Jobs and Careers
BD
IT Compliance Supervisor - Public Sector, Operations
BDO USAUnited Statesfull_timeVerifiedPosted 23 Apr 2025
About the role
Job Summary:
The IT Compliance Supervisor leads the development and oversight of the compliance program and its staff, supporting governance, risk, and compliance efforts across Information Technology teams, business executives, and their respective organizations.
Job Duties:
- Advises senior leadership on interpreting and applying FedRAMP, NIST SP 800‑53, NIST SP 800‑171 Rev 2, NIST CSF, CMMC 2.0, and ISO 27000 requirements to optimize cybersecurity posture and CUI protection
- Develops and maintains multi‑year strategic plans and implementation roadmaps that align with NIST SP 800‑171 control families, CMMC 2.0 Level 2 practices, and DFARS 252.204‑7012 mandates
- Evaluates contracts, Statements of Work, and vendor agreements to ensure inclusion of FAR 52.204‑21, DFARS 252.204‑7012, and other funding, legal, and program requirements, and verifies contractors’ System Security Plans and POA&Ms meet NIST SP 800‑171 standards
- Performs risk assessments per NIST SP 800‑30 methodology—identifying threats, vulnerabilities, and impacts—to support cost‑benefit analyses and residual risk decisions under DFARS requirements
- Interprets U.S. Codes (Titles 10, 18, 32, 50), Presidential Directives, OMB A‑130, and federal/state privacy laws to inform organizational cybersecurity and privacy policies
- Analyzes audit findings, continuous monitoring data, and non‑compliance trends to assess their impact on CMMC maturity and enterprise cybersecurity effectiveness, and prepares detailed audit and assessment reports mapping findings to NIST SP 800‑171 controls with prioritized remediation strategies and POA&Ms
- Promotes awareness of cybersecurity and privacy principles—least privilege, defense in depth, data minimization—across all levels of management to embed them into the organization’s mission and goals
- Provides expert guidance on cyber threats (phishing, ransomware, insider threat) and network security methodologies (firewalls, IDS/IPS, segmentation) as outlined in NIST SP 800‑171 families SC and SI
- Collaborates with General Counsel, External Affairs, and business units to ensure that new and existing systems, services, and vendor practices comply with DFARS 252.204‑7012 CUI safeguarding, privacy obligations, and organizational consent/authorization requirements
- Crafts clear, role‑based policies, SOPs, and instructional materials that align privacy objectives with security controls and satisfy CMMC 2.0 practice statements
- Translates complex technical and planning information into concise briefings for non‑technical stakeholders to secure buy‑in for NIST and CMMC initiatives
- Monitors advancements in information privacy laws, accreditation standards, CMMC updates, and privacy‑enhancing technologies to adapt organizational controls and maintain compliance
- Works across IT, Legal, HR, and other departments to integrate privacy and security objectives, ensuring business processes support both CUI protection and operational goals
- Determines whether security incidents constitute privacy breaches under applicable legal standards and coordinates necessary legal and regulatory actions
- Other duties as required
Supervisory Responsibilities:
- Oversees and manages compliance activities including other compliance staff
Qualifications, Knowledge, Skills, and Abilities:
Education:
- High School Diploma or GED, required
- Bachelor's degree in computer science, cybersecurity, information technology, software engineering, information systems, or computer engineering, preferred
- Annual 40 hours of continuous learning, (may include professional memberships, forums, lunch and learns, roundtables, online training courses, and maintaining certifications), required
Experience:
- Five (5) or more years of relevant experience, required
License/Certifications:
- Industry‑recognized certifications, such as CISM, CASP +, CISSP, CISA, Security +, or other IT credentials demonstrating knowledge management fundamentals, preferred
Other Knowledge, Skills, and Abilities:
- Knowledge of FedRAMP, NIST SP 800-53, NIST SP 800-171, NIST CSF, Cybersecurity Maturity Model Certification (CMMC)
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s