Talent.com
Security Compliance Manager
Security Compliance ManagerGDIT • (VAHOME), Office, Home, VA, USA
Security Compliance Manager

Security Compliance Manager

GDIT • (VAHOME), Office, Home, VA, USA
30+ days ago
Job type
  • Full-time
Job description

Job Description:

We are GDIT. We support and secure some of the most complex government, defense, and intelligence projects across the country. At GDIT, cyber security is not just a singular part of our mission—it connects every one of us because it’s embedded into every aspect of what we do.

GDIT is your place. You make it your own by bringing your ideas and unique perspective to our culture. By owning your opportunity at GDIT, you are helping us ensure today is safe and tomorrow is smarter. As a Security Compliance Manager, you will lead our security team in solving challenging problems for our client, the Division of Federal Systems (DFS) for the Office of Child Support Services (OCSS) under Health and Human Services (HHS) Administration for Children & Families (ACF).

Our team provides program support to DFS OCSS to manage and monitor the development, implementation, operation, maintenance, technical support, and enhancement of the division’s systems and services. Federal Parent Locator Service (FPLS) information is, by statute, made available to child support agencies and a limited number of federal and state agencies. These secure systems and services help child support agencies, employers, insurers, and financial institutions exchange information about child support cases; locate parents; establish paternity, custody and visitation; collect support; and identify fraud.

Currently, this role is hybrid. When on-site traveling is required, the work location for this position is the Department of Health and Human Services Mary Switzer Building near Federal Center Southwest in Washington, D.C.

This role’s core responsibilities consist of the following but not limited to:

People Management:

  • Lead and develop a high-performing security team of 3-4 FTEs to ensure compliance with security standards, while maintaining strong, proactive relationships with customers to meet their unique needs effectively
  • Serve as the primary point of contact for all client interactions, emphasizing strategic oversight and exemplary service to align with both organizational goals and customer expectations
  • Lead team meetings and represent security in Governance, Technical Operations, Change Advisory Board, and Technical Review Boards

Federal Systems, Security & Compliance Governance:

  • Develop and enforce security policies and procedures in compliance with Federal mandates, OMB, NIST standards, HHS/ACF & FPLS security requirements, and customer guidance regarding zero trust, supply chain, risk management, vulnerability management, etc.
  • Industry Knowledge: Stay abreast of emerging trends, technologies, and regulatory changes in the federal security compliance landscape and provide recommendations for adapting policies and procedures accordingly

Security Authorization:

  • Security Control Monitoring: Continuously monitor the implementation of security controls by collaborating with stakeholders, conducting regular internal assessments/audits, and recommend corrective actions as needed.
  • Provide guidance to the design and development teams on security issues and assist as needed in the development of security documentation (specifically, System Security Plan (SSP)) for Security Authorization
  • Assist the FPLS ISSO, FPLS ITSSO and Technical Manager to ensure that FPLS upholds all security requirements to maintain the ACF Authority to Operate

Risk Management:

  • Provide oversight to ensure comprehensive risk assessments and vulnerability scanning is performed of system portfolio to identify potential vulnerabilities and weaknesses in the organization's security posture
  • Participate in routine and on-demand system and application vulnerability scanning, document findings and recommendations, and present analysis of results to stakeholders
  • Document and track internal POAMs for DFS systems and applications

Incident Response & Reporting:

  • Maintain Incident Response (IR) Plan
  • Develop comprehensive reports detailing the nature and impact of each data incident and ensure timely notification to senior management and relevant government officials
  • Monitor and track data incidents through remediation and closure
  • Collaborate with internal teams and external stakeholders to effectively manage and resolve data incidents, ensuring adherence to established protocols and regulatory requirements
  • Utilize root cause analyses to enhance incident response procedures, mitigate risks, and improve overall data security posture and to minimize the risk of recurring incidents
  • Maintain accurate and comprehensive records of all data incidents, including incident details, response actions, and outcomes
  • Ensure proper documentation of incident resolution, lessons learned, and recommended preventive measures

Audits & Compliance:

  • Plan and execute regular audits to assess compliance with federal security standards and regulatory requirements
  • Support the Security Team in responding to external audits conducted by the HHS Inspector General (IG), Internal Revenue Service (IRS) and other Federal agencies as required
  • Support systems security evaluations, audits, and reviews.
  • Prioritize and coordinate the resolution of audit findings.

