LEAD COMPLIANCE SPECIALIST

Emagine IT•Rockville, MD
•$180,000 - $250,000•Remote

About The Position

Emagine IT is seeking a Lead Compliance Specialist to lead the compliance and privacy workstream of the Government's cybersecurity program. As designated Key Personnel, this role leads Security Assessment and Authorization under the NIST Risk Management Framework across approximately 30 FISMA systems, owns FISMA reporting and audit support, and serves as the privacy subject matter expert supporting the Senior Official for Privacy. The Lead Compliance Specialist directs a team of Compliance Specialists and Compliance and Privacy Specialists and is the program's authority on federal and Department security and privacy policy. Consistent with the CIO-SP3 IT Policy/Legislative Specialist labor category, the role assists in interpreting and implementing IT public policy initiatives, supports long-term strategy development, tracks legislation, and makes policy recommendations.

Requirements

  • Certification: One of CISSP, CAP, Security+, CISM, GSEC, or an equivalent certification meeting DoD 8570 IAT Level II or higher standards. Equivalents must be approved by the COR.
  • Experience: Minimum 5 years of cybersecurity experience and a solid understanding of FISMA, NIST, and federal privacy laws (e.g., Privacy Act of 1974, HIPAA).
  • SA&A and privacy: Experience leading SA&A activities using the NIST RMF in compliance with FISMA, and experience processing PIAs and SORNs.
  • Clearance & citizenship: U.S. citizen or lawful permanent resident. Ability to obtain and maintain a Public Trust suitability determination (tier to be confirmed with the Government), obtain a Government PIV card, and sign the Government Contractor Non-Disclosure Agreement and Government Rules of Behavior before receiving access to Government systems or data. Must complete Government security awareness, privacy, and records management training before performing work and annually thereafter.

Nice To Haves

  • Baltimore Cyber Range (BCR) Cybersecurity Technical Proficiency (PWS-preferred).
  • Bachelor's degree in Cybersecurity, Information Systems, or a related field.
  • Experience with an enterprise GRC platform such as RSA Archer, Xacta, RegScale, or ServiceNow IRM.
  • Experience with federal civilian agency FISMA reporting and Zero Trust scorecards.
  • Familiarity with 42 CFR Part 2 and OSCAL-based compliance automation.

Responsibilities

  • Assist in interpreting and implementing federal IT and cybersecurity public policy initiatives, including long-term strategy development, tracking legislation and mandates (FISMA, executive orders, OMB memoranda), and making policy recommendations.
  • Meet with the Government client, often on a daily basis, to relay progress and establish priorities for compliance and privacy work.
  • Develop and deliver the Information Security Program Plan, NIST Cybersecurity Framework Implementation Plan, and Risk Management Framework documentation within 30 days of award; review and update annually.
  • Own the rolling ATO governance calendar and lead SA&A for new and existing systems: FIPS-199 categorization 5 business days before assessment start, control selection and tailoring, test plans, and SSP/SAR packages within 14 days of assessment completion.
  • Brief system owners, the CISO, and the Authorizing Official on non-compliant controls and corrective actions; deliver Authorization Package Briefings and the quarterly RMF/ATO Optimization Report.
  • Compile monthly, quarterly, and annual FISMA reports for the Department; maintain the system inventory and POA&Ms in the agency GRC tool; brief the COR and CISO 5 business days before Department due dates.
  • Lead responses to Department, CISA BOD/ED, GAO, OIG, and other data calls and audits; maintain the master Cybersecurity Compliance Matrix.
  • Provide privacy expertise to the Senior Official for Privacy: PTA/PIA/SORN governance, PII system inventory, 3-year PIA reviews, Privacy Act clearance reviews, and 42 CFR Part 2 considerations.
  • Analyze new federal, Department, and agency policy; develop recommendations; and manage annual review of IT security policies and procedures within 11 months of last approval.
  • Operate the agency GRC tool (RSA Archer today) and lead deployment of any Government-designated successor GRC suite, including configuration, testing, user documentation, and training.
  • Oversee supply chain risk management per NIST SP 800-161 Rev 2, including the Supply Chain Risk Inventory and vendor secure-software attestations.
  • Supervise, mentor, and quality-review the work of Compliance Specialists and Compliance and Privacy Specialists.

Benefits

  • medical, dental, and vision insurance
  • a 401(k) with company match
  • paid time off and holidays
  • professional development and certification support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service