Alternate Information Security Compliance Manager
The University of Texas at AustinAbout the role
Job Posting Title:
Alternate Information Security Compliance Manager----
Hiring Department:
Applied Research Laboratories----
Position Open To:
All Applicants----
Weekly Scheduled Hours:
40----
FLSA Status:
Exempt from FLSA----
Earliest Start Date:
Immediately----
Position Duration:
Expected to Continue----
Location:
PICKLE RESEARCH CAMPUS----
Job Details:
Purpose
The Alternate Information Security Compliance Manager, you will help scale ARL:UT's compliance program to accommodate the growing and evolving needs of the organization and its many customers. Additionally, you will provide backup support for the Information Security Compliance Manager and help the Information System Security Manager in carrying out the review of classified information systems. You will collaborate with people both inside and outside of the organization, including system engineers, administrators, sponsors, and other organizations.
Responsibilities
Responsible for ensuring classified systems follow government and ARL regulations while meeting program demands and operating in an accredited state.
Assist in day-to-day IT governance, risk management, and compliance functions.
Responsible for assisting in ensuring that classified information systems meet the Risk Management Framework requirements for National Security computing environments as defined by the National Institute of Standards and Technology (NIST) 800-Series, the Defense Counterintelligence and Security Agency Assessment and Authorization Guidance (DAAG), the Joint Special Access Program Implementation Guide(JSIG), and other governing bodies.
Conducting continuous monitoring reviews and self-assessments of classified information systems and their applicable security controls to ensure both government and ARL policy compliance.
Providing oversight of compliance assurance for the daily administration of information security measures in compliance with the NISPOM, DAAG, JSIG, DISA, and other relevant system security requirements to include those under the Risk Management Framework (RMF).
Assist in updating and maintaining system level Plan of Action and Milestones (POA&M) through compliance checks, STIG and SCAP reviews, and Nessus Scanning.
Responsible for drafting detailed reports of compliance and self-inspection outcomes for upper management review.
Manage and maintain a compliance database, to include, but not limited to, the updating of control policy descriptions, control compliance status, etc.
Responsible for supervising a small team of Information Security Compliance Analysts.
Other related functions as assigned.
Required Qualifications
HS/ GED
Five years of relevant cybersecurity experience, including compliance assessment and planning through the STIG and POA&M process.
Two years working with the RMF, DAAG, NISPOM, JSIG or other equivalent security frameworks.
Ability to assess security posture by identifying and mitigating vulnerabilities.
Hold a current Security+ or IAM/IAT II equivalent level certification or will have completed upon start date.
Strong multitasking skills with attention to detail.
Relevant education and experience may be substituted as appropriate.
US Citizen. Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information at the level appropriate to the project requirements of the position. Employment is contingent on selected applicant submitting application for access and receiving notification of eligibility within a time period specified in the job offer. Employment must begin within 30 days of confirmation of eligibility. Eligibility for access to classified information must continue without interruption during employment.
Preferred Qualifications
Bachelor's Degree in Computer Science, Cyber Security, or related field.
Experience as an Auditor, ISSO, ISSE, Security Architect, or Information Security Analyst.
Held cybersecurity positions in classified DoD environments for 5+ years.
More than five years working with Linux environments.
Experience with vulnerability/compliance scanning tools (ACAS/Nessus, Retina, MBSA, SCAP etc.)
Experience with the implementation of STIG/SRG compliance configurations.
Eligibility for immediate access to classified information at the level appropr
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s