Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor

sgsconsulting

Job Description

Job Description

Job Title: IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor/ Cybersecurity Compliance Specialist /IT Security Compliance Analyst/ IT Security Auditor

Duration: 3 Years (High Possibility of Extension)

Location: Lexington, MA

 

Job Description:

Clearance: Interim clearance is sufficient for start

Work Location: This position will be predominantly onsite for the first 3-4 months (probably 4 days/week onsite). After the initial ramp up period, there may be an opportunity for more remote, 2-3 days/week.

Interview Process: Initial zoom interview, second round zoom

 

Description:

Develops and oversees compliance programs, supporting compliance efforts, governance/policy, reporting, and incident response. Ensures that the organization remains compliant with all regulations and policies as required based on the local and federal requirements, specifically FAR and DFAR regulations. Conducts internal compliance reviews and documents findings. May participate in internal or external audits. Recommends process or policy change to increase compliance or efficiencies. Generates reports and analyzes data on applicable compliance related topics. Engages with internal stakeholders and any external partners as needed. Develops presentations and collateral for compliance related topics.

 

Background/Need:

The SSD overall mission is to enable research and development while keeping the community safe and secure through the protection of information, network, facilities and personnel.

 

Other information relevant to the job requirement?

The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies: Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0.

 

Requirements:

· Bachelor’s degree in computer science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years’ experience conducting risk assessments.

· Experience in compliance auditing, security reviews, or vulnerability assessments.

· Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience.

· In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800-171 and Security Technical Implementation Guides (STIGs).

· The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR/DFARS Safeguarding CUI series (252.***-7012, etc.), computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF) and NIST SP 800-171.

 

Working experience directly related to Assessment and Authorization using at least one of the following:

· NIST 800-53/Risk Management Framework (RMF)

· Joint Special Access Program (SAP) Implementation Guide

· NIST SP 800-171 Understanding of CMMC Framework

· National Industrial Security Program Operating Manual (NISPOM) Chapter 8

 

Preferred:

· Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).

· Direct experience with DCSA facility compliance reviews and security audits.

\nCompany Description

Software Galaxy Systems, LLC (SGS) is an award-winning Contingent Workforce Services firm providing a broad range of integrated suite of services through a global delivery platform. SGS brings innovative talent management strategies to empower its clients to stay focused on growth of their core competencies. SGS has developed a comprehensive process-oriented methodology to manage high-volume contingent labor, payroll services and SOW’s for today’s competitive landscape.

SGS is proud of the partnerships it has built with its clients, MSP’s, and employees which has allowed it to deliver unparalleled service to its wide-ranging customer base. SGS is a certified minority owned enterprise that provides innovative yet practical solutions, from concept through execution. We combine technology with strategy and aim to deliver results today that endure tomorrow. SGS’ client centric approach delivers unparalleled value with vastly responsive, streamlined and highly process oriented workforce solutions.

SGS has been awarded and acknowledged by leading MSP’s (i.e., KellyOCG, TAPFIN, Guidant Global, etc.) for its exemplary performance in the contingent workforce space.

Company Description

Software Galaxy Systems, LLC (SGS) is an award-winning Contingent Workforce Services firm providing a broad range of integrated suite of services through a global delivery platform. SGS brings innovative talent management strategies to empower its clients to stay focused on growth of their core competencies. SGS has developed a comprehensive process-oriented methodology to manage high-volume contingent labor, payroll services and SOW’s for today’s competitive landscape.\r\n\r\nSGS is proud of the partnerships it has built with its clients, MSP’s, and employees which has allowed it to deliver unparalleled service to its wide-ranging customer base. SGS is a certified minority owned enterprise that provides innovative yet practical solutions, from concept through execution. We combine technology with strategy and aim to deliver results today that endure tomorrow. SGS’ client centric approach delivers unparalleled value with vastly responsive, streamlined and highly process oriented workforce solutions.\r\n\r\nSGS has been awarded and acknowledged by leading MSP’s (i.e., KellyOCG, TAPFIN, Guidant Global, etc.) for its exemplary performance in the contingent workforce space.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor in Lexington, MA vacancy
  •  ...opportunity for an IT Third Party and Compliance Analyst in the Technology...  ...Summary The IT Risk and Compliance Analyst...  ...firms’ Information Security Program. This position...  ...employees, external auditors or internal auditors...  ..., etc. As a specialist on complex technical... 
    Suggested
    Full time
    Work experience placement
    Work at office

    100KCrossing

    Boston, MA
    6 days ago
  • $90k - $200k

     ...InvestigationsKroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is...  ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic matters... 
    Suggested
    Temporary work

    Kroll

    Boston, MA
    3 days ago
  • $111.2k - $139k

     ...Yours As a Senior Technical Compliance Analyst, you’ll strengthen our...  ...Working across Engineering, Security, Legal, Compliance, Internal...  ..., validate controls, address risks, and provide clear guidance to...  ...Internal Audit, and external auditors to assess control design and... 
    Suggested
    Full time
    Immediate start

