Security Compliance SME

The Squires GroupWashington, DC
Hybrid

About The Position

TSGi is seeking a Security Compliance SME to support a large-scale federal travel and expense modernization initiative serving civilian government agencies. This role will lead security compliance, assessment and authorization (A&A), and continuous monitoring activities within a highly regulated federal environment. The ideal candidate will possess deep expertise in FedRAMP and FISMA compliance, NIST security controls, and federal authorization processes, while serving as a key liaison among engineering teams, assessors, and Authorizing Officials (AOs). Candidates local to Herndon, VA are preferred and will be expected to work onsite four (4) days per week. Fully remote candidates will also be considered; however, West Coast candidates will not be considered. Per our Federal government contract, candidates must be U.S. Citizens able to obtain a Public Trust Clearance.

Requirements

  • 5+ years leading A&A efforts for FedRAMP or FISMA Moderate systems through authorization and continuous monitoring.
  • Demonstrated experience managing FedRAMP significant change requests, including coordination with 3PAOs, evidence collection, test support, and SAR remediation activities.
  • Expert knowledge of NIST SP 800-53 Rev. 5 Moderate controls and security control implementation documentation.
  • Experience conducting security impact analyses and advising Authorizing Officials on risk and compliance decisions.
  • Experience managing POA&Ms, deviation requests, and monthly Continuous Monitoring (ConMon) reporting.
  • Working knowledge of UiPath sufficient to document automation workflows, credential usage, and data flows from a compliance perspective.
  • Experience with eMASS administration and federal authorization processes.
  • Strong technical writing skills with the ability to create documentation for assessors, auditors, and government stakeholders.
  • Excellent analytical, organizational, and communication skills.
  • U.S. Citizens able to obtain a Public Trust Clearance.

Responsibilities

  • Lead Authority to Operate (ATO) and Authority to Connect (ATC) activities for federal systems.
  • Manage continuous monitoring, compliance reporting, and security assessment activities.
  • Develop, maintain, and update security documentation, including SSPs, POA&Ms, Contingency Plans, and Incident Response Plans.
  • Perform security impact analyses and provide risk-based recommendations for system changes.
  • Manage eMASS entries, package submissions, and authorization artifacts.
  • Coordinate with assessors, stakeholders, and engineering teams to support audits, assessments, and security reviews.
  • Oversee vulnerability management activities, including ACAS scanning and remediation tracking.

Benefits

  • paid time off (PTO)
  • medical
  • dental
  • vision coverage
  • life insurance
  • long-term disability insurance
  • a 401(k) plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service