FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in security compliance, including authoring and maintaining System Security Plans (SSPs) aligned to NIST standards, managing POA&Ms, and coordinating evidence collection for audits. Proven ability to build and maintain compliance documentation and policies while collaborating with technical teams in cloud environments.
Highest-signal resume keywords
System Security Plans (SSPs)NIST 800-171 CompliancePOA&M ManagementAWS Cloud SecurityAuditor Communication
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security ComplianceGRCCybersecurity PolicyATO SupportEvidence CollectionControl FrameworksArchitecture Diagram InterpretationInfrastructure-as-CodePolicy Library ManagementCMMC Readiness
Soft Skills
Attention to DetailWritten Communication
Tools & Technologies
AWSEKSIAMLoggingEncryption
Certifications & Qualifications
CMMC Level 2FedRAMPDoD ATO
Industry Keywords
Compliance PostureSecurity AssessmentsAudit ReadinessControl TraceabilityDocumentation Practices
Tech Stack
Tools & technologiesAWSCloudCyber Security
About the role
Key responsibilities & impact- Own and maintain the written compliance posture of the Agentic AI platform
- Author, update, and evolve System Security Plans and related compliance artifacts supporting ATO and assessment efforts
- Develop additional SSPs and associated documentation for expanding authorization needs
- Build, organize, and maintain a security policy and SOP library aligned to relevant control frameworks
- Manage POA&Ms, document gaps, track remediation progress, and maintain visibility into open items
- Coordinate and run evidence collection cycles for internal reviews, external assessments, and audits
- Serve as the primary compliance point of contact for auditors, external assessors, and compliance stakeholders
- Partner with platform, cloud, and security engineers to validate documented control narratives against implemented infrastructure and operational practices
- Review architecture diagrams, infrastructure-as-code, technical diagrams, and engineering documentation for compliance accuracy
- Ensure consistency, traceability, and quality across compliance documentation and supporting artifacts
- Identify documentation gaps, policy inconsistencies, and control narrative issues and drive resolution
- Support repeatable compliance processes that strengthen audit readiness
Requirements
What you’ll need- Minimum of BS with 12+ years of experience, MS with 10+ years of experience, or a Ph.D. with 7 years of experience in security compliance, GRC, cybersecurity policy, or related compliance-focused roles
- Deep hands-on experience authoring and maintaining System Security Plans (SSPs) aligned to NIST 800-171 and NIST 800-53
- Demonstrated experience supporting systems through ATO efforts, formal security assessments, and/or CMMC readiness activities
- Experience managing POA&Ms, coordinating remediation tracking, and running structured evidence collection cycles
- Strong background serving as a primary point of contact for auditors, assessors, and compliance stakeholders
- Proven ability to build and maintain policy libraries, standards, and SOPs aligned to a formal control framework
- Ability to read and interpret architecture diagrams, infrastructure-as-code, and technical documentation
- Working knowledge of AWS and cloud-native environments, including EKS, IAM, logging, encryption, and cloud security controls
- Exceptional attention to detail and ability to identify vague, conflicting, or incomplete documentation
- Strong written communication skills and ability to translate technical implementation into concise, auditor-ready language
- US Citizenship is required
- Desired: CMMC Level 2 preparation, assessment, or sustainment experience
- Desired: FedRAMP or DoD ATO package experience
- Desired: experience in highly technical cloud or platform environments
- Desired: familiarity with evidence management, control traceability, and structured documentation practices
- Desired: experience collaborating with cloud, DevSecOps, or platform engineering teams
- Desired: ability to operate in an environment where compliance maturity is actively being built and refined
Benefits
Comp & perks- Employees may be eligible for overtime
- Shift differential may be available
- Discretionary bonus may be available
