Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced
Compliance & Audit Support Specialist (Mid) to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency in Washington, DC. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role sits within the Information Security Division (ISD) and provides critical compliance monitoring, audit facilitation, documentation support, and risk management services in support of the agency's Federal Information Security Modernization Act (FISMA) obligations, Risk Management Framework (RMF) program, and enterprise-wide cybersecurity and privacy compliance requirements.
The ideal candidate is a detail-oriented and analytically driven cybersecurity compliance professional with a strong foundation in federal information security policy, NIST security frameworks, security controls documentation, and audit support methodologies. This individual must possess the ability to manage multiple concurrent compliance activities across a complex, multi-system federal IT environment, produce high-quality technical documentation aligned to agency standards, and effectively coordinate with system owners, program offices, auditors, and senior Government stakeholders.
The Compliance & Audit Support Specialist (Mid) is responsible for providing comprehensive cybersecurity policy compliance support, security controls documentation, audit facilitation, FISMA reporting, and enterprise risk management support across an assigned portfolio of federal information systems and programs. This individual works closely with ISSOs, system owners, program offices, cybersecurity leadership, and external auditors to ensure that all assigned systems maintain current, accurate, and compliant security documentation, that audit activities are executed smoothly and efficiently, and that the agency's cybersecurity compliance posture is continuously monitored, measured, and reported in accordance with federal and agency requirements.
Principal responsibilities will include but are not limited to:
Cybersecurity Policy & Compliance Documentation Support- Create, update, revise, and maintain cybersecurity and privacy documentation for assigned systems and programs across the enterprise, ensuring all documentation aligns to applicable agency implementation procedures and is reviewed for acceptance by the Office of the CIO.
- Develop and maintain the following documentation types, among others:
- Cybersecurity and Privacy Policies and Procedures
- System Security Plans (SSPs) with detailed, technology-specific control implementation descriptions
- Configuration Management Plans (CMPs)
- Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs)
- E-authentication Risk Assessments (ERAs)
- User recertification documentation
- Architecture, topology, and data flow diagrams (OV-1 and SV-1 equivalent)
- Ensure all control implementation descriptions are written to the level of detail required by agency implementation procedures, clearly explaining how each control is specifically implemented across all technologies within the system boundary, and avoiding high-level generalizations or simple restatement of NIST control language.
- Deliver all documentation on or before agency-defined completion dates, addressing all Government comments, edits, and questions within 10 business days of receipt, and escalating stakeholder unresponsiveness to the Government POC after 10 business days without response.
- Ensure selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as directed by the COR.
- Maintain and update all assigned documents in the agency's Governance, Risk, and Compliance (GRC) tool, ensuring records are current, complete, and accessible.
Controls Assessment & Evaluation Support- Provide security and privacy controls assessment support for assigned systems, including assistance with testing and validation of NIST SP 800-53 controls, documentation of NIST SP 800-53A Determine If Statements (DISs), and mapping of vulnerabilities to applicable controls and control families.
- Support the development of draft Security and Risk Assessment Plans (SAPs), Security and Risk Assessment Reports (SARs), Annual Assessment Reports (AARs), and Plans of Action and Milestones (POAMs) in accordance with established agency timelines and deliverable requirements.
- Assist with technical control assessments across multiple technology types within assigned system boundaries (e.g., Windows, UNIX/Linux, network devices, web applications, cloud platforms), supporting sampling strategies across in-scope devices, users, and services.
- Ensure all assessment reports are comprehensive to the scope identified in the SAP, 100% aligned to the GRC tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission.
- Incorporate all Government feedback into revised assessment deliverables within 5 business days of receipt of comments.
FISMA Reporting Support- Collect, compile, validate, and contribute to FISMA reporting metrics for assigned systems and programs, supporting the development of consolidated metrics reports that are accurate, mathematically verified, and representative of the total agency FISMA inventory.
- Assist in the development and maintenance of dynamically updatable FISMA metrics visualizations and dashboards, contributing data and narrative content aligned to federal CIO metrics requirements.
- Support quarterly FISMA reporting activities, ensuring consolidated reports are delivered for Government review not later than 10 business days prior to submission due dates, and supporting entry of approved metrics into the CyberScope tool as directed.
- Respond to ad hoc or interim FISMA reporting requests within established timelines as directed by the COR.
Audit Support- Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors, ensuring all audit activities are executed smoothly, on schedule, and in accordance with auditors' requirements.
- Facilitate audit meetings and walkthroughs of key cybersecurity capabilities, coordinating with relevant support personnel, supplying auditors with requested artifacts and examples, and responding to auditor follow-up questions within established timeframes.
- Ensure all audit artifacts are delivered on time, pre-reviewed by the Government, and of sufficient quality and completeness to minimize repeated requests from auditors.
- Communicate any issues or problems encountered during audit support activities to the Government POC immediately upon discovery.
- Ensure SOC reports are received from program offices for audit purposes as required, tracking outstanding items and escalating delays proactively.
Automated Information System Accreditation Support- Provide knowledge management services for all information required to perform accreditation services, maintaining all required artifacts and documentation-including appointment orders, ATO documentation, Acceptance of Risk (AOR) documents, Memoranda of Understanding/Agreement, and Data Sharing Agreements-in a centrally organized and accessible repository.
- Monitor all active AOR expiration dates and initiate resubmission processes at least 90 days prior to expiration, ensuring no AOR lapses without renewal or COR notification.
- Respond to customer requests for documentation or guidance within two business days, ensuring all requests are addressed accurately and completely.
- Maintain the SharePoint-based or GRC-based central repository for accreditation artifacts, ensuring documentation is properly organized, version-controlled, and accessible to authorized stakeholders.
Ongoing Authorization (OA) Evaluation Support- Assist ISSOs with the development and submission of OA Playbooks for systems approved for Ongoing Authorization, documenting testing methodologies for each OA core control in accordance with agency implementation procedures.
- Support the monthly execution and documentation of OA Positive Testing results in the agency GRC tool, ensuring testing is conducted comprehensively across the technology stack of each target system.
- Support the annual execution and documentation of OA Negative Testing, coordinating with penetration testing resources as necessary and ensuring results are documented in detail within the GRC tool.
- Ensure all OA test results are peer-reviewed for accuracy and consistency prior to submission, incorporating Government corrections within approximately five business days of receipt.
Enterprise Risk Management (ERM) Support- Assist in maintaining cybersecurity and privacy risk registers for assigned systems, ensuring registers are updated monthly and available via online visualization and internal web portal.
- Support the application of the Factor Analysis of Information Risk (FAIR) methodology to assist in quantifying risk for assigned systems and programs, and contribute to the integration of cybersecurity and privacy risks into the agency ERM Risk Register as directed.
- Evaluate and document major risks related to cybersecurity, privacy, information theft, and sensitive information protection for assigned systems, collaborating on the development of risk register entries with associated controls, planned mitigations, and risk quantification data.
- Contribute risk register inputs and supporting artifacts to monthly ERM deliverables on time and in a format suitable for Government review.
High Value Asset (HVA) Assessment Support- Support the development, maintenance, and regular updating of the agency HVA inventory list, ensuring HVA activities are incorporated into broader IT and information security management planning activities including change management and Information Security Continuous Monitoring (ISCM) strategy.
- Assist with the identification, categorization, and prioritization of HVAs, the implementation and validation of required security controls, and the development and tracking of HVA remediation plans in accordance with established milestones and timelines.
- Support the completion of CISA HVA Assessment 3.0 training requirements and contribute to annual HVA reported metrics, ensuring deliverables are accurate and submitted for Government review not later than 10 business days prior to due dates.
FedRAMP Continuous Monitoring (CONMON) Support- Support the facilitation of monthly FedRAMP CONMON meetings with applicable stakeholders for assigned systems, maintaining sufficient understanding of each system to assist with guidance and comments to Cloud Service Providers (CSPs).
- Assist with the review of vulnerability, penetration test, and ad hoc reporting submitted by CSPs, flagging potential security risks and supporting the review and approval of major change requests in accordance with established procedures.
- Ensure all tasks and deliverables from the agency back to the vendor are facilitated within five business days.
Awareness Training Development Support- Support the development of cybersecurity and privacy awareness training content, including annual, role-based, and condition-based training courses, in accordance with agency requirements and the Shareable Content Object Reference Model (SCORM) format.
- Assist with updating training course content and underlying code annually, ensuring all courses are delivered to the Government for review within 30 business days of request and that all Government comments are addressed within five business days of receipt.
- Support the delivery of cybersecurity awareness training via digital media, printed media, email notices, and instructor-led or self-paced formats as directed.
Security & Compliance- Ensure all compliance and audit support activities comply with applicable Federal security requirements, including FISMA, NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, NIST SP 800-37 Rev 2, FIPS 199, FIPS 200, OMB Circular A-130, and all referenced agency policies and implementation procedures.
- Comply with annual cybersecurity awareness training requirements and maintain all required certifications as current and unexpired throughout the period of performance.
- Ensure all work products are Section 508 accessibility compliant where required, government-owned, and free of proprietary or company-specific markings or restrictions.
Education and Experience:Required:- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Business Administration, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
- Minimum of 3 years of experience in information security compliance, security documentation, or audit support in a federal government IT environment.
- Demonstrated experience developing and maintaining cybersecurity compliance documentation-including SSPs, CMPs, ISCPs, SARs, and POAMs-in accordance with NIST RMF requirements and agency templates.
- Demonstrated experience supporting federal security control assessments, including familiarity with NIST SP 800-53 control families and NIST SP 800-53A assessment methodologies.
- Experience supporting federal audit activities, including artifact collection, coordination with auditors