Cyber Security NIST/CMMC Documentation Specialist bei American Roll-on Roll-off Carrier Group
American Roll-on Roll-off Carrier Group · Parsippany, Vereinigte Staaten Von Amerika · Hybrid
- Professional
- Optionales Büro in Parsippany
American Roll-on Roll-off Carrier (ARC) is seeking an experienced Cybersecurity Compliance Specialist with 5+ years of hands-on experience implementing and maintaining controls under NIST SP 800-171 (CMMC Level 2) within a U.S. Government contractor environment where Controlled Unclassified Information (CUI) is processed.
The ideal candidate will be responsible for developing, maintaining, and updating comprehensive compliance documentation, including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), policies, procedures, and other supporting artifacts. This role requires proven experience authoring detailed documentation aligned to established control frameworks, as well as preparing for and supporting third-party assessments and audits to validate compliance readiness.
Note: This position is not intended for network engineers or system administrators. The focus is on documentation, governance, and compliance rather than hands-on configuration or system operations.
In this role you will:
- Develop and maintain NIST 800-171 / CMMC Level 2 POA&Ms, system security plans (SSPs), detailed policy & procedure documentation and supporting evidence/artifacts.
- Be execution responsible for the implementation of (and continuous review, update and reverification of) the Company’s IT-related security and compliance requirements and initiatives.
- Collaborate with both internal resources as well as external consultants and auditors, to facilitate compliance reviews, assessments and gap analyses.
- Prepare for and facilitate CMMC assessments, including self-assessments and third-party audits by Certified Third-Party assessor Organizations (C3PAO).
- Assist internal teams in understanding CMMC requirements and their impact on organizational processes, technology, and security posture.
- Develop and deliver cyber-related training programs for employees/stakeholders.
- Provide security awareness training on recognizing and reporting potential indicators of insider threats.
- Stay current on CMMC program changes and evolving cybersecurity standards from NIST and other relevant bodies.
- Gain thorough understanding of all of the Company’s technology, and the business and operational processes they facilitate, sufficiently to evaluate controls and identify risk and compliance concerns.
- Develop and verify IT-related remediation and contingency plans.
- Develop and review, on a continuous basis, cybersecurity advisories, logs and reports, to assure security.
- Design/identify, implement, and maintain automated solutions, to facilitate proactive notifications of security-related issues/incidents – including unauthorized or inappropriate configuration changes.
- Be a reliable, responsible, and accountable self-starter, able to prioritize tasks and work independently.
Job Requirements:
Required skills/experience:
- Minimum of 3 years of experience in a Corporate IT environment, in a hands-on role dedicated to information security compliance , systems security, IT risk management, IT audit, or similar/related.
- Demonstrated hands-on experience with NIST 800-171 and ISO-27001 controls.
- Hybrid position, but must be within commuting distance to Northern NJ for regular meetings. Occasional domestic USA travel (Washington/Virginia, Jacksonville FL).
- Experience independently evaluating controls which are applied to technology-driven processes.
- Experience authoring and maintaining detailed documentation which define policies, procedures and execution plans, and as proof/support of compliance.
- Strong knowledge of enterprise Information Security pillars (Perimeter security, Identity Management and Governance, Privileged Account Management, Compliance, Penetration testing, Encryption, Cloud Security, Incident Response, Vulnerability Management).
- Familiarity with a variety of technologies, operating systems, databases, and reporting and data analytics tools.
- Ability to effectively communicate security-related concepts to a broad range of technical and non-technical professionals.
- Excellent project and time management and organizational skills.
- Eligibility for security clearance.
- Bachelor’s degree in Computer Science, Cyber/Information Security, or similar.
A plus if you have any of these:
- Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISM), Certified Information Systems Manager (CISA), GIAC (Global Information Assurance Certification)/GSNA (GIAC Systems & Network Auditors) or other similar certification(s).
- Demonstrated experience with NIST 800-53, NIST CSF, SANS / CIS Top 20, Fedramp, FISMA, GDPR.
- Security clearance (active or recent expired).
Target Salary to $135k (DOE)
About ARC
ARC provides global logistics and shipping services to the U.S. Government. ARC and its affiliates own and manage the largest U.S. flag roll-on roll-off (Ro-Ro) fleet. This includes providing American-owned, managed, and crewed RoRo shipping and intermodal services committed to the requirements of the Department of Defense, other U.S. Government departments and agencies, and commercial customers.
OUR COMMITMENT TO EQUAL OPPORTUNITIES
We are a global group of people from diverse backgrounds and lifestyles. ARC is proud to be an equal opportunity employer committed to building a workplace where all contributors feel they can bring their best selves every day, learn from each other, and be appreciated. Our journey towards sustainable and integrated logistics compels us to attract people with diverse experiences, skills, and abilities.
Pay Type :Salary Jetzt bewerben