Security/Compliance SME
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security/compliance SME advancing Department of the Air Force ICAM capabilities for Koniag Government Services. Aligning Zero Trust architectures, ATO processes, and governance studies with DoD policy.
Responsibilities:
- Serve as the authoritative policy and compliance reference across three System Enhancement Studies
- Review and interpret Government-Furnished Information and applicable DoD, DAF, and Federal regulatory references
- Provide security and compliance guidance for CDO-L edge identity architecture, disconnected operations, break-glass access, PKI certificate validation, and synchronization methods
- Assess security posture management requirements for CDO-L edge node operations
- Evaluate and document Authority to Operate implications for classified NIPRNet and SIPRNet edge components
- Provide security and compliance guidance for NPE attribute schemas, governance workflows, credential management policies, and target architecture
- Review and validate NPE credential management governance, including credential rotation, secret vault storage, and hardcoded credential controls
- Assess Zero Trust Architecture alignment of NPE governance, workload identity, dynamic access control, and continuous authentication
- Define compliance requirements for NPE audit logging and monitoring, including SOC and ELICSAR integration and UEBA/AI-driven anomaly detection
- Guide JML transformation architecture, attribute sanitization, Microsoft Entra ID integration, event-driven group management, and administrator delegation
- Review and validate Leaver revocation architecture, including mailbox handling, DAF365 license reclamation, Entra ID token revocation, and Okta disablement sequencing
- Assess delegated provisioning against least-privilege, separation-of-duties, and audit-trail requirements
- Conduct cross-study compliance gap analysis and identify required controls, waivers, or ATO actions
- Contribute security and compliance sections and regulatory mappings to three Technical Study Reports
- Advise the Program Manager and Study Lead Engineers on emerging DoD and DAF cybersecurity policy developments
- Support draft Performance Work Statements for subsequent implementation Task Orders
- Verify assigned personnel hold required security clearances and notify the Government of status changes
Requirements:
- Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Systems, or a related field from an accredited college or university
- 7+ years of experience in cybersecurity, information assurance, or security compliance in Defense or Federal government IT environments
- Demonstrated experience interpreting and applying DoD and Federal cybersecurity policy frameworks including NIST SP 800-53, NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, and related mandates to enterprise IT system design and governance
- Experience supporting Authority to Operate (ATO) processes for Defense information systems, including RMF package development, security control assessment, and accreditation timeline management
- Active Secret security clearance, with final adjudication required prior to assignment
- Deep knowledge of DoD and Federal cybersecurity and identity management policy frameworks
- Strong understanding of Zero Trust Architecture principles and application to enterprise ICAM systems, disconnected edge environments, non-person entity governance, and identity lifecycle management
- Experience with DoD Risk Management Framework (RMF) and Authority to Operate (ATO) processes
- Knowledge of PKI-based authentication, certificate lifecycle management, DoD/DoW X.509 Certificate Policy, and Common Access Card (CAC) authentication security requirements
- Familiarity with Okta and SailPoint IdentityIQ
- Knowledge of DoD audit standards and log management requirements, including CJCSI 6510.01 and SIEM/SOC integration
- Experience performing compliance gap analysis and documenting findings in formal technical reports
- Ability to interpret and apply complex, conflicting regulatory requirements
- Experience advising technical engineers and architects on security and compliance requirements
- Strong technical writing skills for compliance assessments, regulatory mapping, technical study reports, and draft Performance Work Statements
- Ability to work collaboratively across cross-functional technical teams
- Exceptional written and oral communication skills in English
- Ability to obtain and maintain a Secret security clearance
Benefits:
- Medical, dental, and vision insurance
- 401(k) retirement plan
- Paid time off
- Paid parental leave
- Life and disability insurance
- Flexible spending accounts
- Commuter benefits
- Tuition reimbursement

















