Point your AI agent at freehire and let it find you a job.

Get the CLI →

CTS Engines

Open 67d

IT Security & Compliance Manager

Posted Updated
Discussion

Position Overview

We are seeking an IT Security & Compliance Manager to oversee, maintain, and defend our digital infrastructure while strictly enforcing federal cybersecurity requirements. In this role, you will own our compliance posture, ensuring full alignment with NIST SP 800-171, DFARS 252.204-7012, and CMMC Level 2.


The ideal candidate bridges the gap between technical execution and regulatory governance. You will be responsible for managing security operations, maintaining our System Security Plan (SSP), closing Plan of Action and Milestones (POA&M) items, and preparing the organization for a formal third-party CMMC assessment.


Key Responsibilities

  • CMMC & NIST Governance: Own, update, and enforce the System Security Plan (SSP) and Plan of Action and Milestones (POA&M). Ensure all 110 practices of NIST SP 800-171 are fully implemented and auditable.
  • Infrastructure Security Oversight: Oversee the security posture of our technical stack, ensuring secure configurations across firewalls, Endpoint Detection and Response (EDR), Remote Monitoring and Management (RMM), and cloud environments.
  • Cloud & Tenant Security: Manage data enclave boundaries and security policies, specifically optimizing and maintaining a Microsoft 365 GCC High environment to prevent CUI spillage.
  • Data Flow & CUI Management: Map, audit, and control the flow of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across all internal and external systems.
  • Incident Response & DFARS Reporting: Lead the incident response team. Ensure full compliance with DFARS 252.204-7012, including rapid reporting of cyber incidents to the DoD Cyber Crime Center (DC3) within 72 hours.
  • Vulnerability & Patch Management: Conduct regular internal audits, vulnerability scans, and risk assessments. Prioritize and remediate vulnerabilities across servers, endpoints, and network devices.
  • Vendor & Supply Chain Risk: Evaluate subcontractors and third-party vendors to ensure they meet mandatory DFARS flow-down requirements.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available