Contingency Planning/Disaster Recovery:

  • Maintain and update IT contingency plans and disaster recovery procedures.
  • Support DR exercises (tabletop, functional, etc.)

Security Site Assessments:

  • Lead security site assessments conducted on data-matching partner sites and FPLS contractor sites. This includes planning, reviewing relevant documents, writing comprehensive reports, and reviewing/responding to Plans of Action and Milestones (POAMs)
  • Questionnaire Review: Review questionnaires submitted by our matching partners to assess their adherence to security controls and requirements.
  • Conduct kickoff meetings and virtual audits to validate the implementation of appropriate security measures

Security Awareness Training:

  • Manage security trainings to educate staff on federal security requirements and best practices, ensuring that all training meets the compliance standards set by ACF, HHS, and the IRS
  • Assist in the development and delivery of Security Awareness Training as required

Stakeholder Communication:

  • Communicate effectively with various stakeholders, including senior management, IT teams, legal teams, and external auditors, to convey compliance issues, risks, and remediation plans.
  • Support the client in communicating and publishing security alerts, advisories, and bulletins as necessary
  • Documentation: Maintain accurate and up-to-date documentation of compliance activities, audit findings, and remediation efforts.

Technology:

  • Proficiency or familiarity with project management tools, particularly Jira, is preferred. The ability to effectively utilize Jira for task tracking, issue management, and collaboration is highly desirable.

WHAT YOU’LL NEED TO SUCCEED:

  • Bachelor's degree in Computer Science, Information Systems, or in a related field
  • Minimum of 5 years of experience working as a Federal Security Compliance Analyst with at least 5 years leadership experience in managing teams
  • 2 years security compliance experience NIST, FedRAMP, FISMA, OMB, ZTA, Supply Chain knowledge

PREFERRED QUALIFICATIONS:

  • Relevant security certifications (e.g., CISSP, CISM, CISA) are highly desirable

GDIT IS YOUR PLACE:

  • 401K with company match
  • Comprehensive health and wellness packages
  • Internal mobility team dedicated to helping you own your career
  • Professional growth opportunities including paid education and certifications
  • Cutting-edge technology you can learn from
  • Rest and recharge with paid vacation and holidays

The likely salary range for this position is $140,250 - $189,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Hybrid

Work Location:

USA DC Home Office (DCHOME)

Create a job alert for this search

Security Compliance Manager • (VAHOME), Office, Home, VA, USA

Similar jobs

Assistant Warden: Dillwyn Correctional Center #00002

State of VirginiaBuckingham, VA, United States
Full-time

Title: Assistant Warden: Dillwyn Correctional Center #00002 State Role Title: Security Manager III Hiring Range: $78,280.Pay Band: 6 Agency: Dept of Corr - Central Admin Location: Dillwyn Correctio...Show more

 • Promoted

Deputy Ground Software Lead

Northrop GrummanVA, United States
Full-time

RELOCATION ASSISTANCE: Relocation assistance may be available.CLEARANCE REQUIRED FOR START: Yes.At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems tha...Show more

 • Promoted

PT Quality Assurance Assoc

Food LionVA, United States
Full-time

USA-VA-Manakin Sabot-30 Broad Street.Food Lion has been providing an easy, fresh and affordable shopping experience to the communities we serve since 1957.Today, our 82,000 associates serve more th...Show more

 • Promoted

Site Safety Health Officer / SSHO

Johnson ControlsVirginia, VA, United States
Full-time

We are seeking a Site Safety and Health Officer (SSHO) to join our federal team in the Norfolk, VA regional area.At Johnson Controls, we support our nation’s most critical facilities, the people wh...Show more

