Security & Compliance Administrator

SOSi

United States

Remote

USD 110,000 - 170,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SOSi is seeking a Security & Compliance Administrator to support a DoD customer with a scalable, federated data ecosystem emphasizing RMF, NIST 800-53, and DoD IL4/IL5 controls.

The role involves monitoring deployments, performing vulnerability scans, maintaining SSPs/SARs, and enforcing encryption, IAM/RBAC policies, and audit logging across cloud and on‑prem environments.

Qualifications

  • Active in scope secret clearance.
  • Bachelor’s degree or five years of equivalent security experience.
  • Proficient in NIST 800-53, FedRAMP, and DoD IL-4/IL-5 security policies.
  • Experience with IAM, SIEM solutions, and vulnerability frameworks.

Responsibilities

  • Monitor and validate Kubernetes and data lake deployments for RMF/NIST/DoD IL4/IL5 compliance.
  • Maintain continuous monitoring dashboards and conduct vulnerability scans to support ATO.
  • Prepare and update SSPs, SARs, and POA&Ms reflecting changes to architecture or risk conditions.
  • Enforce encryption, logging, and IAM RBAC audit policies across the data layer.
  • Submit the Security & Compliance Assessment Report with findings and remediation actions.

Skills

IAM
SIEM
Zero-trust
Vulnerability assessment
Security monitoring
DoD RMF
NIST 800-53
RBAC

Education

Bachelor’s degree in Cybersecurity
Five years of equivalent security experience

Tools

Splunk
Cloud security tooling

Job description

Company Description

Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Job Description
**This position is contingent upon award of contract**

SOSi is seeking a Security & Compliance Administrator to support mission requirements for a structured approach to further develop, integrate, and sustain a scalable, federated data ecosystem that enhances interoperability, governance, and mission-driven analytics for a DoD customer. The primary objective of the program is to bridge the operational gaps between DoD, IC, interagency, and non-traditional international partners to enable real-time information sharing, dynamic data integration, and mission-tailored analytical capabilities.

Essential Job Duties
  • The contractor shall monitor and validate Kubernetes and data lake deployments for compliance with RMF, NIST 800-53, and DoD IL4/IL5 requirements, in collaboration with agency cybersecurity teams.
  • The contractor shall maintain continuous monitoring dashboards and conduct vulnerability scans of deployed infrastructure and workloads, supporting the agency’s ATO process and risk posture.
  • The contractor shall prepare and update system security documentation—including SSPs, SARs, POA&Ms—to reflect changes to architecture, controls, or risk conditions under other work orders.
  • The contractor shall enforce encryption, logging, and identity access policies (IAM, RBAC, audit logging) to maintain traceability and accountability across the Kubernetes-based data layer.
  • The contractor shall submit the Security & Compliance Assessment Report, providing a summary of control effectiveness, findings, and recommended remediation actions.
Qualifications
  • Active in scope secret clearance.
  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or a related field, or five (5) years of equivalent experience in security and compliance roles.
  • Proposed personnel possess the knowledge and capability to implement, monitor, and enforce security policies, frameworks, and compliance controls across cloud-based and on-premises environments.
  • Personnel must be proficient in NIST 800-53, FedRAMP, DoD IL-4/5 security policies, and risk assessment methodologies.
  • Strong understanding of identity and access management (IAM), security monitoring tools (Splunk, SIEM solutions), zero-trust architecture, and vulnerability assessment frameworks is required.
  • Experience in conducting security audits, assessing system compliance with DoD cybersecurity policies, and implementing security controls in cloud and hybrid environments.
  • Experience with security automation, endpoint protection, and incident response processes is required.
Preferred Qualifications
  • Desirable but not required certifications include Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or AWS Certified Security – Specialty.
Additional Information
Working Conditions
  • Remote. Offsite.
Working at SOSi

All interested individuals will receive consideration and will not be discriminated against for any reason.

Get your free, confidential resume review.

or drag and drop your file here.