IT Security Risk Auditor
Posted: 07/07/2026
Industry: Systems, Software and IT
Job Number: 19309
Security Clearance: Ability to obtain Top Secret
Job Description
IT Security Risk AuditorÂ
3 year contract
Pay Range: $55-$72/hr
Hybrid: predominantly onsite to start eventually leading to 2-3 days/week on site
Clearance: eligible to obtain Top Secret (interim sufficient to start)
The Security Services Department’s (SSD) overall mission is to enable research and development while keeping the community safe and secure through the protection of information, network, facilities and personnel.
The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies: Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0.
Responsible for maintaining and auditing programs to validate compliance with various government regulations and Information Security policies. The position is responsible for conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls (i.e. the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome) with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system and for the ability to conduct open source and internal research to identify current threat indicators, exploits, and vulnerabilities.
Requirements:
• Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years’ experience conducting risk assessments.
• Experience in compliance auditing, security reviews, or vulnerability assessments.
• Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience.
• In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800-171 and Security Technical Implementation Guides (STIGs).
• The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR/DFARS Safeguarding CUI series (252.204-7012, etc.), computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF) and NIST SP 800-171.
• Working experience directly related to Assessment and Authorization using at least one of the following:
o NIST 800-53/Risk Management Framework (RMF)
o Joint Special Access Program (SAP) Implementation Guide
o NIST SP 800-171 Understanding of CMMC Framework
o National Industrial Security Program Operating Manual (NISPOM) Chapter 8
Preferred:
• Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).
• Direct experience with DCSA facility compliance reviews and security audits.
Hybrid role:
-This position will be predominantly onsite for the first 3-4 months (probably 4 days/wk onsite). After the initial ramp up period, there may be an opportunity for more remote, 2-3 days/week. Long term, candidate must be comfortable with being onsite at least 2+ days and as needed for the project work.
Clearance:
-Interim clearance sufficient for start; but candidate will need to clear up to the Top Secret Level.
Â
3 year contract
Pay Range: $55-$72/hr
Hybrid: predominantly onsite to start eventually leading to 2-3 days/week on site
Clearance: eligible to obtain Top Secret (interim sufficient to start)
The Security Services Department’s (SSD) overall mission is to enable research and development while keeping the community safe and secure through the protection of information, network, facilities and personnel.
The IT Security Risk Auditor position performs audits of classified and unclassified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, Cybersecurity Maturity Model Certification (CMMC), DCSA Assessment and Authorization Process Manual (DAAPM) and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies: Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0.
Responsible for maintaining and auditing programs to validate compliance with various government regulations and Information Security policies. The position is responsible for conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls (i.e. the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome) with respect to meeting the security requirements of the Authorization to Operate (ATO) or other government regulation or contractual requirement for the system and for the ability to conduct open source and internal research to identify current threat indicators, exploits, and vulnerabilities.
Requirements:
• Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years’ experience conducting risk assessments.
• Experience in compliance auditing, security reviews, or vulnerability assessments.
• Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience.
• In-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), NIST SP 800-171 and Security Technical Implementation Guides (STIGs).
• The ability to read, understand and apply government regulation, policies and procedure such as the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, FAR/DFARS Safeguarding CUI series (252.204-7012, etc.), computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF) and NIST SP 800-171.
• Working experience directly related to Assessment and Authorization using at least one of the following:
o NIST 800-53/Risk Management Framework (RMF)
o Joint Special Access Program (SAP) Implementation Guide
o NIST SP 800-171 Understanding of CMMC Framework
o National Industrial Security Program Operating Manual (NISPOM) Chapter 8
Preferred:
• Information Assurance Certifications preferred (CISSP/CISA, Security+, CCP/CCA, or other industry-recognized Certification that validate knowledge in Cybersecurity framework or equivalent).
• Direct experience with DCSA facility compliance reviews and security audits.
Hybrid role:
-This position will be predominantly onsite for the first 3-4 months (probably 4 days/wk onsite). After the initial ramp up period, there may be an opportunity for more remote, 2-3 days/week. Long term, candidate must be comfortable with being onsite at least 2+ days and as needed for the project work.
Clearance:
-Interim clearance sufficient for start; but candidate will need to clear up to the Top Secret Level.
Â
| Must Have | |
|---|---|
| Admin | |
| Compliance & Auditing | 7Â years |
| Degree Level | |
| Bachelor's Degree | Yes |
| Experience | |
| Document audit findings, including non-compliance issues or deviations | 7Â years |
| Identify potential compliance issues and recommend policy/procedure changes | 7Â years |
| IT system security compliance (NIST, PCI, HIPPA, CMMC) | 3Â years |
| Support preparation for audit/review activities | 7Â years |
| Government Policy/Regulations | |
| STIG Compliance | 3Â years |
| Security | |
| NISPOM 32 CFR Part 117 experience | 3Â years |
| NIST 800-171 | 3Â years |
| NIST 800-53 | 3Â years |
| Risk Management Framework (RMF) | 3Â years |
| Soft Skills | |
| Strong Verbal and Written Communication | Yes |
| Time Management | Yes |
| Software | |
| MS Suite (Excel, ppt) | 7Â years |
| Nice to Have | |
| Certification | |
| Security+ CE, CASP, CISSP, or similar security certification | Yes |
| Security | |
| Cybersecurity Maturing Model Compliance (CMMC) | 0Â years |
Job Requirements
NIST, RMF, compliance auditing, vulnerability, risk assessment, NISPOM
Meet Your Recruiter
Share This Job:
Related Jobs:
There are currently no related jobs. Please sign up for Job Alerts.
Loading...
Login to save this search and get notified of similar positions.
About Bedford, MA
Explore exciting job opportunities in and around Bedford, Massachusetts! Located in Middlesex County, just a short drive from Boston, this charming town offers a perfect blend of suburban tranquility and urban convenience. With close proximity to historic sites like the Bedford Flag and the Minute Man National Historical Park, as well as a thriving arts scene showcased at the Higgins Art Gallery, job seekers can enjoy a rich cultural experience while advancing their careers. Indulge in delicious New England cuisine, catch a show at the nearby Merrimack Repertory Theatre, or cheer on the beloved Boston Red Sox at Fenway Park. Embrace the picturesque beauty of nature at nearby Bedford Center Park or take a stroll by the Concord River. Don't miss the chance to grow both personally and professionally in this vibrant and dynamic region!
Are you sure you want to apply for this job?
Please take a moment to verify your personal information and resume are up-to-date before you apply.