Bachelor's degree in Cybersecurity, Information Assurance, Information Technology, or a related field.
6+ years of experience in cybersecurity compliance, audit, or risk management roles.
Experience supporting federal compliance frameworks (FISMA, NIST RMF, FedRAMP).
Experience with audit processes, documentation, and evidence collection.
Requirements:
Lead cybersecurity compliance efforts aligned with federal standards including FISMA, NIST SP 800-53, OMB, CISA directives, and HUD policies.
Oversee development, implementation, and maintenance of compliance frameworks, policies, and procedures.
Manage audit readiness activities including FISMA audits, internal reviews, and third-party assessments.
Coordinate audit requests, collect evidence, and track audit artifacts in centralized systems.
Job description
cFocus Software seeks a Compliance Lead to join our program supporting Housing and Urban Development (HUD). This position is remote. This position requires a Public Trust clearance. Qualifications:
Bachelor’s degree in Cybersecurity, Information Assurance, Information Technology, or related field.
6+ years of experience in cybersecurity compliance, audit, or risk management roles.
Experience supporting federal compliance frameworks (FISMA, NIST RMF, FedRAMP).
Experience with audit processes, documentation, and evidence collection.
Duties:
Lead cybersecurity compliance efforts aligned with federal standards including FISMA, NIST SP 800-53, OMB, CISA directives, and HUD policies.
Oversee development, implementation, and maintenance of compliance frameworks, policies, and procedures.
Manage audit readiness activities including FISMA audits, internal reviews, and third-party assessments.
Coordinate audit requests, collect evidence, and track audit artifacts in centralized systems.
Serve as primary liaison with auditors and stakeholders during audit engagements.
Develop and maintain Plans of Action and Milestones (POA&M) to remediate findings.
Track and manage Notice of Findings and Recommendations (NFRs) through remediation lifecycle.
Ensure proper documentation, storage, and retrieval of compliance artifacts and evidence.
Support Assessment & Authorization (A&A) processes and Risk Management Framework (RMF) activities.
Develop risk acceptance documentation and support accreditation packages.
Monitor compliance posture and report on risks, gaps, and remediation progress.
Ensure continuous compliance monitoring and alignment with evolving federal mandates.
Provide compliance reporting including monthly, quarterly, and annual status reports.
Support development of SOPs, governance documentation, and compliance strategies.