Compliance & Audit Support - Jr.

Koniag Government Services, LLCWashington, DC
Hybrid

About The Position

Koniag Data Solutions, a Koniag Government Services company, is seeking a motivated and detail-oriented Compliance & Audit Support Specialist (Jr) to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved. This role sits within the Information Security Division (ISD) and provides foundational compliance monitoring, audit facilitation, security documentation, and risk management support in service of the agency's Federal Information Security Modernization Act (FISMA) obligations, Risk Management Framework (RMF) program, and enterprise-wide cybersecurity compliance requirements. The ideal candidate is an early-career cybersecurity professional with a foundational understanding of federal information security policy, NIST security frameworks, and security documentation practices who is eager to develop deep technical expertise in a complex, mission-driven federal IT environment. This individual must be a motivated self-starter who demonstrates strong written communication skills, exceptional attention to detail, and the ability to manage competing priorities in a fast-paced compliance environment under the guidance of senior ISSOs and cybersecurity leadership. The Compliance & Audit Support Specialist (Jr) provides foundational support across a range of cybersecurity policy compliance, documentation, audit facilitation, and continuous monitoring activities under the direction of senior ISSOs, the Compliance & Audit Support Specialist (Mid), and cybersecurity program leadership. This individual assists in the development and maintenance of security documentation for assigned systems, supports the preparation and tracking of audit artifacts, contributes to FISMA reporting activities, and helps ensure that compliance-related tasks are executed accurately, on time, and in accordance with federal and agency requirements. This role offers significant professional development opportunities for an early-career cybersecurity professional seeking to build expertise in federal RMF compliance, NIST security frameworks, security documentation, and enterprise cybersecurity program support within a dynamic and mission-critical environment.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Business Administration, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
  • Minimum of 1–2 years of experience in information security, IT compliance, audit support, or a closely related field, including internship, academic project, or entry-level professional experience in a federal government IT environment or federal contractor setting.
  • Demonstrated foundational knowledge of the NIST Risk Management Framework (RMF) and NIST SP 800-53 security control families, obtained through coursework, certification study, or practical work experience.
  • Demonstrated ability to produce clear, well-organized, and professionally written technical documentation aligned to templates and style guides.
  • Ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and all required system access authorizations prior to performing work.
  • Strong written communication skills in English with the demonstrated ability to produce clear, concise, grammatically correct, and professionally formatted technical documentation aligned to provided templates and style guidance.
  • Foundational knowledge of the NIST Risk Management Framework (RMF), including the general purpose and structure of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and FISMA compliance requirements.
  • Strong organizational and time management skills with the demonstrated ability to track multiple concurrent documentation assignments, compliance deadlines, and audit support activities with a high degree of accuracy and attention to detail.
  • Ability to follow detailed procedural instructions, agency templates, and style guidelines to produce compliant and consistently formatted documentation outputs.
  • Demonstrated ability to review documents for completeness, formatting consistency, grammatical accuracy, and alignment to provided templates before submission.
  • Proficiency with Microsoft Office Suite, including Word, Excel, PowerPoint, and Adobe Acrobat Pro, for document creation, tracking, and formatting activities.
  • Familiarity with SharePoint for document management, repository organization, and team collaboration activities.
  • Strong interpersonal skills with the ability to coordinate effectively with system owners, program offices, auditors, and technical staff to collect required information, schedule meetings, and track outstanding items.
  • Knowledge of Section 508 accessibility compliance requirements as they apply to technical documentation and training materials.
  • Proficiency with Microsoft Teams and other enterprise collaboration tools for daily communication, meeting coordination, and document sharing.
  • Eagerness to learn, grow, and develop expertise in federal cybersecurity compliance, RMF, FISMA, and NIST security frameworks under the mentorship of senior compliance and ISSO staff.

