FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Compliance Specialist
Supermicro. Drive day-to-day federal compliance execution, security assurance, and audit readiness for SMCI Federal .
Posted 9/28/2026full-timeSan Jose • California • United StatesMid-LevelSenior💰 $133,000 - $165,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in federal compliance execution, security assurance, and audit readiness, with a strong focus on NIST SP 800-171 and CMMC Level 2 frameworks. Proficient in managing technical security controls, incident response, and compliance documentation in a highly regulated environment.
Highest-signal resume keywords
NIST SP 800-171 ManagementCMMC Level 2 ComplianceSecurity Risk ManagementIncident Response ReadinessTechnical Security Controls Validation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Risk ManagementCompliance AuditingTechnical GRC ExecutionIdentity and Access Management (IAM)Access Control MatricesAudit LoggingData EncryptionPhysical Security Control RequirementsCUI and ITAR ComplianceIncident Response Planning
Soft Skills
Exceptional Written Skills
Tools & Technologies
ServiceNowJiraCloud-Based GRC Platforms
Certifications & Qualifications
CISSPCISACISMCRISCCMMC Registered Practitioner (RP)
Industry Keywords
Federal ComplianceDFARSControlled Technical DataDefense Industrial Base (DIB)Compliance Evidence Repository
Tech Stack
Tools & technologiesCloudCyber SecurityServiceNow
About the role
Key responsibilities & impact- Drive day-to-day federal compliance execution, security assurance, and audit readiness for SMCI Federal
- Complete and maintain NIST SP 800-171 self-assessment scoring and SPRS submissions
- Own, manage, and update the System Security Plan (SSP) and Plan of Action & Milestones (POA&M)
- Track and close control gaps against defined SLAs
- Maintain incident response readiness for DFARS 72-hour reporting requirements
- Lead annual incident response tabletop exercises and ensure rapid, accurate security-event reporting
- Validate technical safeguarding controls delivered through GCC High and SMCI-operated systems against NIST SP 800-171
- Establish and administer Technology Control Plans and technical access controls for controlled technical data
- Operate deemed-export prevention processes across engineering, sales, and manufacturing
- Support and validate physical protection controls at the dedicated federal facility, including badge access, visitor management, and physical safeguarding of CUI
- Partner with Facilities and Security on control design for spaces where CUI or ITAR-controlled technical data is handled
- Deliver an assessment-ready posture for third-party CMMC Level 2 certification audits
- Independently validate technical security controls and maintain separation of duties
- Drive and track completion of mandatory CUI, ITAR, and insider-threat training
- Support insider-threat access-lifecycle controls and reporting channels with HR and Security
- Maintain the compliance evidence repository and CUI-environment asset inventory
- Support evaluation of GRC tooling as the program matures
Requirements
What you’ll need- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related technical field
- 5+ years of hands-on experience in security risk management, compliance auditing, or technical GRC execution within a highly regulated environment
- Direct experience managing NIST SP 800-171, CMMC Level 2, DFARS (252.204-7012/7019/7020), and ITAR compliance frameworks
- Proven understanding of technical security controls, including Identity and Access Management (IAM), access control matrices, audit logging, and data encryption
- Working familiarity with physical security control requirements under the NIST SP 800-171 Physical Protection family in a controlled facility
- Exceptional written skills for drafting SSPs, POA&Ms, technical control documents, and audit artifacts
- Preferred: CISSP, CISA, CISM, CRISC, or CMMC Registered Practitioner (RP)
- Preferred: Experience supporting hardware manufacturers, server/data center infrastructure, or defense industrial base (DIB) suppliers
- Preferred: Experience automating compliance evidence collection and utilizing ticketing/GRC tools such as ServiceNow, Jira, or cloud-based GRC platforms
Benefits
Comp & perks- Comprehensive benefits package
- Potential eligibility for bonus programs
- Potential eligibility for equity award programs