Regulatory & Compliance Manager
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Information Security
Overview
Aero Simulation, Inc. (ASI) provides quality flight training devices to the US Military with over 40 years of experience. Programs include B-1 Training Systems (Air Force), E-2D Training Systems (Navy), CH-53E Training Devices (USMC), IMOMS (Coast Guard), Navigation, Seamanship, Ship handling Trainer – NSST (Navy). ASI is 100% employee-owned and offers a flexible work environment, competitive compensation, and comprehensive benefits.
ASI is a great place to build a career and grow with a company dedicated to quality, service, and a supportive team. To learn more about this opportunity, keep reading.
Position SummaryThe Regulatory & Compliance Manager (Defense Programs) interprets and operationalizes U.S. defense-related regulatory requirements including ITAR, EAR, CMMC, DFARS cybersecurity clauses, and related DoD information-protection requirements. This role leads the development, implementation, and governance of company-wide policies, procedures, training programs, and assessment activities to ensure proper governance, classification, protection, and exportability determinations for Controlled Unclassified Information (CUI), Controlled Technical Information (CTI), and ITAR/EAR-controlled data.
This position supports program execution, audits, pre-contract reviews, and routine departmental operations to mitigate regulatory, contractual and security risk. This is not a technical role, but a general understanding of tools and technologies used to implement technical security controls is preferred.
- Regulatory Interpretation and Program Development – Serve as the company’s subject matter expert on ITAR, EAR, CMMC, DFARS cybersecurity clauses, and DoD-specific controlled information categories.
- Develop and maintain corporate policies, operating procedures, standards, and guidance related to data protection, export controls, and information governance.
- Maintain a regulatory intelligence function tracking changes to relevant U.S. government requirements, industry trends, and enforcement actions, and assess potential impact to company operations and programs.
- Lead classification and marking reviews for CUI, CTI, ITAR/EAR technical data, and company proprietary information, and establish processes for data handling, storage, transmission, and access authorization in line with requirements.
- Work with engineering, program management, quality, operations, and HR to embed classification controls into daily workflows and business processes.
- Training and Awareness – Develop annual and role-based training programs for CUI, export controls, cybersecurity compliance, and sensitive data handling; deliver instructor-led training as needed to maintain training records for audit readiness.
- Assessments, Monitoring, and Oversight – Support internal readiness assessments for CMMC and NIST 800-171; participate in program reviews, contract kickoff meetings, and export-related technical reviews to identify compliance risks early; conduct periodic audits of data storage locations, document repositories, and file-sharing platforms to ensure compliance.
- Export Controls (ITAR/EAR) – Provide guidance on jurisdiction and classification (USML/ECCN) for technical data and defense articles; coordinate with legal counsel on export license requirements and technology control plans (TCPs); enforce access restrictions and ensure safeguards for export-controlled information.
- Cross-Functional Collaboration – Partner with HR, IT, Security, Engineering, Operations, and Program Management to integrate compliance requirements within business processes; serve as a point of contact during audits, inspections, and external assessments; support incident response involving potential mishandling of controlled information.
- Experience – 5-10+ years in defense-sector compliance, cybersecurity, export controls, or related governance roles.
- Strong understanding of ITAR, EAR, CMMC 2.0, NIST 800-171, and DFARS 7012/7019/7020/7021; experience creating policies, procedures, and training content; demonstrated ability to perform controlled-information classification and export-control evaluations.
- Preferr…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).