Security Compliance Industry Specialist

Supermicro•San Jose, CA

About The Position

Supermicro is seeking a Security Compliance Industry Specialist to drive day-to-day federal compliance execution, security assurance, and audit readiness for SMCI Federal. Reporting to the Director of Federal Compliance, this high-impact, hands-on role ensures our advanced hardware platforms, manufacturing environments, and technical data adhere strictly to CMMC Level 2, NIST SP 800-171, DFARS cybersecurity reporting obligations, and ITAR compliance standards. This role acts as an independent compliance validator separate from technical implementation teams, providing critical execution capacity to safeguard and grow federal revenue across public sector, prime contractor, and government accounts.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related technical field.
  • 5+ years of hands-on experience in security risk management, compliance auditing, or technical GRC execution within a highly regulated environment.
  • Direct experience managing NIST SP 800-171, CMMC Level 2, DFARS (252.204-7012/7019/7020), and ITAR compliance frameworks.
  • Proven understanding of technical security controls including Identity and Access Management (IAM), access control matrices, audit logging, and data encryption.
  • Working familiarity with physical security control requirements (NIST SP 800-171 Physical Protection family) as they apply to a controlled facility.
  • Exceptional written skills for drafting SSPs, POA&Ms, technical control documents, and audit artifacts.

Nice To Haves

  • CISSP, CISA, CISM, CRISC, or CMMC Registered Practitioner (RP).
  • Experience supporting hardware manufacturers, server/data center infrastructure, or defense industrial base (DIB) suppliers.
  • Experience automating compliance evidence collection and utilizing ticketing/GRC tools (e.g., ServiceNow, Jira, or cloud-based GRC platforms).

Responsibilities

  • Complete and maintain NIST SP 800-171 self-assessment scoring and Supplier Performance Risk System (SPRS) submissions.
  • Own, manage, and update the System Security Plan (SSP) and Plan of Action & Milestones (POA&M), ensuring 100% of control gaps are tracked and closed against defined SLAs.
  • Maintain operational incident response readiness in compliance with DFARS 72-hour reporting requirements; lead annual incident response tabletop exercises and ensure rapid, accurate reporting of security events.
  • Validate that technical safeguarding controls delivered through GCC High and any SMCI-operated systems are correctly configured against NIST SP 800-171 requirements, confirming the platform's shared-responsibility boundary is properly understood and implemented rather than assumed.
  • Establish and administer Technology Control Plans (TCP) and technical access controls for controlled technical data.
  • Operate deemed-export prevention processes to restrict unauthorized access to controlled technical data across engineering, sales, and manufacturing operations.
  • Support the implementation and validation of physical protection controls (NIST SP 800-171 Physical Protection family) at the dedicated federal facility, including badge access, visitor management, and physical safeguarding of CUI.
  • Partner with Facilities and Security functions on control design for any space where CUI or ITAR-controlled technical data is discussed, stored, or processed.
  • Deliver a fully documented, “assessment-ready” posture ahead of third-party CMMC Level 2 certification audits.
  • Serve as an independent validator of technical security controls, ensuring separation of duties between the teams implementing controls and the function validating them.
  • Partner with cross-functional teams to drive and track 100% completion of mandatory CUI, ITAR, and insider-threat training programs across all in-scope personnel.
  • Support the broader insider threat program beyond training alone — including personnel access-lifecycle controls and a defined reporting channel — in partnership with HR and Security.
  • Maintain the compliance evidence repository and supporting asset inventory for the CUI environment, and support evaluation of GRC tooling to manage this at scale as the program matures.

Benefits

  • comprehensive benefits package
  • participation in bonus and equity award programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service