Talent.com
serp_jobs.error_messages.no_longer_accepting
Cybersecurity Compliance Specialist

Cybersecurity Compliance Specialist

R.E. Darling Co. Inc.Tucson, AZ, US
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

This position will require access to ITAR and / or EAR controlled technical data, technology or source code, and requires that all individuals in this role be authorized to access such information

General Description

The Cybersecurity & Compliance Specialist is a salaried position reporting to the Information Technology & Systems Manager. The Cybersecurity & Compliance Specialist is responsible for the Cybersecurity posture, compliance, readiness, training and ongoing governance of information systems subject to Cybersecurity Maturity Model Certification (CMMC) and Controlled Unclassified Information (CUI). The Cybersecurity & Compliance Specialist will lead cross-functional working groups and coordinate with External Service Providers (ESP) as required. This position requires strong organizational skills, analytical skills, a high level of attention to detail and knowledge of current requirements for compliance. Good communications skills are required with the ability to work with all levels of the organization diplomatically and skillfully.

Primary Responsibilities

  • Provide governance and CMMC Program Management to ensure compliance to legal and regulatory requirements including dictated customer requirements
  • Maintain and update REDAR's System Security Policy, Plan of Action & Milestones (POA&Ms), Risk assessments and related security policies
  • Cyber Security / Disaster Recovery / Incident Response and Business Continuity Planning
  • Cyber Security, Controlled Unclassified Information (CUI), Risk Awareness and IT policy training
  • Ensure continuous monitoring, logging, vulnerability scanning and system hardening

Education and Experience Requirements

  • Bachelor's degree in computer sciences, Information Systems or a specialized cybersecurity program, which will provide foundational knowledge in network security, risk management, cryptography, and threat detection
  • Minimum three years' experience in the following areas
  • Monitoring and remediating Cyber Security threats
  • Implementation and retention of corporate policies
  • Training employees on Cyber Security policies and awareness
  • Windows server administration
  • Microsoft Office 365 & Exchange administration
  • Previous employment with a Department of Defense Contractor preferred
  • Previous experience with CMMC and NIST 800-171 compliance preferred
  • Specific Tasks and Focus Areas

  • Provide governance and CMMC Program Management to ensure compliance to legal and regulatory requirements including dictated customer requirements
  • Collaborate with Information Technology & Systems Manager to manage Information System Security for CUI systems
  • Cybersecurity Maturity Model Certification (CMMC) and NIST 800-171 Compliance & Governance
  • Develop and execute a strategic roadmap to achieve and maintain CMMC Level 2 Compliance
  • Coordinate readiness assessments, gap analysis and remediation planning
  • Oversee implementation and maintenance of NIST SP 800-171 controls
  • Implementation, and retention of IT policies, processes and systems required to satisfy CMMC (including NIST 800-171) compliance
  • Collaborate with business units to develop and implement processes & procedures to support regulatory and customer dictated security requirements
  • Provide evidence / supporting documents to attest to individual requirements of CMMC and NIST 800-171
  • Enter data required in Procurement Integrated Enterprise Environment (PIEE) for CMMC, Supplier Performance Risk System (SPRS), etc.
  • Coordinate with Registered Practitioner Organization (RPO) and Certified Third-Party Assessor Organization (C3PAO) to attain / retain CMMC certification.
  • Primary liaison with Customers, Senior Leaders, Managers, Contracts / Exports Department and other internal employees as required regarding CMMC compliance and status
  • Collaboration with Supply Chain
  • Monitoring of CMMC related FAR / DFAR clauses
  • Develop and execute process to Audit departments and users for compliance
  • Current awareness of changing and upcoming security and compliance requirements
  • Additional Focus

  • Maintain and update REDAR's System Security Policy (SSP), Plan of Action & Milestones (POA&Ms), Risk assessments and related security policies
  • Review and update System Security Plan (SSP) to reflect current requirements
  • Review and update Plan of Action and Milestones (POAM) to reflect current status for meeting / retaining CMMC certification
  • Review and update REDAR Information System Security (ISS) policies as required
  • Communicate and train users to revised requirements for the SSP, POA&M and related policies
  • Cyber Security / Disaster Recovery / Incident Response and Business Continuity Planning

  • Review and update REDAR's Incident Response Plan
  • Lead security incident response and reporting activities for in-scope systems
  • Respond to and oversee mitigation of threats in a timely manner per REDAR's Incident Response Plan
  • Ensure best practices for security with least level of access required are employed
  • Stay abreast of current and trending threats by reviewing Cyber Intel provided by Managed Detection and Response (MDR) and / or Managed Service Security Provider (MSSP) as required
  • Collaborate with Information Technology & Systems Manager to implement and support requirements for qualification of Cybersecurity Insurance
  • Collaborate with Information Technology & Systems Manager to implement proactive solutions to prevent against new threats as they become known
  • Oversee and direct company communication and education to provide user awareness of ongoing threats and risks
  • Oversee system patches / updates to operating systems & clients are implemented
  • Awareness of company data Backup, Disaster Recovery and Business Continuity Plans
  • Collaborate with the Information Technology & Systems Manager to develop and review that appropriate security procedures are in place to safeguard the systems from physical harm and viruses, unauthorized users and damage to data
  • Review and update REDAR's incident response plan
  • Training and Awareness