Nice To Haves

  • Prior internship, co-op, or entry-level work experience supporting federal cybersecurity compliance, audit support, or RMF documentation activities in a federal agency or federal contractor environment.
  • Familiarity with a federal agency GRC tool for documentation management, POAM tracking, or continuous monitoring activities.
  • Exposure to federal audit processes, including artifact collection, audit facilitation support, or Inspector General or GAO audit coordination experience.
  • CompTIA Security+, CompTIA CySA+, (ISC)² Systems Security Certified Practitioner (SSCP), or equivalent entry-level cybersecurity certification demonstrating foundational information security knowledge.
  • Completion of CISA HVA Assessment 3.0 Training or demonstrated willingness to complete within the first 90 days of contract performance.
  • Familiarity with common federal GRC platforms used for RMF documentation, POAM management, and continuous monitoring tracking in federal agency environments.
  • Exposure to FISMA reporting processes, including quarterly metrics collection, CyberScope, or equivalent federal reporting mechanisms.
  • Basic familiarity with cloud security concepts and cloud computing service models (IaaS, PaaS, SaaS) as they relate to federal information system security categorization and controls applicability.
  • Exposure to FedRAMP program requirements and Continuous Monitoring (CONMON) activities, including familiarity with CSP reporting obligations and review processes.
  • Basic familiarity with vulnerability management concepts, including Common Vulnerability Scoring System (CVSS) scoring and the general POAM development process.
  • Familiarity with privacy compliance requirements, including the Privacy Act of 1974, Privacy Impact Assessments (PIAs), and Privacy Threshold Analyses (PTAs) as they relate to federal information system compliance.
  • Exposure to Controlled Unclassified Information (CUI) program requirements, including basic familiarity with CUI categories, marking requirements, and safeguarding standards.
  • Familiarity with the NIST Cybersecurity Framework (CSF) and its relationship to federal security control implementation and assessment activities.
  • Basic data organization and reporting skills using Microsoft Excel, including the ability to maintain tracking spreadsheets, pivot tables, and compliance status logs.
  • Experience with or exposure to cybersecurity awareness training content development or delivery in a federal or corporate environment.
  • Demonstrated academic or professional interest in federal cybersecurity policy, information assurance, or privacy compliance through coursework, certifications, research, or professional development activities.

