Senior Security Compliance Specialist
Listed on 2026-08-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Fortem Technologies is the global leader in airspace security, delivering advanced solutions that protect against today’s autonomous aerial threats while ensuring the safety of tomorrow’s advanced air mobility. Fortem’s AI-powered Sky Dome® Family of Systems combines True View™ sensors, command-and-control software, and autonomous Drone Hunter® interceptors to defend military, government, and commercial operations worldwide from hostile or unauthorized drones. Fortem is the only company authorized to deploy a drone-on-drone kinetic interceptor in U.S. airspace, and its technology has been validated in operational deployments across Europe, the Middle East, and East Asia.
Headquartered in Lindon, Utah, Fortem is privately held and backed by Lockheed Martin, DCVC, Toshiba, AE Industrial Partners, AIM
13, Signia Venture Partners, and others.
We are seeking an experienced IT Security Compliance Specialist to lead our organization's implementation, certification, and ongoing maintenance of Cybersecurity Maturity Model Certification (CMMC) Level 2 controls. This role owns the technical and administrative work required to protect Controlled Unclassified Information (CUI) in accordance with NIST SP 800-171, prepare the organization for its C3
PAO assessment, and sustain continuous compliance across the contract lifecycle. The ideal candidate combines hands-on IT/security engineering skills with a strong understanding of DFARS , CMMC assessment methodology, and federal contracting security requirements.
Technical Security Controls & Infrastructure:
Designing, deploying, and managing the technical backbone of the compliance program.
- Design, configure, and implement technical controls across access control, audit/accountability, configuration management, identification/authentication, incident response, media protection, physical security, risk assessment, system/communications protection, and system/information integrity domains.
- Deploy and manage supporting technologies: MFA, endpoint detection and response (EDR), SIEM/log management, data loss prevention, encryption (at rest and in transit), privileged access management, and network segmentation/enclaving for CUI.
Compliance Readiness & Regulatory Engagement:
Maintaining the compliance ecosystem required to demonstrate and sustain compliance and staying current with evolving requirements.
- Maintain the System Security Plan (SSP), Plan of Action and Milestones (POA&M), Network/Data Flow Diagrams, and control implementation evidence.
- Author and maintain required policies and procedures (Incident Response Plan, Access Control Policy, Configuration Management Plan, etc.) mapped to each control family.
- Maintain a centralized compliance evidence repository sufficient to support a C3
PAO assessment. - Manage recurring compliance activities: annual affirmations, periodic risk assessments, vulnerability scanning/patching cadence, access reviews, and audit log reviews.
- Establish a continuous monitoring program to track control effectiveness, configuration drift, and emerging vulnerabilities; track and remediate assessment findings within required time frames.
- Serve as the primary technical point of contact during the CMMC Level 2 Certification Assessment (C3
PAO) or Self-Assessment, as applicable. - Coordinate with external assessors, consultants, and Registered Practitioner Organizations (RPOs) as needed.
- Maintain compliance through system changes, new vendor/subcontractor relationships (flow-down requirements), and IT infrastructure updates.
- Monitor changes to CMMC/DFARS/NIST 800-171 requirements and update the compliance program accordingly.
- Develop and deliver security awareness and role-based training required under CMMC.
- Partner with HR/Legal on insider threat and personnel security requirements tied to CUI access.
- Partner with Procurement/IT vendors to ensure third-party services (cloud, MSP, SaaS) meet CMMC/FedRAMP requirements.
Other duties as required and assigned in line with IT Security Compliance.
Required Skills/Experience:
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or equivalent experience.
- 3–5+…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).