Senior Security Compliance Specialist

Fortem TechnologiesLindon, UT

About The Position

We are seeking an experienced IT Security Compliance Specialist to lead our organization's implementation, certification, and ongoing maintenance of Cybersecurity Maturity Model Certification (CMMC) Level 2 controls. This role owns the technical and administrative work required to protect Controlled Unclassified Information (CUI) in accordance with NIST SP 800-171, prepare the organization for its C3PAO assessment, and sustain continuous compliance across the contract lifecycle. The ideal candidate combines hands-on IT/security engineering skills with a strong understanding of DFARS 252.204-7012, CMMC assessment methodology, and federal contracting security requirements.

Requirements

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or equivalent experience.
  • 3–5+ years of IT security/compliance experience, including direct experience with NIST SP 800-171, NIST SP 800-53, or CMMC frameworks.
  • Working knowledge of DFARS 252.204-7012, FAR 52.204-21, and CUI handling requirements.
  • Experience with Microsoft 365 GCC High, Azure Government, AWS GovCloud, or similar CUI-capable environments strongly preferred.
  • Hands-on proficiency with core security tooling: MFA, EDR/antivirus, SIEM, vulnerability scanning, and patch management.
  • Strong documentation and technical writing skills with high attention to detail; comfortable sustaining long-term, documentation-intensive compliance work.
  • Analytical and solution-oriented; able to translate complex compliance requirements into actionable technical controls.
  • Clear communicator capable of presenting technical and compliance concepts to non-technical stakeholders and senior leadership.
  • Self-directed and organized; able to independently manage a long-term compliance program while balancing competing contract-driven deadlines.

Nice To Haves

  • Prior role supporting a Defense Industrial Base (DIB) contractor through a CMMC Level 2 certification.
  • Experience working with a C3PAO or RPO during a formal assessment.
  • Familiarity with NIST SP 800-171A assessment procedures.

Responsibilities

  • Designing, deploying, and managing the technical backbone of the compliance program.
  • Design, configure, and implement technical controls across access control, audit/accountability, configuration management, identification/authentication, incident response, media protection, physical security, risk assessment, system/communications protection, and system/information integrity domains.
  • Deploy and manage supporting technologies: MFA, endpoint detection and response (EDR), SIEM/log management, data loss prevention, encryption (at rest and in transit), privileged access management, and network segmentation/enclaving for CUI.
  • Maintaining the compliance ecosystem required to demonstrate and sustain compliance and staying current with evolving requirements.
  • Maintain the System Security Plan (SSP), Plan of Action and Milestones (POA&M), Network/Data Flow Diagrams, and control implementation evidence.
  • Author and maintain required policies and procedures (Incident Response Plan, Access Control Policy, Configuration Management Plan, etc.) mapped to each control family.
  • Maintain a centralized compliance evidence repository sufficient to support a C3PAO assessment.
  • Manage recurring compliance activities: annual affirmations, periodic risk assessments, vulnerability scanning/patching cadence, access reviews, and audit log reviews.
  • Establish a continuous monitoring program to track control effectiveness, configuration drift, and emerging vulnerabilities; track and remediate assessment findings within required timeframes.
  • Serve as the primary technical point of contact during the CMMC Level 2 Certification Assessment (C3PAO) or Self-Assessment, as applicable.
  • Coordinate with external assessors, consultants, and Registered Practitioner Organizations (RPOs) as needed.
  • Maintain compliance through system changes, new vendor/subcontractor relationships (flow-down requirements), and IT infrastructure updates.
  • Monitor changes to CMMC/DFARS/NIST 800-171 requirements and update the compliance program accordingly.
  • Develop and deliver security awareness and role-based training required under CMMC.
  • Partner with HR/Legal on insider threat and personnel security requirements tied to CUI access.
  • Partner with Procurement/IT vendors to ensure third-party services (cloud, MSP, SaaS) meet CMMC/FedRAMP requirements.
  • Other duties as required and assigned in line with IT Security Compliance Requirements
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service