×
Register Here to Apply for Jobs or Post Jobs. X

Compliance Specialist, IT​/Tech

Job in Lexington, Middlesex County, Massachusetts, 02173, USA
Listing for: Gilder Search Group
Full Time position
Listed on 2026-07-15
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 90000 - 130000 USD Yearly USD 90000.00 130000.00 YEAR
Job Description & How to Apply Below

IT Security Risk Auditor

Clearance Level: Must be able to obtain an Active Secret Clearance to be considered. Must be US Citizen

Location: Must be within 100 miles from Lexington, MA

At Aquila Technology, you will see our team’s passion every day, whether we are building a robust, policy-compliant IT system or stress‑testing a system to identify gaps and security vulnerabilities. To own the advantage, we ensure our team owns results and gets the work done right the first time by deploying smart, purposeful solutions that work. Aquila is the right people with the right skills driving the right outcomes.

We call this the Aquila Advantage.

About the Role

Aquila Technology is seeking a IT Security Risk Auditor to join its team in support of one of the nation’s premier defense research organizations. The team's overall mission is to enable research and development while keeping the organizations community safe and secure through the protection of information, network, facilities and personnel. The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and organizational Information System Security Procedures.

The candidate must be knowledgeable in fundamental computer security principles and policies:
Security Technical Implementation Guides (STIGs), NIST 800‑53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1‑4, NIST SP 800‑171 and DAAPM 2.0.

Responsibilities

The IT Security Risk Auditor will be responsible for maintaining and auditing programs to validate compliance with various government regulations and organizational Information Security policies. The position is responsible for conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls (i.e. the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome) with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system and for the ability to conduct open‑source and internal research to identify current threat indicators, exploits, and vulnerabilities.

Requirements
  • Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years’ experience conducting risk assessments.
  • Experience in compliance auditing, security reviews, or vulnerability assessments.
  • Technical experience and skills, coursework completed toward a degree, and industry IT certifications (e.g., CISSP, CISA) may be considered substitutes for education and experience.
  • In‑depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800‑171 and Security Technical Implementation Guides (STIGs).
  • The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR/DFARS Safeguarding CUI series (252.204‑7012, etc.), computer security principles and policies, to include Security Technical Implementation Guides (STIGs) and NIST 800‑53 / Risk Management Framework (RMF) and NIST SP 800‑171.
  • Working experience directly related to Assessment and Authorization using at least one of the following:
    • NIST 800‑53/Risk Management Framework (RMF)
    • Joint Special Access Program (SAP) Implementation Guide
    • NIST SP 800‑171 Understanding of CMMC Framework
    • National Industrial Security Program Operating Manual (NISPOM)…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary