C

IT Security & Compliance Lead

Job Description - IT Security & Compliance Lead



  • Key Responsibilities:



    • Strong understanding of security program and control frameworks, assessment methodologies, and practices, e.g., NIST 800-171, CMMC, NIST RMF, NIST CSF, ISO 27001/2, and FedRAMP

    • Strong understanding of data controls and compliance regimens involving CUI, export control, and data privacy

    • Experience with cybersecurity programs in the Defense and/or Federal/Civilian

    • Experience with the conduct of security assessments

    • Ability to communicate technical security concepts to non-technical audiences

    • Experience leading compliance programs

    • Effective program management, project management, and organization management skills

    • Certification such as Certified Information Systems Security Professional (CISSP) or the Certified Information Systems Auditor (CISA) preferred.


    Required Experience:



    • 7+ years of experience in an IT security or compliance role

    • 3+ years of experience working directly with CMMC and/or DFARS -7012 compliance

    • 2+ years writing polices, requirements, or similar documents

    • Bachelor's degree or 4+ years of experience in a relevant field


    Required Skills:



    • Strong understanding of security program and control frameworks, assessment methodologies, and practices, e.g., NIST 800-171, CMMC, NIST RMF, NIST CSF, ISO 27001/2, and FedRAMP

    • Strong understanding of data controls and compliance regimens involving CUI, export control, and data privacy

    • Experience with cybersecurity programs in the Defense and/or Federal/Civilian

    • Experience with the conduct of security assessments




















Education, Experience and Certification
























Required/Preferred



Education Level



Description



Required



Bachelors Degree



computer science, information technology, or related field


























Required/Preferred



Years of Experience



Description



Required



5 years



Experience in an IT security or compliance role


Experience with cybersecurity programs in the Defense and/or Federal/Civilian


Experience leading compliance programs


























Required/Preferred



License/Certification



Description



Preferred



Certification



CISA





Knowledge, Skills, and Abilities



  • Advanced understanding of security program and control frameworks, assessment methodologies, and practices e.g. NIST RMF, NIST CSF, ISO-27001, 800-53, 800-171, CMMC, CNSSI 1253, 800-137, PCI-DSS, GDPR, HITRUST, etc.

  • Advanced understanding of data controls and compliance regimens including CUI, ITAR/ EAR, PCI, PII, etc.

  • Ability to communicate technical security concepts to non-technical audiences

  • Effective program management, project management, and organization management skills

  • Certification such as Certified Information Systems Security Professional (CISSP) or the Certified Information Systems Auditor (CISA) preferred.


Travel Requirements



  • What percentage of their role do they have to leave their base location? Base location is a specific office or home location. Up to 10%.


 


Disclaimer


This job description is subject to change by the employer as the needs of the employer and requirements of the job change.


We maintain a drug-free workplace and perform pre-employment substance abuse testing.


J&J Worldwide Services CBRE Government and Defense Business is thrilled at the opportunity for you to apply to one of our roles. This position may also be eligible for a wide range of competitive benefits that can include but not limited to: medical, well-being, financial planning and short-term incentives benefits.




Due to compliance requirements imposed by a federal contract, this position may be filled by U.S. Persons only. U.S. Persons includes: U.S. citizens, U.S. nationals, lawful permanent residents, individuals granted refugee status in the U.S., and individuals granted asylum in the U.S.   


This description is not intended to be an “all inclusive” list of the accountabilities of the job described. Rather, it describes the general nature of the job. In addition, some aspects of this job may change over time, according to business needs, and these changes may not be recorded immediately. Requirements stated represent the minimum levels of knowledge, skills and/or abilities to qualify and satisfactorily perform this job.


THIS DOCUMENT SHOULD NOT BE CONSTRUED AS CREATING A CONTRACT OF EMPLOYMENT BETWEEN J&J WORLDWIDE SERVICES AND ANY OF ITS EMPLOYEES OR OTHERWISE ALTERING AN EMPLOYEE’S AT WILL EMPLOYMENT RELATIONSHIP WITH J&J WORLDWIDE SERVICES.




 

Original job IT Security & Compliance Lead posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar IT Security & Compliance Lead Jobs in the US

GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast! Find the best jobs in the US, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.