Massachusetts Institute of Technology

Senior Manager Audit and Compliance

Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Security Management, Cybersecurity, Information Assurance, Business Administration, Criminal Justice, or related field, or equivalent experience.
  • 10+ years in industrial security, compliance, audit, inspection, or risk management within cleared defense or government contractor environments.
  • 7+ years of leadership experience managing security programs and professional teams.
  • Proven success leading enterprise-level audit and compliance programs, especially in government contexts.
  • Strong understanding of security regulations and frameworks (e.g., NISPOM, CMMC 2.0, NIST).
  • Excellent communication and analytical skills; ability to brief senior leadership and external stakeholders.
  • Active Top Secret security clearance with eligibility for compartmented programs.

Responsibilities

  • Lead and manage security audit, compliance, and risk assessment programs.
  • Supervise a team of auditors, compliance specialists, and risk management professionals.
  • Develop and implement audit methodologies and compliance monitoring processes.
  • Plan and oversee self-inspections and government security reviews.
  • Prepare the organization for government-led inspections and assessments.
  • Monitor regulatory changes and advise leadership on compliance requirements.
  • Evaluate security controls and facility compliance.

Benefits

  • Comprehensive health, dental, and vision plans.
  • MIT-funded pension.
  • Matching 401K contributions.
  • Paid leave including vacation, sick, and parental leave.
  • Tuition reimbursement and continuing education opportunities.
  • Mentorship programs.
  • Various work-life balance options.
Full Job Description
What will you do?

The Senior Security Manager, Audit & Compliance is responsible for leading the Laboratory's independent security assurance and compliance program across unclassified, collateral, and special access environments. Reporting directly to the Chief Security Officer (CSO)/Chief Information Security Officer (CISO), this role provides objective oversight of security compliance, audit readiness, risk management, and continuous improvement efforts. The position operates independently from mission-support security functions and serves as a key advisor to executive leadership on organizational security posture, regulatory compliance, and inspection readiness.

Key Responsibilities
* Lead and manage the Laboratory's security audit, compliance, inspection, and risk assessment programs.
* Supervise a team of security auditors, compliance specialists, and risk management professionals.
* Develop and implement audit methodologies, compliance monitoring processes, and risk-based assessment strategies.
* Plan and oversee self-inspections, government security reviews, compliance assessments, CMMC evaluations, CORA readiness activities, privacy reviews, and corrective action validation efforts.
* Prepare the organization for DCSA, Air Force, Intelligence Community, and program sponsor-led inspections and assessments.
* Monitor changes to government security regulations and provide guidance to leadership on compliance requirements and associated risks.
* Evaluate security controls, classified facility compliance, access control procedures, safeguarding practices, and physical security requirements.
* Develop compliance metrics, dashboards, and executive reports to measure program effectiveness and identify trends.
* Lead corrective and preventive action (CAPA) initiatives and continuous improvement efforts to strengthen security performance and reduce risk.
* Partner with Laboratory leadership, government representatives, and oversight organizations to ensure effective remediation and long-term compliance.
* Support policy development, governance initiatives, workforce training, and organizational awareness programs that promote a culture of compliance and accountability.

What you need/Requirements:

For this position, you must meet these basic requirements: Bachelor's degree in Security Management, Cybersecurity, Information Assurance, Business Administration, Criminal Justice, or a related field, or equivalent combination of education and experience.
* Minimum of 10 years of experience in industrial security, compliance, audit, inspection, or risk management within a cleared defense, intelligence, federal research, or government contractor environment.
* Minimum of 7 years of leadership experience managing professional staff and complex security programs.
* Demonstrated success leading enterprise-level audit, compliance, inspection, or assessment programs and supporting government inspections.
* Strong knowledge of NISPOM 32 CFR Part 117, CUI requirements, DAAG, ICDs, DO Manuals, DoD security regulations, CMMC 2.0, NIST frameworks, risk management principles, and audit methodologies.
* Exceptional communication, analytical, and leadership skills, with the ability to brief senior executives, government officials, and external auditors.
* Candidates must possess one or more of the following audit, security, or compliance certifications, or be able to obtain it within 12 months of hire: Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified CMMC Assessor (CCA) ISO 19011 Lead Auditor Training Certificate
* Active Top Secret security clearance with eligibility for access to compartmented programs.
* Availability for occasional travel and after-hours support during security incidents or inspections.
* Position may require local and overnight travel.
* Subject to pre-employment and periodic background investigations.

Ideally, you will have:

* Experience supporting FFRDC/UARCs, Department of War organizations, Intelligence Community agencies, or major defense contractors.
* Experience with SAP, SCI, and compartmented security programs.
* Experience managing DCSA Security Vulnerability Assessments and other government oversight activities.
* Experience implementing governance, risk, and compliance (GRC) tools and leading enterprise continuous improvement initiatives.
* Professional certifications such as CISA, CISSP, CISM, CompTIA Security+, CRISC, Certified CMMC Assessor (CCA), ISO 19011 Lead Auditor, or related security and compliance credentials.

Hiring Range: $138,600 - $183,600

Disclaimer: MIT Lincoln Laboratory provides a typical hiring range as a good faith estimate of what we reasonably expect to offer for this position at the time of posting. The final salary offered to a selected candidate will depend on various factors, including-but not limited to-the scope and responsibilities of the role, the candidate's experience, skills and education/training, internal equity considerations and applicable legal requirements. This range reflects base salary only and does not include additional forms of compensation or benefits.

At MIT Lincoln Laboratory, our exceptional career opportunities include many outstanding benefits to help you stay healthy, feel supported, and enjoy a fulfilling work-life balance. Benefits offered to employees include:
  • Comprehensive health, dental, and vision plans
  • MIT-funded pension
  • Matching 401K
  • Paid leave (including vacation, sick, parental, military, etc.)
  • Tuition reimbursement and continuing education programs
  • Mentorship programs
  • A range of work-life balance options
  • ... and much more!


Please visit our Benefits page for more information. As an employee of MIT, you can also take advantage of other voluntary benefits, discounts and perks.

Selected candidate will be subject to a pre-employment background investigation and must be able to obtain and maintain a Secret level DoD security clearance.

About Massachusetts Institute of Technology

The Massachusetts Institute of Technology (MIT) is a private research university located in Cambridge, Massachusetts. MIT is a member of the Association of American Universities (AAU) and is classified among "R1: Doctoral Universities – Very high research activity". The university is known for its strong emphasis on scientific and technological research and its engineering programs. MIT was founded in 1861 and has a long history of innovation and entrepreneurship. The university has produced numerous Nobel laureates, Rhodes Scholars, and MacArthur Fellows.
Learn more about Massachusetts Institute of Technology
Size
13,000 employees
Industry

Similar Jobs

More Jobs at Massachusetts Institute of Technology

More Education, Government & Non-Profit Jobs

Find similar Senior Manager Audit and Compliance jobs: