Senior Security and Compliance Specialist

Posted 3 Days Ago
Be an Early Applicant
McLean, VA, USA
In-Office
150K-170K Annually
Senior level
Software
The Role
Supports cybersecurity, risk management, and regulatory compliance for federal technology programs. Provides expertise in NIST RMF, FISMA, and NIST SP 800-53; evaluates security impacts, supports ATO and continuous monitoring, maintains POA&Ms and compliance documentation, prepares audit artifacts, and advises technical teams, leadership, partners, and government stakeholders. The role also mentors colleagues and contributes to recruiting activities.
Summary Generated by Built In
Senior Security and Compliance Specialist

This is a remote position.
JOB ID #980

Ad Hoc is a technology company that empowers organizations to deliver scalable, impactful digital services. Using modern, agile methods, our team creates products that meet people’s needs and transform their experience of government.

Work on things that matter

Our collaborations have shaped some of the defining moments in public-sector service delivery. We’ve helped build products that connect Veterans to tailored services, help millions access affordable health care, and support important programs like Head Start. As we work with agencies to deliver critical services, we’re also changing how the government approaches technology.

Built for a remote life

Our culture, communications, and tools are built for remote work, enabling us to bring together top talent nationwide. At Ad Hoc, remote life empowers our teams to design work environments that fit their lives and that foster flexibility and collaboration to achieve positive outcomes for our customers.

Committed to high expectations and a welcoming culture

Ad Hoc values acceptance, accountability, and humility. We aren’t heroes. We learn from our mistakes and improve the process for the next time. We build small, inclusive teams to collaborate closely with our partners to solve the right problems and deliver software that works.

The Veterans Affairs business unit helps transform the VA into a modern digital services organization where Veteran outcomes are at the center of every effort. We partner with the VA to design and deliver seamless user experiences for Veterans, their families and caregivers, and VA employees. By applying better practices in service design, product management, and technology, we enable the VA to increase the use, quality, and reliability of services and decrease the time Veterans spend waiting for outcomes.

Primary Responsibilities

As a Senior Security and Compliance Specialist, you will serve as an experienced individual contributor responsible for supporting security, risk management, and regulatory compliance across complex federal technology programs.

Working with minimal oversight, you will collaborate with technical teams, program leadership, and government stakeholders to ensure systems meet security and compliance requirements while supporting successful program delivery.

You will contribute to the development and implementation of security and compliance strategies, provide subject matter expertise, and help identify opportunities to strengthen security practices and processes. You may serve as a primary security and compliance point of contact for program stakeholders, providing technical guidance and supporting cross-functional teams.

Primary expectations of a Senior Security and Compliance Specialist include:

  • Serve as a subject matter expert on security and compliance requirements, providing guidance and recommendations to internal teams, external partners, and government stakeholders.
  • Apply expertise in the NIST Risk Management Framework (RMF), Federal Information Security Modernization Act (FISMA), and NIST SP 800-53 security and privacy controls.
  • Evaluate how system changes, technical decisions, and development activities may impact security, privacy, and regulatory compliance.
  • Support the implementation and continuous improvement of security and compliance processes across the program.
  • Execute security and compliance activities, prioritize tasks, identify and resolve blockers, and collaborate with development teams to support secure software delivery.
  • Support Authorization to Operate (ATO) preparation, maintenance, and continuous monitoring activities while balancing security requirements with program delivery objectives.
  • Maintain security and compliance documentation, Plans of Action and Milestones (POA&Ms), and system artifacts within the organization's Governance, Risk, and Compliance (GRC) tools.
  • Interpret applicable cybersecurity laws, regulations, frameworks, and standards, translating requirements into actionable guidance for cross-functional teams.
  • Develop and maintain formal security documentation, compliance reports, and supporting artifacts for internal reviews, external audits, and regulatory requirements.
  • Collaborate with program leadership, technical teams, and external partners to identify security risks, recommend mitigation strategies, and improve compliance practices.
  • Provide technical guidance and mentorship to colleagues, helping strengthen security and compliance knowledge across the team.
  • Support recruiting activities, including reviewing technical assessments and participating in candidate interviews as needed.

Basic Qualifications

  • Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, or a related field, with 7+ years of relevant professional experience. Additional relevant experience may be considered in lieu of a degree.
  • At least 4 years of hands-on cybersecurity experience and at least 2 years of experience working with security and compliance frameworks.
  • Strong knowledge of NIST RMF, FISMA, and NIST SP 800-53 security controls.
  • CompTIA Security+ certification and either CISSP or CISM certification.
  • Must be legally authorized to work in the United States and be able to successfully complete and maintain all required federal Public Trust background investigations and suitability/fitness determinations within the required customer onboarding timelines.
  • Previous favorable Public Trust determination or federal customer suitability approval preferred.

Preferred Qualifications

  • Certificate of Competence in Zero Trust (CCZT).
  • CompTIA SecurityX (formerly CASP+) certification.
  • Experience with ServiceNow Continuous Authorization and Monitoring (SNOWCAM).
  • Familiarity with Kubernetes and Amazon Web Services Elastic Kubernetes Service (AWS EKS).

To learn more about working at Ad Hoc, please visit:https://adhocteam.us/join

Benefits:

  • Company-subsidized health, dental, and vision insurance

  • Flexible PTO

  • 401K with employer match

  • Paid parental leave after one year of service

  • Employee Assistance Program

Ad Hoc LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, ancestry, sex, sexual orientation, gender identity or expression, religion, age, pregnancy, disability, work-related injury, covered veteran status, political ideology, marital status, or any other factor that the law protects from employment discrimination.

We value the unique skills gained through military service and encourage veterans and transitioning service members to apply.

In support of various state and city equal pay transparency laws, Ad Hoc job descriptions feature the starting range we reasonably expect to pay to candidates who would join our team with little to no need for training on the responsibilities we've outlined above. Actual compensation is influenced by a wide range of factors including but not limited to skill set, level of experience, and responsibility. The range of starting pay for this role is $150,000 - $170,000. Our recruiters will be happy to answer any questions you may have, and we look forward to learning more about your salary requirements.

job reference:

https://adhoc.team/

Skills Required

  • Bachelor’s degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent additional relevant experience
  • 7+ years of relevant professional experience
  • At least 4 years of hands-on cybersecurity experience
  • At least 2 years of experience working with security and compliance frameworks
  • Strong knowledge of NIST RMF, FISMA, and NIST SP 800-53 security controls
  • CompTIA Security+ certification
  • CISSP or CISM certification
  • Legal authorization to work in the United States
  • Ability to successfully complete and maintain required federal Public Trust background investigations and suitability or fitness determinations
  • Previous favorable Public Trust determination or federal customer suitability approval
  • Certificate of Competence in Zero Trust (CCZT)
  • CompTIA SecurityX certification, formerly CASP+
  • Experience with ServiceNow Continuous Authorization and Monitoring (SNOWCAM)
  • Familiarity with Kubernetes and AWS EKS
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: 's-Gravenhage
486 Employees
Year Founded: 2014

What We Do

Ad Hoc is a digital services company that helps the federal government better serve people. Our team of experts from across commercial industry and government brings the modern skills necessary to help agencies transform public services into digital services. Our work enables agencies to meet the needs of their users while closing the gap between consumer expectations and government.

Similar Jobs

Mastercard Logo Mastercard

Manager, Economic Modeling

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Arlington, VA, USA
38800 Employees
130K-254K Annually

Capital One Logo Capital One

Full-stack Engineer

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
2 Locations
55000 Employees
179K-225K Annually

Capital One Logo Capital One

Senior Director, Integrated Work Force Transformation

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
McLean, VA, USA
55000 Employees
239K-272K Annually

Capital One Logo Capital One

Director, AI Engineering (Remote - eligible)

Fintech • Machine Learning • Payments • Software • Financial Services
Remote or Hybrid
3 Locations
55000 Employees
245K-335K Annually

Similar Companies Hiring

Ford Energy Thumbnail
Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
US
55 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account