- ...Facilities Manager to oversee building operations, space planning, and security systems across designated sites, including Boston and San Francisco offices. The role ensures safety, regulatory compliance, and efficient maintenance programs. You will coordinate with...
- ...looking for an experienced and dynamic Permitting & Regulatory Compliance Specialist II to join our growing team. In this role you will... ...project timelines and ensure all deadlines are met. Identify risks early and implement solutions to keep projects on track....Work at officeImmediate startRemote workFlexible hours
$90k - $110k
...professional growth and development. It means making true, lasting... ...! Overview The Governance, Risk, and Compliance (GRC) Analyst is a strategic... ...Director, Information Security on expanding and supporting... ...Certified Information Systems Auditor (CISA), Certified...Work at officeLocal areaRemote workWork from home- ...Job Description Job Description Food Safety and Regulatory Compliance Specialist About ColdSnap ColdSnap® is a rapid freezing appliance that produces single servings of frozen confections and frozen beverages in about 120 seconds from shelf-stable, ambient temperature...Full timeWork at officeLocal areaRelocation package
- ...2014, serving the Pharmaceutical, Medical Device, Biotech, and IT industries across the USA, Canada, and India. We provide specialized... ..., and long-term client success. Position: Technical Compliance Associate Location: Massachusetts Duration: Long Term...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor. Be the first to apply!