  • Provide Cyber Security, Controlled Unclassified Information (CUI), Risk Awareness and IT policy training
  • Develop and maintain training media for cyber security requirements, CUI and risk awareness
  • Train employees in cyber security requirements, CUI, risk awareness and company security policies
  • Ongoing current cyber threat awareness training
  • Ongoing training on revisions to REDAR's Information Systems Security Policy (ISS) and related policies
  • Continuous Monitoring and Security Operations

  • Ensure continuous monitoring, logging, vulnerability scanning and system hardening.
  • Coordinate with contracted External Service Providers (ESP) for Managed Detection and Response (MDR), Managed Service Provider (MSP) and / or Managed Service Security Provider (MSSP) as required
  • Coordinate with Information Technology & Systems Manager and Network & Systems Administrator as required
  • AA / EOE / W / M / Vet / Disable

    R.E. Darling Co., Inc. is an equal opportunity employer. All qualified applicants will receive consideration of employment without regard to race, religion, color, national origin, gender, gender identity, sexual orientation, age, status as protected veteran, among other things, or status as qualified individual with disability.

    Qualifications

    Education

    Preferred

  • Bachelors or better in Computer Science.
  • Bachelors or better in Information Technology.
  • Technical / other training or better in Computer Science.
  • Technical / other training or better in Information Technology.
  • Equal Opportunity Employer / Protected Veterans / Individuals with Disabilities

    This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Cybersecurity Specialist • Tucson, AZ, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Analyst to enhance the defenses of its information systems by analyzing and responding to cybersecurity threats. Key Responsibilities : Process alerts and r...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Project Manager

    Senior Cybersecurity Project Manager

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cybersecurity Project Manager, responsible for managing technical cybersecurity projects. Key Responsibilities Manage projects with internal and external dependen...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cybersecurity Lead

    Cybersecurity Lead

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Lead to manage and enforce cybersecurity posture, compliance, and continuous monitoring for a cloud-based enterprise environment supporting Department of De...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cybersecurity Engineer to provide technical leadership and support for cybersecurity operations. Key Responsibilities Lead day-to-day SOC operations, including th...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cybersecurity Analyst - Top Secret Clearance

    Cybersecurity Analyst - Top Secret Clearance

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for two Cybersecurity Analysts to provide advanced cybersecurity operations and compliance management support for a Department of Defense enterprise environment.Key Responsibil...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior Cyber Threat Engineer

    Senior Cyber Threat Engineer

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cyber Threat Detection Engineer, remote position.Key Responsibilities Lead the development and maintenance of high-fidelity detection rules to identify security ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Cyber Threat Analyst

    Senior Cyber Threat Analyst

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cyber Threat Intelligence Analyst to join their cybersecurity team.Key Responsibilities Conduct in-depth analysis of cyber threats, identifying patterns, indicat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Engineer III

    Cybersecurity Engineer III

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Engineer III.Key Responsibilities Design and implement cybersecurity solutions, upgrades, and enhancements Provide technical expertise and support for cy...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Trade Compliance Specialist

    Trade Compliance Specialist

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Trade Contractor - L2.Key Responsibilities Conduct ITAR and EAR export jurisdiction & classification reviews of hardware, software, and technical data Ensure complianc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cyber Security Engineering Lead

    Cyber Security Engineering Lead

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Security Engineering Lead.Key Responsibilities Optimize cybersecurity program processes and contribute to the broader program roadmap Manage and execute cybersec...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Cyber Threat Hunter

    Senior Cyber Threat Hunter

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cyber Threat Hunter to enhance its cybersecurity efforts.Key Responsibilities Identify vulnerabilities using penetration testing tools and techniques to secure c...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Vice President of Cybersecurity

    Vice President of Cybersecurity

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Vice President of Cybersecurity to lead the development and execution of an enterprise-wide cybersecurity strategy. Key Responsibilities Develop and implement a comprehe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Insider Threat Analyst

    Senior Insider Threat Analyst

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    Key Responsibilities Identify and respond to insider threat security events Analyze alerts from DLP, UEBA, and other monitoring tools to detect anomalous activity Develop insider threat use cas...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    IT Compliance Lead

    IT Compliance Lead

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for an IT Compliance Lead to enhance its IT control environment and compliance posture.Key Responsibilities Own and maintain the Common Control Set in alignment with SOX ITGC...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Principal Cybersecurity Engineer

    Principal Cybersecurity Engineer

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Principal Cybersecurity Engineer - Battery Storage.Key Responsibilities Drive the cybersecurity program and activities, aligning with compliance and security postures ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Project Manager

    Cybersecurity Project Manager

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Project Manager to join their cybersecurity project team.Key Responsibilities Implement Project Management best practices to reduce risks and improve serv...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cybersecurity SecOps Head

    Cybersecurity SecOps Head

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a SecOps Head.Key Responsibilities Oversee security operations and incident response strategies Ensure compliance with security standards and regulations across cloud en...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Cybersecurity Subject Matter Expert

    Cybersecurity Subject Matter Expert

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Technology Management Analyst.Key Responsibilities Serve as the Cybersecurity Subject Matter Expert (SME) for cybersecurity architecture policies, standar...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cyber Security Analyst

    Senior Cyber Security Analyst

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cyber Security Analyst.Key Responsibilities Assist in the design and implementation of comprehensive compliance programs aligned with multiple frameworks Config...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cyber Security Analyst

    Cyber Security Analyst

    VirtualVocationsTucson, Arizona, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Security Analyst for a 100% remote W2 contract position.Key Responsibilities Monitor, manage, and respond to security events in collaboration with the internal cy...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30