Compliance & Audit Support (Mid)

Koniag Government Services, LLCWashington, DC
$105,000 - $135,000Hybrid

About The Position

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Compliance & Audit Support Specialist (Mid) to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency in Washington, DC. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved. This role sits within the Information Security Division (ISD) and provides critical compliance monitoring, audit facilitation, documentation support, and risk management services in support of the agency's Federal Information Security Modernization Act (FISMA) obligations, Risk Management Framework (RMF) program, and enterprise-wide cybersecurity and privacy compliance requirements. The ideal candidate is a detail-oriented and analytically driven cybersecurity compliance professional with a strong foundation in federal information security policy, NIST security frameworks, security controls documentation, and audit support methodologies. This individual must possess the ability to manage multiple concurrent compliance activities across a complex, multi-system federal IT environment, produce high-quality technical documentation aligned to agency standards, and effectively coordinate with system owners, program offices, auditors, and senior Government stakeholders. The Compliance & Audit Support Specialist (Mid) is responsible for providing comprehensive cybersecurity policy compliance support, security controls documentation, audit facilitation, FISMA reporting, and enterprise risk management support across an assigned portfolio of federal information systems and programs. This individual works closely with ISSOs, system owners, program offices, cybersecurity leadership, and external auditors to ensure that all assigned systems maintain current, accurate, and compliant security documentation, that audit activities are executed smoothly and efficiently, and that the agency's cybersecurity compliance posture is continuously monitored, measured, and reported in accordance with federal and agency requirements.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Business Administration, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
  • Minimum of 3 years of experience in information security compliance, security documentation, or audit support in a federal government IT environment.
  • Demonstrated experience developing and maintaining cybersecurity compliance documentation—including SSPs, CMPs, ISCPs, SARs, and POAMs—in accordance with NIST RMF requirements and agency templates.
  • Demonstrated experience supporting federal security control assessments, including familiarity with NIST SP 800-53 control families and NIST SP 800-53A assessment methodologies.
  • Experience supporting federal audit activities, including artifact collection, coordination with auditors, and facilitation of audit walkthroughs.
  • Ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and all required system access authorizations prior to performing work.
  • Exceptional communication skills in English—both written and oral—with the demonstrated ability to produce clear, concise, thorough, and professionally written technical documentation aligned to agency templates, implementation procedures, and Section 508 accessibility standards.
  • Solid knowledge of the NIST Risk Management Framework (RMF), including NIST SP 800-37 Rev 2, NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, NIST SP 800-30 Rev 1, and NIST SP 800-137.
  • Working knowledge of federal information security law, policy, and standards, including FISMA, FIPS 199, FIPS 200, OMB Circular A-130, HSPD-12, and applicable OMB memoranda.
  • Demonstrated ability to write detailed, technology-specific security control implementation descriptions covering all technology types within a system boundary, avoiding high-level summary statements and clearly explaining specific implementation mechanisms.
  • Experience conducting or supporting security controls assessments across multi-technology environments, including the application of appropriate sampling strategies across in-scope devices, users, and services.
  • Familiarity with enterprise GRC platforms for documentation management, continuous monitoring tracking, POAM management, and FISMA metrics reporting.
  • Strong organizational skills with the ability to manage multiple concurrent documentation assignments, compliance deadlines, and audit support activities simultaneously with a high degree of accuracy and attention to detail.
  • Ability to track and manage document expiration timelines—including ATO and AOR expiration dates—proactively initiating renewal processes well in advance of deadlines.
  • Familiarity with SharePoint for document management, central repository maintenance, and artifact organization in a federal compliance environment.
  • Knowledge of Section 508 accessibility compliance requirements as applied to technical documentation, training materials, and reporting deliverables.
  • Proficiency with Microsoft Office Suite, including Word, Excel, PowerPoint, and Adobe Acrobat Pro, and enterprise collaboration tools such as Microsoft Teams.