Responsibilities

  • Assist senior ISSOs and compliance staff in the creation, updating, revision, and maintenance of cybersecurity and privacy documentation for assigned systems and programs, ensuring all documentation aligns to applicable agency implementation procedures and templates.
  • Support the development and maintenance of System Security Plans (SSPs) and supporting annexes, Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs), E-authentication Risk Assessments (ERAs), User recertification documentation, and Architecture, topology, and data flow diagrams under senior staff direction.
  • Review draft documentation for completeness, formatting consistency, grammar, and alignment to agency templates prior to submission, ensuring deliverables are peer-reviewed and meet quality standards before Government submission.
  • Track document review cycles, revision requests, and submission deadlines across all assigned documentation, ensuring Government comments are addressed within 10 business days of receipt and that stakeholder unresponsiveness is escalated to the Government POC after 10 business days without response.
  • Assist with uploading and maintaining assigned documents in the agency's Governance, Risk, and Compliance (GRC) tool, ensuring records are current, complete, and properly organized.
  • Support the preparation of selected policy and procedure documents in both Adobe and Word formats, assisting with Section 508 accessibility remediation as directed by senior staff and the COR.
  • Provide foundational support for security and privacy controls assessment activities under senior staff direction, including assistance with artifact collection, evidence gathering, stakeholder coordination, and documentation of NIST SP 800-53A Determine If Statements (DISs).
  • Assist with the preparation of draft Security and Risk Assessment Plans (SAPs), Security and Risk Assessment Reports (SARs), Annual Assessment Reports (AARs), and Plans of Action and Milestones (POAMs) by gathering required information, organizing artifacts, and formatting documents in accordance with agency templates.
  • Support sampling strategy coordination for technical control assessments, including scheduling with system administrators and stakeholders, collecting assessment evidence, and organizing evidence packages for review by senior assessment staff.
  • Assist with mapping identified vulnerabilities to applicable NIST SP 800-53 controls and control families in support of SAR and POAM development activities.
  • Track open assessment deliverables and Government comment cycles, ensuring revision timelines are monitored and escalated as needed to maintain compliance with established submission schedules.
  • Assist in the collection, compilation, and initial validation of FISMA reporting metrics for assigned systems and programs, supporting senior staff in the development of consolidated metrics reports that are accurate and representative of the agency's FISMA inventory.
  • Support data entry and formatting activities for quarterly FISMA metrics reports, ensuring data is organized, labeled, and formatted in accordance with agency requirements and federal CIO reporting standards.
  • Assist with the maintenance of FISMA metrics tracking spreadsheets, dashboards, and data visualization inputs, ensuring data sources are current and accessible for quarterly and ad hoc reporting activities.
  • Support ad hoc or interim FISMA data collection and reporting requests within established timelines as directed by the COR or senior compliance staff.
  • Provide logistical and administrative support for internal and external audit activities affecting assigned FISMA systems, including coordination of audit meeting schedules, preparation of artifact packages, and organization of evidence in response to auditor requests.
  • Assist senior staff with the facilitation of audit walkthroughs by preparing briefing materials, organizing system documentation, and ensuring required artifacts are accessible and pre-reviewed prior to auditor meetings.
  • Track outstanding audit artifact requests, submission deadlines, and auditor follow-up items, maintaining a current status log and escalating delays or issues to senior staff and the Government POC promptly.
  • Assist in collecting SOC reports from program offices for audit purposes, following up on outstanding items and tracking receipt status in the compliance tracking log.
  • Review audit artifact packages for completeness, accuracy, and formatting consistency prior to submission, ensuring deliverables minimize repeated requests from auditors.
  • Assist with knowledge management activities for accreditation artifacts, supporting the organization and maintenance of appointment orders, ATO documentation, Acceptance of Risk (AOR) documents, Memoranda of Understanding/Agreement, and Data Sharing Agreements in the designated central repository.
  • Monitor AOR and accreditation document expiration tracking logs, flagging documents approaching expiration at least 90 days in advance and notifying senior staff to initiate renewal processes.
  • Support responses to customer requests for accreditation documentation or guidance by locating and preparing requested artifacts within the required two business day response window.
  • Assist with SharePoint or GRC-based central repository organization, ensuring documents are properly named, version-controlled, and accessible to authorized stakeholders.
  • Assist senior compliance staff with the development, formatting, and maintenance of POAM entries in the agency GRC tool, ensuring all required data fields are accurately completed and consistently formatted.
  • Track open POAM items across assigned systems, monitoring milestone due dates, remediation status updates, and scheduled completion dates, and notifying senior staff of approaching deadlines or delayed items.
  • Assist with compiling and formatting monthly POAM status reports for Government review, ensuring data is accurate, current, and aligned to agency reporting templates.
  • Support the coordination of POAM remediation evidence collection from system owners and technical teams, organizing evidence packages for senior staff review and GRC tool upload.
  • Provide administrative and documentation support for OA activities on assigned systems, including formatting and organizing OA Playbook drafts, test result documentation, and GRC tool entries under senior staff direction.
  • Assist with scheduling and coordinating OA Positive and Negative Testing activities, including outreach to system administrators, penetration testing resources, and other stakeholders required to support testing execution.
  • Support the compilation and formatting of monthly OA Positive Testing results for GRC tool entry, ensuring documentation is organized, consistently formatted, and submitted within established timelines.
  • Assist senior compliance staff with the monthly update and maintenance of cybersecurity and privacy risk registers for assigned systems, ensuring entries are accurately documented and formatted for Government review.
  • Support the development of risk register visualizations and data inputs, contributing to the organization and formatting of monthly ERM deliverables for online visualization and internal web portal publication.
  • Assist with data compilation and formatting activities in support of ERM Risk Register inputs and ERM Board meeting materials as directed by senior staff.
  • Assist with the maintenance and periodic updating of the agency HVA inventory list, supporting data collection, formatting, and submission activities under senior staff direction.
  • Support tracking of HVA remediation plan milestones and timelines, maintaining a current status log and notifying senior staff of approaching deadlines or overdue items.
  • Complete CISA HVA Assessment 3.0 Training within the first 90 days of contract performance and provide course completion certificate to the designated Government POC.
  • Assist with logistical preparation for monthly FedRAMP CONMON meetings, including scheduling, agenda preparation, meeting minutes documentation, and action item tracking.
  • Support senior staff in the review of CSP-submitted vulnerability, penetration test, and ad hoc reporting by organizing submitted materials, tracking receipt and review status, and maintaining a current CONMON activity log.
  • Assist with tracking and following up on outstanding CONMON tasks and deliverables, ensuring all items due back to vendors are completed within the required five business day timeframe.
  • Provide administrative and content development support for cybersecurity and privacy awareness training initiatives, including research, content drafting, formatting, and coordination assistance under senior staff direction.
  • Assist with tracking training development timelines, Government review cycles, and revision deadlines, ensuring all milestones are monitored and escalated as needed.
  • Support the coordination of training delivery activities, including scheduling, logistics, and tracking of completion records across program offices as directed.
  • Complete all required annual cybersecurity awareness training within established deadlines and maintain all required certifications as current and unexpired throughout the period of performance.
  • Ensure all work products are Section 508 accessibility compliant where required, government-owned, and free of proprietary or company-specific markings or restrictions.
  • Adhere to all applicable Federal security, privacy, and compliance requirements, including FISMA, NIST SP 800-53, OMB Circular A-130, and agency-specific cybersecurity policies, in the performance of all assigned duties.

Benefits

  • health, dental and vision insurance
  • 401K with company matching
  • flexible spending accounts
  • paid holidays
  • three weeks paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service