Cybersecurity Compliance and Risk Manager

Booz Allen HamiltonNorth Chicago, IL
$61,900 - $141,000Hybrid

About The Position

The Cybersecurity Compliance and Risk Manager is a hybrid technical and compliance-focused role responsible for designing, implementing, and managing procedures that ensure database, software, and system‑level security across client infrastructures. This position blends hands‑on cybersecurity expertise with strategic risk management to safeguard enterprise environments against evolving threats. You will work both independently and collaboratively, applying functional cybersecurity knowledge to develop solutions for a wide range of moderately complex challenges. This role may also include mentoring junior team members and guiding clients through critical decisions in the security lifecycle.

Requirements

  • 3+ years of experience with DoW or Navy cybersecurity and Risk Management Framework (RMF)
  • 3+ years of experience with cyber vulnerability assessment, remediation, and mitigation tools, including ACAS, eMASS, and VRAM
  • 1+ years of experience working with DoW STIGs and SRGs
  • Experience implementing, documenting, assessing, and monitoring NIST SP 800-53 security controls, including drafting implementation or remediation statements and conducting ConMon activities
  • Secret clearance
  • HS diploma or GED
  • DoW 8140 Certification such as Security+ CE, CISM, CISSP, or SecurityX Certification

Nice To Haves

  • Experience as a Navy Qualified Validator (NQV) or Information System Security Engineer (ISSE)
  • Experience serving in a Navy Package Submitting Office (PSO)
  • Experience with Xacta, ESS, Altiris, and ServiceNow
  • Experience supporting the U.S. Navy’s training, education, or mission-critical systems
  • Knowledge of network architecture, firewalls, ports and protocols, TCP/IP, VLANs, VMware, and Cisco networking or switching devices
  • Bachelor’s degree in a technical field preferred; Master’s degree in a technical field a plus

Responsibilities

  • Lead RMF execution, including security control attribution, documentation, assessment, and authorization.
  • Implement and validate NIST SP 800‑53 security controls across enterprise systems.
  • Maintain continuous monitoring activities for system compliance and risk visibility.
  • Perform vulnerability assessments and risk analysis using DoW security tools such as ACAS, VRAM, and eMASS.
  • Apply and verify DoW Security Technical Implementation Guidelines (STIGs) and Security Readiness Guidelines (SRGs) across software, database, and network environments.
  • Manage enterprise POA&Ms to track and remediate security findings.
  • Collaborate with clients and SMEs to develop mitigation strategies and clearly communicate technical risks.
  • Provide guidance and mentorship to cybersecurity team members.

Benefits

  • health
  • life
  • disability
  • financial
  • retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service