Dev Technology Group
Security Compliance Analyst (Secret Clearance)
Dev Technology Group, Colorado Springs, Colorado, United States, 80509
Overview
Dev Technology is seeking a Security Compliance Analyst to support a federal client in maintaining compliance and strengthening the security posture of mission-critical systems. The role ensures adherence to government security requirements, manages Plans of Action and Milestones (POA&Ms), and supports risk and vulnerability management activities vital to safeguarding critical systems and data in defense of our Homeland. Clearance: U.S. Citizenship is required. DHS Secret Clearance required. Candidates with dual citizenship cannot be considered per government requirements. Responsibilities
Serve as the primary point of contact for security compliance activities, collaborating with stakeholders to track and resolve security concerns. Manage and maintain POA&Ms, ensuring timely remediation of findings and alignment with government and contract requirements. Support vulnerability management efforts, including reviewing scan results, tracking remediation activities, and verifying closure of findings. Conduct risk management activities, including risk assessments, risk analysis, and documentation of risk mitigation strategies. Conduct compliance reviews to ensure systems adhere to federal regulations, contract requirements, and applicable frameworks (e.g., NIST 800-53, RMF). Assist in preparing and maintaining security documentation, including System Security Plans (SSPs), assessment reports, and risk analyses. Collaborate with technical teams across disciplines to validate security controls, provide compliance guidance, and ensure mission success. Participate in incident response and after-action reviews, documenting lessons learned and compliance impacts. Develop and deliver compliance reports and metrics for leadership, federal stakeholders, and auditors. Contribute to security awareness and training initiatives to promote compliance across operational teams. Qualifications
Active Secret clearance required. U.S. Citizenship required (dual citizens not eligible due to federal contract requirements). Experience with federal government contracts, with a preference for contracts under Homeland Security. 7+ years of experience in security compliance, vulnerability management, or related cybersecurity field. 4+ years of experience with:
Managing and tracking POA&Ms within government contracting environments. Federal security frameworks, policies, and requirements (e.g., FISMA, NIST RMF). Vulnerability management processes and tools. Risk management activities, including conducting risk assessments and risk analysis. Collaboration with technical teams to address findings and implement compliance solutions.
Strong written and verbal communication skills with the ability to prepare compliance documentation and reports. Candidates must reside within a commutable distance for daily onsite work and meet recall/on-call requirements in a 24x7x365 environment. Preferred Qualifications
Certifications in the security field, such as CISSP, CISM, CAP, or similar. Recent DHS experience with security compliance, risk management, or assessment activities. Salary
Our estimated salary range for this position is $80,000-$85,000. This salary range is not a guarantee of compensation and may vary based on education, experience, geographic location, and contractual requirements. Salary could fall outside of this range. About Us
Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with federal customers to deliver technology services and solutions, and to drive missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. EEO
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans #J-18808-Ljbffr
Dev Technology is seeking a Security Compliance Analyst to support a federal client in maintaining compliance and strengthening the security posture of mission-critical systems. The role ensures adherence to government security requirements, manages Plans of Action and Milestones (POA&Ms), and supports risk and vulnerability management activities vital to safeguarding critical systems and data in defense of our Homeland. Clearance: U.S. Citizenship is required. DHS Secret Clearance required. Candidates with dual citizenship cannot be considered per government requirements. Responsibilities
Serve as the primary point of contact for security compliance activities, collaborating with stakeholders to track and resolve security concerns. Manage and maintain POA&Ms, ensuring timely remediation of findings and alignment with government and contract requirements. Support vulnerability management efforts, including reviewing scan results, tracking remediation activities, and verifying closure of findings. Conduct risk management activities, including risk assessments, risk analysis, and documentation of risk mitigation strategies. Conduct compliance reviews to ensure systems adhere to federal regulations, contract requirements, and applicable frameworks (e.g., NIST 800-53, RMF). Assist in preparing and maintaining security documentation, including System Security Plans (SSPs), assessment reports, and risk analyses. Collaborate with technical teams across disciplines to validate security controls, provide compliance guidance, and ensure mission success. Participate in incident response and after-action reviews, documenting lessons learned and compliance impacts. Develop and deliver compliance reports and metrics for leadership, federal stakeholders, and auditors. Contribute to security awareness and training initiatives to promote compliance across operational teams. Qualifications
Active Secret clearance required. U.S. Citizenship required (dual citizens not eligible due to federal contract requirements). Experience with federal government contracts, with a preference for contracts under Homeland Security. 7+ years of experience in security compliance, vulnerability management, or related cybersecurity field. 4+ years of experience with:
Managing and tracking POA&Ms within government contracting environments. Federal security frameworks, policies, and requirements (e.g., FISMA, NIST RMF). Vulnerability management processes and tools. Risk management activities, including conducting risk assessments and risk analysis. Collaboration with technical teams to address findings and implement compliance solutions.
Strong written and verbal communication skills with the ability to prepare compliance documentation and reports. Candidates must reside within a commutable distance for daily onsite work and meet recall/on-call requirements in a 24x7x365 environment. Preferred Qualifications
Certifications in the security field, such as CISSP, CISM, CAP, or similar. Recent DHS experience with security compliance, risk management, or assessment activities. Salary
Our estimated salary range for this position is $80,000-$85,000. This salary range is not a guarantee of compensation and may vary based on education, experience, geographic location, and contractual requirements. Salary could fall outside of this range. About Us
Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with federal customers to deliver technology services and solutions, and to drive missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. EEO
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans #J-18808-Ljbffr