Security and Compliance Manager II
Ad HocAbout the role
Security and Compliance Manager II
This is a remote position.
Ad Hoc is a technology company that empowers organizations to deliver scalable, impactful digital services. Using modern, agile methods, our team creates products that meet people’s needs and transform their experience of government.
Work on things that matter
Our collaborations have shaped some of the defining moments in public-sector service delivery. We’ve helped build products that connect Veterans to tailored services, help millions access affordable health care, and support important programs like Head Start. As we work with agencies to deliver critical services, we’re also changing how the government approaches technology.
Built for a remote life
Our culture, communications, and tools are built for remote work, enabling us to bring together top talent nationwide. At Ad Hoc, remote life empowers our teams to design work environments that fit their lives and that foster flexibility and collaboration to achieve positive outcomes for our customers.
Committed to high expectations and a welcoming culture
Ad Hoc values acceptance, accountability, and humility. We aren’t heroes. We learn from our mistakes and improve the process for the next time. We build small, inclusive teams to collaborate closely with our partners to solve the right problems and deliver software that works.
The Federal Civilian business unit supports many customers spanning the federal, commercial, and nonprofit space. Our customers include NASA, the General Services Administration, Office of Personnel Management, the Library of Congress, Health & Human Services, and the FDIC. We partner with these agencies to build new capabilities, deliver products, establish data as a strategic asset for informed decision-making, modernize legacy systems, and build the digital service infrastructure necessary to scale their mission impact.
Primary Responsibilities:
Security and Compliance Manager II serves as an individual contributor within a team; with the support and guidance of leadership, you will be responsible for supporting the goal of meeting scope, schedule and delivery requirements. You will begin to develop an awareness and understanding of the security and compliance within your designated program, as well as interact with stakeholders. Primary expectations for a Security and Compliance Manager II include:
-
Conducts security control tests of design and operational effectiveness
-
Manages remediation tasks to completion on tight deadlines
-
Supports internal and external auditors
-
Maintains documentation related to security compliance
-
Identifies opportunities for security compliance control automation
-
Maintains security compliance automation tasks
-
Building an understanding of at least two security control frameworks (e.g. SOC, NIST, etc.)
-
Works towards understanding how compliance works with cloud-native tech stacks
-
onboarding for new developers
-
Exhibits understanding for other roles and practices, including how they are intended to work together
-
Participates in planning sessions to ensure security and compliance requirements are met
Basic Qualifications:
-
Bachelor’s degree in computer science, information assurance, cybersecurity or related field, 3+ years of experience
-
Relevant years of experience may be substituted for education
-
-
At least 2+ years experience working with a SaaS company and passion for learning and working in compliance programs
-
Operate effectively in a fast-paced environment managing multiple concurrent security requests and priorities
-
Support recurring security processes including security impact analysis, risk assessments, remediation tracking, and ongoing documentation updates
-
Apply NIST security controls (preferably NIST 800-53) within a GRC/RMF framework to evaluate system security posture
-
Assist in translating security control requirements into actionable guidance for engineering teams.
-
Demonstrate the ability to work independently by researching existing documentation, standards, and previous artifacts to resolve questions before escalating.
-
Maintain and update security artifacts and documentation in Jira and Confluence, ensuring accuracy and completeness
-
Work closely with DevOps, infrastructure, and data engineering teams to review system changes and assess potential security impact
-
Participate in secu
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s