Cyber Compliance and Policy Lead

Posted 5 Days Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
135K-165K Annually
Senior level
Co-Working Space or Incubator
The Role
The Cyber Compliance and Policy Lead develops and governs cybersecurity policies, manages compliance efforts, and trains staff across Nooks' infrastructure, ensuring adherence to government mandates and promoting a security culture.
Summary Generated by Built In

ABOUT NOOKS

Are you seeking an exciting and unique opportunity to grow and support our national security? As a startup, we are offering a limited-time opportunity to be an equity owner in a pioneering new industry. Nooks is pioneering Classified Infrastructure-as-a-Service (CIaaS) to provide government and industry partners with the fastest, most efficient access to classified infrastructure. We are building a nationwide network of accredited classified spaces and systems, ensuring that the best technologies equip our nation’s warfighters. At Nooks, we value innovation, collaboration, and a service-first mindset.

ABOUT THE ROLE:

The Compliance and Policy Lead is a critical role focused on developing, implementing, and governing Nooks' enterprise-wide cybersecurity policies and standards. This position is the cornerstone of our compliance program, ensuring our infrastructure, systems, and personnel adhere to the stringent requirements of the DoD and Intelligence Community. You will be the subject matter expert on compliance frameworks like CMMC, DAAPM, and the Risk Management Framework (RMF), responsible for translating complex regulatory guidance into actionable policies, effective training, and verifiable standards. This role is ideal for a meticulous and articulate professional who excels at writing, teaching, and driving a culture of security and compliance across a distributed organization.

KEY RESPONSIBILITIES:

  • Policy Development & Governance: Author, review, and maintain the full suite of enterprise cybersecurity policies, standards, and procedures to ensure alignment with CMMC, DAAPM, NIST SP 800-53/171, and other relevant government directives.
  • Compliance Management: Lead the company's CMMC readiness and sustainment efforts. Develop and manage an internal audit program to continuously monitor compliance across all Nooks sites and systems. Track findings and remediation activities through Plans of Action & Milestones (POA&Ms).
  • Training & Awareness: Design, develop, and implement a comprehensive security training and awareness program for all employees, including annual refreshers and role-based training for technical staff, security personnel, and leadership.
  • Strategic Support: Serve as the primary policy and compliance advisor to the Senior Cybersecurity Manager and site-level security teams (ISSMs/ISSOs), providing expert guidance on interpreting and implementing security controls.
  • Audit & Accreditation Support: Prepare documentation and evidence for external audits, assessments, and system accreditations. Act as a key point of contact for government assessors and third-party auditors (C3PAOs).

REQUIRED QUALIFICATIONS:

  • An active Top Secret (TS) security clearance is required, with SCI eligibility.
  • A minimum of 7-10 years of experience in Cybersecurity, with at least 4 years focused on policy development, compliance, and auditing within the DoD/IC landscape.
  • Proven expertise in writing, managing, and implementing information security policies and standards for a government contractor.
  • In-depth knowledge and hands-on experience with CMMC, RMF, NIST SP 800-53, NIST SP 800-171, and the DAAPM.
  • Demonstrated experience in developing and delivering effective security training programs.
  • Exceptional written and verbal communication skills, with a proven ability to distill complex regulations into clear, concise, and actionable documentation for both technical and non-technical audiences.
  • Active DoD 8570/8140 IAM Level II certification (e.g., CAP, CASP+, CISM, CISSP). The CISSP or CISM certification is strongly preferred.

PREFERRED QUALIFICATIONS:

  • Experience serving as a formal security control assessor or auditor.
  • CMMC Certified Professional (CCP) or CMMC Certified Assessor (CCA) certification.
  • Experience supporting compliance for TS/SCI and/or Special Access Program (SAP) environments.
  • Experience with cloud security compliance in AWS GovCloud or Azure Government.
  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field.

TRAVEL:

  • This role requires 35% travel

ELIGIBILITY + CLEARANCE:

  • You must be a US Citizen with an active Top Secret Clearance.

Salary Range for all departments

Salary Range
$135,000$165,000 USD

Top Skills

Aws Govcloud
Azure Government
Cmmc
Daapm
Nist Sp 800-171
Nist Sp 800-53
Rmf
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
0 Employees

What We Do

Nooks is tackling the challenging necessity of Classified-Infrastructure-as-a-Service (CIaaS) for both industry and government customers to accelerate collaboration, technology adoption and engagement between industry and government to win the Great Power competition. Nooks will lower the barrier-of-entry/scale to qualified companies to engage in classified environments to rapidly bring innovative solutions to reality and revolutionize the landscape of classified operations.

We strive to build a culture of "People First, Service Always." We are a Veteran Owned Small Business, and we believe that service to country can continue even after leaving the military/government. We want each of our employees to grow, learn, and achieve more than they ever thought possible in a culture that embraces diverse backgrounds and perspectives. Come join our team!

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

ES Strategy and Planning Director

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Nashua, NH, USA
150K-256K Annually

Dandy Logo Dandy

Senior Manager, CX Enablement

Computer Vision • Healthtech • Information Technology • Logistics • Machine Learning • Software • Manufacturing
Remote
USA
149K-181K

Dropbox Logo Dropbox

Senior Engineering Manager

Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Remote
United States
241K-326K Annually

HopSkipDrive Logo HopSkipDrive

Metro Service Manager - Denver

Automotive • Edtech • Kids + Family • Mobile • Social Impact • Transportation
Easy Apply
In-Office or Remote
Denver, CO, USA
80K-90K

Similar Companies Hiring

Cie Thumbnail
Software • Enterprise Web • Digital Media • Consulting • Co-Working Space or Incubator • Angel or VC Firm • Agency
Irvine, CA
65 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account