Nice To Haves

  • Prior experience supporting federal civilian agency cybersecurity compliance programs within an ISD or OCIO environment.
  • Experience working with a federal agency GRC tool for documentation management, continuous monitoring tracking, and POAM management.
  • Familiarity with FISMA reporting processes, including quarterly metrics collection and CyberScope submission procedures.
  • Experience supporting Ongoing Authorization (OA) programs or FedRAMP Continuous Monitoring activities.
  • CompTIA Security+, (ISC)² Systems Security Certified Practitioner (SSCP), Certified Information Systems Security Professional (CISSP), or equivalent cybersecurity certification meeting Federal IAM or IAT level requirements.
  • ISACA Certified in Risk and Information Systems Control (CRISC) or equivalent risk management certification.
  • Experience with the Factor Analysis of Information Risk (FAIR) methodology for quantitative cybersecurity risk assessment and ERM risk register development.
  • Experience supporting Ongoing Authorization (OA) programs, including contributing to OA Playbook development and supporting positive and negative testing activities.
  • Experience supporting FedRAMP Continuous Monitoring activities, including facilitation of monthly CONMON meetings and review of CSP-submitted vulnerability and penetration test reports.
  • Familiarity with High Value Asset (HVA) assessment requirements, including CISA HVA 3.0 assessment framework and BOD 18-02 compliance activities.
  • Experience with CyberScope for federal FISMA metrics submission and quarterly reporting activities.
  • Familiarity with enterprise cybersecurity tools used in federal environments, including Tenable Nessus/Security Center, Microsoft Sentinel, Microsoft Defender for Endpoint, Microsoft Purview, and ServiceNow.
  • Experience developing and contributing to cybersecurity awareness training content in SCORM format for delivery via an agency Learning Management System (LMS).
  • Knowledge of Privacy Act requirements, Privacy Impact Assessment (PIA) development, Privacy Threshold Analysis (PTA), and System of Records Notice (SORN) processes as they relate to cybersecurity compliance activities.
  • Experience with automated dashboard development and data visualization tools (e.g., Power BI, Excel pivot tables) in support of FISMA reporting and continuous monitoring activities.
  • Familiarity with Common Vulnerability Scoring System (CVSS) and vulnerability-to-control mapping methodologies for POAM development and risk prioritization.
  • Experience supporting multi-system FISMA portfolios including a mix of on-premises, IaaS, PaaS, and SaaS implementation models.
  • Familiarity with the NIST Cybersecurity Framework (CSF) and its application to assessment report visualization and security posture reporting.