 • Promoted

Client Solutions Manager

Slice Merchant ServicesLandtown, VA, US
Full-time

Excellent opportunity to join a leading, national credit card processing company that has over a decade of industry experience.Slice Merchant Services offers innovative payment processing solutions...Show more

 • Promoted

Cloud / Automation Engineer - Secret Cleared

Global TechProVA, US
Full-time

Automation / DevOps Engineer — Cloud & Infrastructure Full-time · DevOps Practice · Remote/Hybrid About the role We are looking for an automation-minded engineer who thrives at the intersection of ...Show more

 • Promoted

Guidance Navigation Control (GNC) Engineer – Level 5

Northrop GrummanVA, United States
Full-time

RELOCATION ASSISTANCE: Relocation assistance may be available.CLEARANCE REQUIRED FOR START: Yes.At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems tha...Show more

 • Promoted

Mission Manager - Active Security Clearance

CadreVA, USA
Full-time
Quick Apply

Serve as a specialized officer providing direct support to a client driving complex worldwide operations to develop actionable intelligence against the highest priority threats to US national secur...Show more

Master at Arms

US NavyChristiansted, Virginia, United States
Full-time

Job Title: Security & Law Enforcement (Master-at-Arms).Category / Component: Enlisted • Active.Master-at-Arms (MA) Sailors provide the Navy's core security, antiterrorism, and law enforcement capab...Show more

 • Promoted

Shift Leader

Pizza HutAppomattox, VA, United States
Part-time

The person holding this supervisory position is considered a part time team member and is responsible and accountable for: the daily operation of the restaurant, assisting the RGM with hiring and t...Show more

 • Promoted

Border Patrol Agent (BPA) Experienced - New Hire Sign-On and Retention Incentives

US Customs and Border ProtectionCharlotte Court House, Virginia, US
Full-time

Border Patrol Agent (BPA) – in the Federal Security and Public Safety Sector Experienced (GL-9 GS-11).Is your CV ready If so, and you are confident this is the role for you, make sure to apply asap...Show more

 • Promoted

Management Analyst

U.S. Department of StateVA, US
Permanent

Open and Close Dates: Apr 23, 2026 - Apr 30, 2026 Marketing Statement: Summary: This position is located in Human Resources Management, Office of the Executive Director, Bureau of Diplomatic Securi...Show more

 • Promoted

Quality Control Manager

FluxVA, United States
Full-time

This project is for the Design-Build, Multi-Purpose Dynamic Training Range (P-306), Fort Barfoot, Virginia.The work will take place out in the range training areas of Fort Barfoot.The work includes...Show more

 • Promoted

Program Analyst

U.S. Department of StateVA, US
Permanent

Open and Close Dates: Apr 09, 2026 - Apr 15, 2026 Marketing Statement: Summary: This Program Analyst position resides within the Office of the Chief Technology Officer (CTO), Office of the Executiv...Show more

 • Promoted

Shift Manager

Pizza HutAppomattox, VA, United States
Full-time

The person holding this supervisory position is considered a full time team member and is responsible and accountable for: the daily operation of the restaurant, assisting the RGM with hiring and t...Show more

 • Promoted

Director of Certification

The Monitoring AssociationDhs, Virginia, US
Full-time

Position Overview: TMA is seeking a strategic, growth-oriented Director of Certification to lead and expand its portfolio of certification programs for companies and individuals.Are you the right a...Show more

 • Promoted • New!

Calling all mid-career TS-cleared Guidance Navigation Control (GNC) Engineers!

Northrop GrummanVA, United States
Full-time

RELOCATION ASSISTANCE: Relocation assistance may be available.CLEARANCE REQUIRED FOR START: Yes.At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems tha...Show more

 • Promoted

Named Account Executive, State Government (Justice and Public Safety)

Salesforce, Inc.VA, United States
Full-time

To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Salesforce is the #1 AI CRM, where humans with age...Show more