    National Geographic

    Boston, MA
    4 days ago
  •  ...community impact, Vitra Health is seeking a Compliance Analyst who is passionate about...  ...deserve. The Opportunity As a Compliance Specialist with Vitra Health’s, you will support the...  ...internal audits, regulatory reporting, risk management activities, and compliance training... 
    Suggested
    Work at office
    Monday to Friday

    Vitra Health

    Boston, MA
    4 days ago
  • $70k - $150k

     ...InvestigationsKroll's North American Investigations, Diligence and Compliance - Specialist practice is seeking an Associate Manager based in the U.S....  ...and effectiveness of internal controls, performing insider risk compliance assessments, managing projects and resources,... 
    Suggested
    Temporary work
    Interim role
    Flexible hours

    Kroll

    Boston, MA
    3 days ago
  • $90k - $110k

     ...is looking for a talented Global Trade Compliance Specialist to support our Logistics team. You will...  ...carriers, and customs brokers to ensure secure, timely shipment of sensitive hardware....  ...to advise internal stakeholders on risk mitigation.Trade Declarations: Prepare... 
    Full time
    Contract work
    Visa sponsorship

    Boston Dynamics

    Waltham, MA
    1 day ago
  • $110.7k - $218.3k

    Position Summary Senior Consultant - Regulatory & Compliance - Enterprise Operations & Risk Our Deloitte Regulatory, Risk & Forensic team helps client leaders translate multifaceted risk and an evolving regulatory environment into defensible actions that strengthen... 
    Local area
    Visa sponsorship

    Deloitte

    Boston, MA
    3 days ago
  • Security, Risk and Compliance Consultant WHO WE LOOK FOR An SEI-er is amaster communicator and active listenerwho understands how to navigate an audience...  ..., internal or external audits, or experience as an auditor Projects or roles requiring coordination across lines of defense... 
    Permanent employment
    Work experience placement

    SEI

    Boston, MA
    5 days ago
  •  ...leading international economics consulting firm is seeking a Compliance & Client Response Analyst to join its Boston-based team....  ...firm’s capabilities, projects, policies and practices, and IT/data security infrastructure. Key Responsibilities Coordinate with... 
    Work at office
    Flexible hours
    Shift work
    Boston, MA
    more than 2 months ago
  •  ...Harvard’s Office of Research and Academic Compliance (ORAC) within the Office of the Vice...  ...operational expertise, including proactive risk assessment, consultation, and mitigation...  ...and mitigation, compliance, research security, operations, and education/training in the... 
    Work at office
    Shift work

    Harvard University

    Cambridge, MA
    4 days ago
  • $74k - $104k

    IT Internal Auditor Location: Wilmington, Massachusetts Job ID 2605094...  ..., IT operational audits, IT compliance audits, and system development...  ...to strengthen governance and risk management practices, and...  ...computer operations, logical security, and other key technology controls... 
    Work experience placement
    Work at office

    UniFirst

    Wilmington, MA
    6 days ago
  • $27.4 per hour

     ...seeking a Field Operations Associate in Woburn, MA. You will manage onboarding documents, maintain the Candidate Tracker, and ensure compliance with background checks and drug tests. You will provide front desk service, organize office supplies, and support a seamless... 
    Hourly pay

    Aerotek

    Woburn, MA
    2 days ago
  • $99.5k - $119.5k

    General Information Job Title Manager, IT Auditor Job ID 110041 Work Areas...  ..., which reports directly into the Chief Risk Officer and the Board Risk Subcommittee....  ...covering vulnerability and patch management, security monitoring and threat detection,... 
    Permanent employment
    Full time
    Work at office
    Local area
    1 day per week

    Bain & Company

    Boston, MA
    7 hours ago
  • $99.8k - $131k

     ...Information Technology Auditor Corporate Audit Team...  ...information technology risk and control expert,...  ...management while championing compliance with standards for...  ...focusing on helping people secure financial freedom and...  ...review of enterprise IT audit projects that includes... 
    Full time
    Work experience placement
    Worldwide

    Massachusetts Mutual Life Insurance Company

    Boston, MA
    2 days ago
  • $95k - $120k

     ...Description Job Summary The  Security Advisor (Senior Cybersecurity Compliance Consultant) delivers...  ...relationship ownership, risk management, and ongoing...  ...remediation with client IT teams and internal engineers...  ...directly to auditors, third-party assessors, or... 
    Remote job
    Permanent employment
    Contract work
    Fixed term contract

    Intelligent Technical Solutions

    Boston, MA
    1 day ago
  • $110k - $130k

     ...seeking a motivated, detail-oriented, and proactive Senior Compliance Specialist to join our dynamic in-house legal and compliance team! This...  ...smooth operation of our Compliance & Ethics, Financial Crime Risk Management, and Regulatory programs. We are looking for an upbeat... 
    Work at office
    Flexible hours
    3 days per week

    Kayak Europe

    Concord, MA
    3 days ago
  • The IT Internal Audit Contractor will work closely with Internal Audit management and will use IT audit knowledge and...  ...contribute to a variety of concurrent audits, including risk-based assessments and compliance, regulatory and Sarbanes-Oxley reviews. Under the general... 
    For contractors

    Kaav Inc.