Responsibilities

  • Create, update, revise, and maintain cybersecurity and privacy documentation for assigned systems and programs across the enterprise, ensuring all documentation aligns to applicable agency implementation procedures and is reviewed for acceptance by the Office of the CIO.
  • Develop and maintain the following documentation types, among others: Cybersecurity and Privacy Policies and Procedures, System Security Plans (SSPs) with detailed, technology-specific control implementation descriptions, Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs), E-authentication Risk Assessments (ERAs), User recertification documentation, Architecture, topology, and data flow diagrams (OV-1 and SV-1 equivalent).
  • Ensure all control implementation descriptions are written to the level of detail required by agency implementation procedures, clearly explaining how each control is specifically implemented across all technologies within the system boundary, and avoiding high-level generalizations or simple restatement of NIST control language.
  • Deliver all documentation on or before agency-defined completion dates, addressing all Government comments, edits, and questions within 10 business days of receipt, and escalating stakeholder unresponsiveness to the Government POC after 10 business days without response.
  • Ensure selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as directed by the COR.
  • Maintain and update all assigned documents in the agency's Governance, Risk, and Compliance (GRC) tool, ensuring records are current, complete, and accessible.
  • Provide security and privacy controls assessment support for assigned systems, including assistance with testing and validation of NIST SP 800-53 controls, documentation of NIST SP 800-53A Determine If Statements (DISs), and mapping of vulnerabilities to applicable controls and control families.
  • Support the development of draft Security and Risk Assessment Plans (SAPs), Security and Risk Assessment Reports (SARs), Annual Assessment Reports (AARs), and Plans of Action and Milestones (POAMs) in accordance with established agency timelines and deliverable requirements.
  • Assist with technical control assessments across multiple technology types within assigned system boundaries (e.g., Windows, UNIX/Linux, network devices, web applications, cloud platforms), supporting sampling strategies across in-scope devices, users, and services.
  • Ensure all assessment reports are comprehensive to the scope identified in the SAP, 100% aligned to the GRC tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission.
  • Incorporate all Government feedback into revised assessment deliverables within 5 business days of receipt of comments.
  • Collect, compile, validate, and contribute to FISMA reporting metrics for assigned systems and programs, supporting the development of consolidated metrics reports that are accurate, mathematically verified, and representative of the total agency FISMA inventory.
  • Assist in the development and maintenance of dynamically updatable FISMA metrics visualizations and dashboards, contributing data and narrative content aligned to federal CIO metrics requirements.
  • Support quarterly FISMA reporting activities, ensuring consolidated reports are delivered for Government review not later than 10 business days prior to submission due dates, and supporting entry of approved metrics into the CyberScope tool as directed.
  • Respond to ad hoc or interim FISMA reporting requests within established timelines as directed by the COR.
  • Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors, ensuring all audit activities are executed smoothly, on schedule, and in accordance with auditors' requirements.
  • Facilitate audit meetings and walkthroughs of key cybersecurity capabilities, coordinating with relevant support personnel, supplying auditors with requested artifacts and examples, and responding to auditor follow-up questions within established timeframes.
  • Ensure all audit artifacts are delivered on time, pre-reviewed by the Government, and of sufficient quality and completeness to minimize repeated requests from auditors.
  • Communicate any issues or problems encountered during audit support activities to the Government POC immediately upon discovery.
  • Ensure SOC reports are received from program offices for audit purposes as required, tracking outstanding items and escalating delays proactively.
  • Provide knowledge management services for all information required to perform accreditation services, maintaining all required artifacts and documentation—including appointment orders, ATO documentation, Acceptance of Risk (AOR) documents, Memoranda of Understanding/Agreement, and Data Sharing Agreements—in a centrally organized and accessible repository.
  • Monitor all active AOR expiration dates and initiate resubmission processes at least 90 days prior to expiration, ensuring no AOR lapses without renewal or COR notification.
  • Respond to customer requests for documentation or guidance within two business days, ensuring all requests are addressed accurately and completely.
  • Maintain the SharePoint-based or GRC-based central repository for accreditation artifacts, ensuring documentation is properly organized, version-controlled, and accessible to authorized stakeholders.
  • Assist ISSOs with the development and submission of OA Playbooks for systems approved for Ongoing Authorization, documenting testing methodologies for each OA core control in accordance with agency implementation procedures.
  • Support the monthly execution and documentation of OA Positive Testing results in the agency GRC tool, ensuring testing is conducted comprehensively across the technology stack of each target system.
  • Support the annual execution and documentation of OA Negative Testing, coordinating with penetration testing resources as necessary and ensuring results are documented in detail within the GRC tool.
  • Ensure all OA test results are peer-reviewed for accuracy and consistency prior to submission, incorporating Government corrections within approximately five business days of receipt.
  • Assist in maintaining cybersecurity and privacy risk registers for assigned systems, ensuring registers are updated monthly and available via online visualization and internal web portal.
  • Support the application of the Factor Analysis of Information Risk (FAIR) methodology to assist in quantifying risk for assigned systems and programs, and contribute to the integration of cybersecurity and privacy risks into the agency ERM Risk Register as directed.
  • Evaluate and document major risks related to cybersecurity, privacy, information theft, and sensitive information protection for assigned systems, collaborating on the development of risk register entries with associated controls, planned mitigations, and risk quantification data.
  • Contribute risk register inputs and supporting artifacts to monthly ERM deliverables on time and in a format suitable for Government review.
  • Support the development, maintenance, and regular updating of the agency HVA inventory list, ensuring HVA activities are incorporated into broader IT and information security management planning activities including change management and Information Security Continuous Monitoring (ISCM) strategy.
  • Assist with the identification, categorization, and prioritization of HVAs, the implementation and validation of required security controls, and the development and tracking of HVA remediation plans in accordance with established milestones and timelines.
  • Support the completion of CISA HVA Assessment 3.0 training requirements and contribute to annual HVA reported metrics, ensuring deliverables are accurate and submitted for Government review not later than 10 business days prior to due dates.
  • Support the facilitation of monthly FedRAMP CONMON meetings with applicable stakeholders for assigned systems, maintaining sufficient understanding of each system to assist with guidance and comments to Cloud Service Providers (CSPs).
  • Assist with the review of vulnerability, penetration test, and ad hoc reporting submitted by CSPs, flagging potential security risks and supporting the review and approval of major change requests in accordance with established procedures.
  • Ensure all tasks and deliverables from the agency back to the vendor are facilitated within five business days.
  • Support the development of cybersecurity and privacy awareness training content, including annual, role-based, and condition-based training courses, in accordance with agency requirements and the Shareable Content Object Reference Model (SCORM) format.
  • Assist with updating training course content and underlying code annually, ensuring all courses are delivered to the Government for review within 30 business days of request and that all Government comments are addressed within five business days of receipt.
  • Support the delivery of cybersecurity awareness training via digital media, printed media, email notices, and instructor-led or self-paced formats as directed.
  • Ensure all compliance and audit support activities comply with applicable Federal security requirements, including FISMA, NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, NIST SP 800-37 Rev 2, FIPS 199, FIPS 200, OMB Circular A-130, and all referenced agency policies and implementation procedures.
  • Comply with annual cybersecurity awareness training requirements and maintain all required certifications as current and unexpired throughout the period of performance.
  • Ensure all work products are Section 508 accessibility compliant where required, government-owned, and free of proprietary or company-specific markings or restrictions.

Benefits

  • health, dental and vision insurance
  • 401K with company matching
  • flexible spending accounts
  • paid holidays
  • three weeks paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service