Compliance & Audit ; Mid
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced
Compliance & Audit Support Specialist (Mid)to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency in Washington, DC. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role sits within the Information Security Division (ISD) and provides critical compliance monitoring, audit facilitation, documentation support, and risk management services in support of the agency's Federal Information Security Modernization Act (FISMA) obligations, Risk Management Framework (RMF) program, and enterprise-wide cybersecurity and privacy compliance requirements.
The ideal candidate is a detail-oriented and analytically driven cybersecurity compliance professional with a strong foundation in federal information security policy, NIST security frameworks, security controls documentation, and audit support methodologies. This individual must possess the ability to manage multiple concurrent compliance activities across a complex, multi-system federal IT environment, produce high-quality technical documentation aligned to agency standards, and effectively coordinate with system owners, program offices, auditors, and senior Government stakeholders.
The Compliance & Audit Support Specialist (Mid) is responsible for providing comprehensive cybersecurity policy compliance support, security controls documentation, audit facilitation, FISMA reporting, and enterprise risk management support across an assigned portfolio of federal information systems and programs. This individual works closely with ISSOs, system owners, program offices, cybersecurity leadership, and external auditors to ensure that all assigned systems maintain current, accurate, and compliant security documentation, that audit activities are executed smoothly and efficiently, and that the agency's cybersecurity compliance posture is continuously monitored, measured, and reported in accordance with federal and agency requirements.
Principal responsibilities will include but are not limited to:
Cybersecurity Policy & Compliance Documentation Support- Create, update, revise, and maintain cybersecurity and privacy documentation for assigned systems and programs across the enterprise, ensuring all documentation aligns to applicable agency implementation procedures and is reviewed for acceptance by the Office of the CIO.
- Develop and maintain the following documentation types, among others:
- Cybersecurity and Privacy Policies and Procedures
- System Security Plans (SSPs) with detailed, technology-specific control implementation descriptions
- Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs)
- Architecture, topology, and data flow diagrams (OV-1 and SV-1 equivalent)
- Ensure all control implementation descriptions are written to the level of detail required by agency implementation procedures, clearly explaining how each control is specifically implemented across all technologies within the system boundary, and avoiding high-level generalizations or simple restatement of NIST control language.
- Deliver all documentation on or before agency-defined completion dates, addressing all Government comments, edits, and questions within 10 business days of receipt, and escalating stakeholder unresponsiveness to the Government POC after 10 business days without response.
- Ensure selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as directed by the COR.
- Maintain and update all…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).