Oasys International logo
Oasys InternationalPosted 3 weeks ago
EXPIRED

Cyber Security Audit & Compliance Specialist

RemoteElizabeth City, North Carolina, United States

Full Time

Job Summary

Execute cybersecurity assessments, control validations, and audit readiness activities aligned with RMF guidelines. Oversee Authorization to Operate (ATO) documentation, manage Plans of Action & Milestones, and support remediation strategies for identified vulnerabilities. Evaluate system security requirements, enforce policies and procedures, and monitor SIEM systems to identify anomalies and ensure threat visibility. Collaborate with development and operations teams to integrate security controls into DevSecOps pipelines. Serve as a liaison with external auditors and federal oversight bodies to ensure compliance with DHS, FISMA, and NIST standards. Review audit logs and configuration reports to detect violations and implement corrective actions. Support security education and training across the Aviation Logistics Center Information Systems Division teams. Maintain readiness for ATO audits across cloud, on-premises, and hybrid environments while managing RMF accreditation artifacts.

Required Qualifications

  • U.S. citizenship
  • Active DoD Secret Clearance
  • CompTIA Security+ certification
  • Bachelor's or Associate's degree in Computer Science, Math, Information Technology, Engineering, or related field
  • Six (6) years of directly relevant experience may substitute for three (3) years of formal education
  • Minimum of six (6) years of experience in Information security with cyber security, security programs or compliance assurance
  • Minimum of six (6) years of experience with Security Information and Event Management (SIEM)
  • Minimum of six (6) years of experience in the risk management framework
  • Basic knowledge of Active Directory, UNIX, Windows, and Relational Databases
  • Deep knowledge of RMF, NIST SP 800-53, FISMA, and DHS 4300A controls
  • Proven experience conducting system audits, preparing for external inspections, and remediating noncompliant findings
  • Expertise with SIEM platforms, vulnerability scanning tools, and GRC platforms
  • Familiarity with enterprise operating environments including Active Directory, Linux/UNIX, Windows, and relational databases
  • Strong written and verbal communication skills
  • Ability to write technical security documentation and brief executive stakeholders
  • Experience supporting secure development pipelines and system baselining in federal DevSecOps environments preferred

Desired Qualifications

  • Experience working on or supporting federal government enterprise systems
  • Additional certifications: Network+, AWS Certified Cloud Practitioner, Microsoft Azure Fundamentals, Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), ITIL Foundation, TOGAF, or other cybersecurity architecture certifications

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles