Security/Compliance Manager #1689024 - United States
19 hours ago

Job description
About NDi:
Network Designs, Inc. (NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly defined core values have driven all aspects of the business, which have been paramount to our company's success and the establishment of an enjoyable workplace atmosphere. At NDi, we believe that our people are the cornerstone of our success, and we value collaboration, career growth, and winning ideas. Military Veterans Encouraged to Apply.
Job Description:
The Security/Compliance Manager will be responsible for overseeing security controls, compliance activities, and continuous monitoring to ensure VESEE systems meet VA cybersecurity, privacy, and regulatory requirements. This role provides governance and coordination across delivery teams, ensuring security controls are implemented, assessed, documented, and sustained in alignment with VA standards, FISMA, and ATO requirements.
Requirements:
- U.S Citizenship required.
- Must be able to obtain and maintain a Public Trust clearance
- This position is remote but may require occasional onsite meetings in McLean, VA.
- You can be based out of following states: AZ, DC, FL, GA, OH, ME, MD, SC, TX, UT, VA, NC, OK, WV.
Qualifications and Experience:
- Bachelor's Degree in Cybersecurity, Information Technology, Information Assurance, or a related field.
- At least 7 years of experience in security compliance, RMF, or federal cybersecurity roles.
- Strong experience with RMF control implementation and assessment.
- Experience managing ACAS vulnerability scanning and reporting.
- Experience with SCAP compliance checks and STIG application.
- Hands-on experience with eMASS documentation and POA&M management.
- Experience overseeing HBSS/ESS host security monitoring.
- Experience reviewing Nessus/Tenable plugin results and coordinating remediation.
- Experience supporting continuous monitoring aligned with FISMA and ATO requirements.
- Experience managing audit log retention and review across Oracle DB, Oracle WebLogic, and Kubernetes platforms.
- Experience enforcing privilege and access control alignment with VA baseline standards.
- Strong organizational, analytical, and communication skills.
- Ability to lead cross-functional teams and manage multiple compliance priorities.
Preferred Qualifications:
- Experience supporting VA systems or other federal agency environments.
- Experience managing security compliance across large, multi-team delivery programs.
- Relevant certifications such as CISSP, CISM, or equivalent federal cybersecurity certifications
Responsibilities
Security Governance and Oversight:
- Oversee implementation and maintenance of security controls across VESEE systems and environments.
- Ensure alignment of security practices with VA cybersecurity, privacy, and regulatory requirements.
RMF and Compliance Management:
- Lead RMF control implementation, assessment coordination, and ongoing control effectiveness monitoring.
- Oversee SCAP compliance checks and STIG application activities.
- Coordinate ACAS vulnerability scanning, reporting, and remediation tracking.
Continuous Monitoring and ATO Sustainment:
- Manage continuous monitoring workflows aligned with FISMA and VA ATO sustainment requirements.
- Ensure security posture is maintained through regular assessments, scans, and evidence collection.
eMASS Documentation and POA&M Management:
- Oversee eMASS control package documentation, updates, and submissions.
- Manage POA&M development, tracking, and remediation coordination.
Vulnerability Management and Remediation Coordination:
- Review ACAS and Nessus/Tenable scan outputs.
- Coordinate remediation activities across technical teams and track resolution status.
- Ensure vulnerabilities are prioritized and addressed in accordance with VA policies.
Host and Platform Security Monitoring:
- Oversee host-based security monitoring using HBSS/ESS.
- Ensure audit log retention and review requirements are met across Oracle DB, Oracle WebLogic, and Kubernetes container platforms.
Access Control and Privilege Management:
- Ensure privilege and access controls align with VA baseline standards.
- Oversee review and validation of role assignments and access enforcement.
Reporting and Evidence Collection:
- Prepare and review security and compliance reports for VA stakeholders.
- Ensure accurate evidence collection to support audits, assessments, and ATO sustainment.
Cross-Team Coordination and Leadership:
- Provide guidance and direction to delivery teams on security and compliance expectations.
- Serve as the primary point of coordination between engineering teams, compliance staff, and VA security stakeholders.
Compensation and Benefits:
At NDi, we value our team and are committed to retaining top talent by offering competitive benefits and compensation packages. Our employee benefits package includes comprehensive health, dental, vision, pet, and legal insurance. Our corporate benefits include 401(k) retirement matching, paid leave, paid holidays, and health and wellness programs. In addition, we provide employer-paid life and disability insurance, professional development, education benefits, and much more to ensure our team has the resources they need to thrive on and off the job.
Veterans First Commitment:
As a Service-Disabled Veteran-Owned Small Business (SDVOSB), NDi is dedicated to hiring veterans and providing a supportive work environment that honors their service while recognizing the unique skills and experiences they bring to our organization.
Commitment to Diversity:
NDi is an Equal Opportunity Employer. We are committed to creating a diverse environment and are proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran or military status, citizenship, national origin, or any other basis prohibited by law in all phases of the employment process and compliance with applicable federal, state, and local laws and regulations. As a federal government contractor, NDi complies with all applicable affirmative action requirements.
Apply Now:
Take advantage of this unique opportunity to join one of the fastest-growing companies in Federal contracting
Similar jobs
TrapWire is seeking an experienced Information Security and Compliance Manager to own and operate our information security and compliance programs. · ...
3 weeks ago
· Nuclear Fuel Services (NFS) is a division of BWX Technologies. At BWX Technologies, Inc. (NYSE: BWXT), we are People Strong, Innovation Driven. A U.S.-based company, BWXT is a Fortune 1000 and Defense News Top 100 manufacturing and engineering innovator that provides safe and ...
2 days ago
We are seeking a senior technical lead to architect and manage the security posture for a high-growth aerospace technology firm. · Authorization Leadership: Direct the end-to-end execution of CMMC Level 2 and FedRAMP High certifications, including architecture design, gap remedia ...
1 month ago
You will get the opportunity to be on the cutting edge of Cloud Security and Compliance. · Responsibilities · Design, develop, and maintain internal controls in response to security and compliance goals: FedRAMP, SOC2, HIPAA, PCI-DSS, ISO27001 etc. · ...
1 week ago
We're looking for a detail-oriented Security Compliance Analyst to join our Governance, Risk, and Compliance (GRC) team. · Key Responsibilities: · Audit Management: Lead the preparation, execution, and remediation phases for global audits including SOC 1/SOC 2. · ...
1 week ago
+Job summary · Filevine is looking for a Senior Security Compliance Analyst to join our Information Security team and ensure that our platform, applications, and infrastructure are compliant and secured at the highest levels. · ++Strategize and outline goals and objectives of the ...
1 week ago
This is a hands on high ownership individual contributor role responsible for Corporate IT and employee enablement SaaS application and access management Execution and monitoring of SOC 2 HIPAA and HITRUST compliance efforts You will be the primary owner of internal IT operations ...
1 week ago
Your primary area of responsibility will be to assist in supporting Coloplast's Acute Care businesses and to contribute to the overall development · and implementation of our Global Coloplast Group Business Ethics & Compliance program within our North America region. · We want t ...
1 week ago
This is a hands on high ownership individual contributor role responsible for corporate IT and employee enablement SaaS application and access management execution and monitoring of SOC 2 HIPAA and HITRUST compliance using Vanta You will be the primary owner of internal IT operat ...
1 week ago
We are dedicated to providing students with an exceptional education in growing healthcare fields; teaching them relevant, required skills for today and the future. As a team, we continually embrace our core values: · Passion: We love helping others succeed. · Excellence: We str ...
3 days ago
· Why You Should Work With Us: · Arizona College of Nursing is a rapidly growing, nursing school that transforms people's lives by preparing them for careers in nursing and improving communities through the care its graduates provide. As a leading nurse educator, Arizona College ...
2 days ago
Join us as a Privacy Risk Professional and play a pivotal role in strengthening our enterprise privacy and compliance efforts. · ...
1 week ago
At RapidScale, exceptional technology is powered by exceptional people. As a growing leader in secure, reliable managed cloud solutions, we help mid-market through enterprise organizations simplify IT and unleash innovation. With a broad portfolio spanning AWS, Azure, and Google, ...
1 day ago
The Product Development Security & Compliance Specialist supports HSI's product and DevOps teams in building and operating secure, · SaaS products.This role is hands-on and focused on control execution,evidence collection(documentation maintenance,and day-to-day coordination with ...
1 week ago
Job summary · As our Security Compliance Senior Analyst,you will be tasked with security compliance activities along with our journey. You are expected to take the initiative to assist us with several security compliance programs and certifications.About the RoleAssist in our sec ...
1 month ago
The Export Compliance Manager ensures adherence to export laws and regulations while collaborating with internal teams to enhance communication and development. · Maintain and continually develop the company's export compliance program. · Ensure that operations are conducted with ...
6 days ago
The Export Compliance Manager is responsible for ensuring adherence to all applicable U.S. export laws and regulations while collaborating with internal teams to support compliant, efficient, and profitable operations. · Bachelor's degree preferred or equivalent combination of ed ...
1 week ago
Join our global diversified pharmaceutical company enriching lives through our relentless drive to deliver better health outcomes to our patients. · ...
1 month ago
Rush Street Interactive (NYSE: RSI) is a market leader in online casino and sports betting currently operating real-money gaming with their brands We're building bridges between online social and land-based gaming businesses to create amazing integrated experiences that keep play ...
1 month ago
We're looking for a Compliance & Risk Program Manager to strengthen Spinwheel's governance foundation by building the programs, systems, and feedback loops that keep us compliant, resilient, and scalable. · Build and maintain Spinwheel's integrated compliance and risk management ...
1 week ago