    Boston, MA
    6 days ago
  •  ...The Governance, Risk, and Compliance (GRC) Analyst is responsible for identifying...  ..., Information Technology (IT), cybersecurity, audit, and...  .... Enterprise & Information Security Risk Management Conduct comprehensive...  ...between business units, auditors, and Information Security to... 

    Massachusetts-Bay-Transportation-Authority

    Boston, MA
    4 days ago
  •  ...Job Summary The Governance, Risk, and Compliance (GRC) Analyst is responsible...  ...units, Information Technology (IT), cybersecurity, audit, and...  ...Enterprise & Information Security Risk Management Conduct comprehensive...  ...between business units, auditors, and Information Security to... 
    Full time
    Part time
    Internship
    Local area
    Immediate start
    Remote work
    All shifts

    MBTA

    Boston, MA
    2 days ago
  • $64.4k - $128.7k

     ...Senior Compliance Specialist Marsh & McLennan Companies, Inc. ("Marsh") is seeking a talented...  ...individual to join the Compliance team at MMA Securities and MMA Asset Management, collectively...  ...assigned area and assist in managing risk across applicable product lines. You... 
    Minimum wage
    Work at office
    Local area
    Remote work
    Flexible hours
    3 days per week
    1 day per week

    Mercer France

    Boston, MA
    3 days ago
  • $33 - $35 per hour

     ...Job Description Job Description Corporate Compliance Specialist  Location: Boston, MA Job Type: Full-Time Work Arrangement: Hybrid – 3 Days Onsite / 2 Days Remote Compensation: $33-$35/hr + Sign On Bonus: $1,000 Reports To: Senior Director of Compliance... 
    Full time
    Work at office
    Remote work
    Relocation package

    Trinity Management Llc

    Boston, MA
    15 days ago
  • $22 - $25 per hour

     ...Investigation Diligence & Compliance (Specialist) - Intern Join Kroll's Global Investigation Diligence & Compliance Team and gain hands-on...  ...help deliver clarity to our clients’ most complex governance, risk, and transparency challenges. Apply now to join One team, One... 
    Temporary work
    Internship
    Work at office
    Local area
    Remote work
    Boston, MA
    more than 2 months ago
  • City of Somerville is seeking a skilled ADA/EEO administrator to manage citywide programs and investigations, ensuring compliance with federal, state, and local laws. The role collaborates with the Commission for Persons with Disabilities and multiple city departments... 
    Local area

    cityofsomerville

    Somerville, MA
    6 days ago
  •  ...promise and power of diversity. We value independent and critical thinking. This role is part of the compliance team, contributing to the core function of mitigating risk and ensuring the company's adherence to applicable laws and regulations. The primary focus is... 

    Lendbuzz

    Boston, MA
    2 days ago
  • Trinity Management LLC is seeking a Corporate Compliance Specialist to join our Boston team, ensuring compliance across LIHTC, Section 8, HOME, Public Housing, and related programs. This role partners with property management to maintain regulatory compliance and operational... 

    Trinity Management LLC

    Boston, MA
    4 days ago
  •  ...Facilities Manager to oversee building operations, space planning, and security systems across designated sites, including Boston and San Francisco offices. The role ensures safety, regulatory compliance, and efficient maintenance programs. You will coordinate with... 

    MENTOR Technical Group Corporation

    Cambridge, MA
    3 days ago
  •  ...looking for an experienced and dynamic Permitting & Regulatory Compliance Specialist II to join our growing team. In this role you will...  ...project timelines and ensure all deadlines are met. Identify risks early and implement solutions to keep projects on track.... 
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Core States Group

    Burlington, MA
    8 days ago
  • $90k - $110k

     ...professional growth and development. It means making true, lasting...  ...! Overview The Governance, Risk, and Compliance (GRC) Analyst is a strategic...  ...Director, Information Security on expanding and supporting...  ...Certified Information Systems Auditor (CISA), Certified... 
    Work at office
    Local area
    Remote work
    Work from home

    Planet Fitness

    Boston, MA
    4 days ago
  •  ...Job Description Job Description Food Safety and Regulatory Compliance Specialist About ColdSnap ColdSnap® is a rapid freezing appliance that produces single servings of frozen confections and frozen beverages in about 120 seconds from shelf-stable, ambient temperature... 
    Full time
    Work at office
    Local area
    Relocation package

    ColdSnap

    Billerica, MA
    9 days ago
  •  ...2014, serving the Pharmaceutical, Medical Device, Biotech, and IT industries across the USA, Canada, and India. We provide specialized...  ..., and long-term client success. Position: Technical Compliance Associate Location: Massachusetts Duration: Long Term... 

    Stark Pharma Solutions Inc

    Burlington, MA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor. Be the first to apply!