×
Register Here to Apply for Jobs or Post Jobs. X

IT Security Risk Auditor

Job in Lexington, Middlesex County, Massachusetts, 02173, USA
Listing for: Connexion Systems and Engineering, Inc.
Part Time position
Listed on 2026-07-24
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 55 - 72 USD Hourly USD 55.00 72.00 HOUR
Job Description & How to Apply Below

Position Summary

MUST BE ABLE TO WORK 2-3 Days onsite in Massachusetts. DO NOT APPLY unless you meet this qualification.

IT Security Risk Auditor

3 year contract

Pay Range: $55-$72/hr

Hybrid: predominantly onsite to start eventually leading to 2-3 days/week on site

Clearance: eligible to obtain Top Secret (interim sufficient to start)

Department Overview

The Security Services Department’s (SSD) overall mission is to enable research and development while keeping the community safe and secure through the protection of information, network, facilities and personnel.

Position Description

The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure they are maintained in a compliant manner and follow applicable laws and government regulations, including NISPOM guidelines, NIST standards, CMMC, DCSA Assessment and Authorization Process Manual (DAAPM), and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies such as STIGs, NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171, and DAAPM 2.0.

Responsibilities include maintaining and auditing programs to validate compliance with government regulations and Information Security policies, conducting comprehensive assessments of management, operation, monitoring and technical security controls within Information Systems, determining the overall effectiveness of controls, and conducting open source and internal research to identify threat indicators, exploits, and vulnerabilities.

Requirements
  • Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field with a minimum of seven (7) years of experience conducting risk assessments.
  • Experience in compliance auditing, security reviews, or vulnerability assessments.
  • Technical experience and skills, coursework completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience.
  • In-depth knowledge of information security principles and policies such as RMF, NIST SP 800-171, and STIGs.
  • Ability to read, understand and apply government regulation, policies and procedures such as NISPOM, 32 CFR Part 117, FAR/DFARS Safeguarding CUI series , etc.), computer security principles and policies, including STIGs and NIST 800-53/Risk Management Framework (RMF) and NIST SP 800-171.
  • Working experience directly related to Assessment and Authorization using at least one of the following:
  • NIST 800-53/Risk Management Framework (RMF)
  • Joint Special Access Program (SAP) Implementation Guide
  • NIST SP 800-171 Understanding of CMMC Framework
  • National Industrial Security Program Operating Manual (NISPOM) Chapter 8
Preferred
  • Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).
  • Direct experience with DCSA facility compliance reviews and security audits.
Hybrid Role

This position will be predominantly onsite for the first 3-4 months (probably 4 days/wk onsite). After the initial ramp up period, there may be an opportunity for more remote, 2-3 days/week. Long term, candidate must be comfortable with being onsite at least 2+ days and as needed for the project work.

Clearance

Interim clearance sufficient for start; but candidate will need to clear up to the Top Secret Level.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary