Security Compliance Specialist

Apexon

$90K — $110K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Advanced knowledge of NIST SP 800 53.
  • Expertise in developing System Security Plans.
  • Extensive experience in cyber security assessments and gap analyses.
  • Intermediate understanding of vulnerability and patch management.
  • Foundational knowledge of cloud security concepts.
  • Proficient in developing compliance and privacy documentation.
  • Strong technical writing and stakeholder management skills.

Responsibilities

  • Develop and maintain System Security Plans (SSPs) for State Government systems.
  • Apply NIST SP 800 53 and relevant regulatory frameworks for security assessments.
  • Conduct security control assessments and compliance reviews.
  • Map findings to security and compliance requirements and recommendations.
  • Prepare privacy documentation, including Privacy Impact Assessments.
  • Support Authorization to Operate packages and audit preparations.
  • Mentor junior team members on compliance practices.

Benefits

  • Health Insurance with Dental & Vision coverage.
  • 401K Plan for retirement savings.
  • Life Insurance, including Short-Term and Long-Term Disability.
  • Paid Vacations and Holidays for work-life balance.
  • Opportunities for continuous skill-based development and career advancement.
Full Job Description
Role: Security Compliance Specialist

Location: Austin, TX

Position: 1

Role Overview:

We are seeking an experienced Security Compliance Specialist to support security, privacy, risk, and compliance activities for State Government client systems. The ideal candidate will have strong expertise in NIST SP 800 53, System Security Plans, security assessments, vulnerability management, and compliance documentation. The candidate will work closely with system owners, ISSOs, auditors, development teams, and IT stakeholders to maintain security authorization and compliance requirements.

Key Responsibilities:
• Develop, update, and maintain System Security Plans (SSPs) for State Government systems
• Apply NIST SP 800 53, NIST Risk Management Framework, and applicable regulatory frameworks to assess and document security posture
• Conduct security control assessments, gap analyses, and compliance reviews
• Map assessment findings to applicable security and compliance requirements
• Prepare privacy documentation including Privacy Impact Assessments and data handling policies
• Support Authorization to Operate packages and coordinate with system owners, ISSOs, and auditors
• Track Plans of Action and Milestones and monitor remediation activities
• Maintain audit ready compliance documentation and evidence repositories
• Review vulnerability assessment results and translate findings into risk ratings and remediation actions
• Support security compliance documentation for cloud environments such as Azure Government and AWS GovCloud
• Use GitHub or similar collaboration tools to manage documentation changes
• Leverage AI tools to research and troubleshoot technical and compliance issues
• Work with development, IT, and project teams to gather information required for compliance documentation
• Document findings, procedures, risks, and remediation plans for technical and nontechnical stakeholders
• Participate in discovery sessions and provide compliance input during sprint planning
• Mentor junior team members on security compliance documentation practices
• Stay current with evolving security, privacy, and compliance frameworks

Required Skills:
• Advanced knowledge of NIST SP 800 53
• Advanced experience developing and maintaining System Security Plans
• Advanced experience conducting cyber security assessments and gap analyses
• Intermediate experience with vulnerability and patch management
• Foundation level knowledge of cloud security concepts
• Experience with NIST Risk Management Framework and security authorization processes
• Experience developing compliance and privacy documentation
• Experience supporting ATO packages, POA&Ms, and audit activities
• Strong understanding of security controls, risk assessment, remediation tracking, and compliance evidence
• Excellent technical writing, documentation, communication, and stakeholder management skills

Preferred Skills:
• Experience with FedRAMP, StateRAMP, or CJIS compliance frameworks
• Experience supporting Azure Government or AWS GovCloud environments
• Experience with vulnerability assessment platforms such as Nessus, Qualys, Tenable, or Veracode
• Experience using GitHub for documentation management and technical collaboration
• Experience with GitHub Copilot or similar AI assisted development tools
• Experience supporting State Government or public sector security programs
• Experience working with privacy assessments and data protection requirements
• Security or compliance certifications are a plus

Education Requirement:

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related field preferred. Equivalent professional experience may be considered.

Our Perks and Benefits:

Our benefits and rewards program has been thoughtfully designed to recognize your skills and contributions, elevate your learning experience, and provide care and support for you and your loved ones.

We also offer:
• Health Insurance with Dental & Vision
• 401K Plan
• Life Insurance, STD & LTD
• Paid Vacations & Holidays
• Continuous Skill Based Development and Career Advancement Opportunities

Similar Jobs

More Jobs at Apexon

More Education, Government & Non-Profit Jobs

Find similar Security Compliance Specialist jobs: