Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
IT Compliance Supervisor - Public Sector, Operations image - Rise Careers
Job details

IT Compliance Supervisor - Public Sector, Operations

Job Summary: 

The IT Compliance Supervisor leads the development and oversight of the compliance program and its staff, supporting governance, risk, and compliance efforts across Information Technology teams, business executives, and their respective organizations.
 

Job Duties:

  • Advises senior leadership on interpreting and applying FedRAMP, NIST SP 800‑53, NIST SP 800‑171 Rev 2, NIST CSF, CMMC 2.0, and ISO 27000 requirements to optimize cybersecurity posture and CUI protection
  • Develops and maintains multi‑year strategic plans and implementation roadmaps that align with NIST SP 800‑171 control families, CMMC 2.0 Level 2 practices, and DFARS 252.204‑7012 mandates
  • Evaluates contracts, Statements of Work, and vendor agreements to ensure inclusion of FAR 52.204‑21, DFARS 252.204‑7012, and other funding, legal, and program requirements, and verifies contractors’ System Security Plans and POA&Ms meet NIST SP 800‑171 standards
  • Performs risk assessments per NIST SP 800‑30 methodology—identifying threats, vulnerabilities, and impacts—to support cost‑benefit analyses and residual risk decisions under DFARS requirements
  • Interprets U.S. Codes (Titles 10, 18, 32, 50), Presidential Directives, OMB A‑130, and federal/state privacy laws to inform organizational cybersecurity and privacy policies
  • Analyzes audit findings, continuous monitoring data, and non‑compliance trends to assess their impact on CMMC maturity and enterprise cybersecurity effectiveness, and prepares detailed audit and assessment reports mapping findings to NIST SP 800‑171 controls with prioritized remediation strategies and POA&Ms
  • Promotes awareness of cybersecurity and privacy principles—least privilege, defense in depth, data minimization—across all levels of management to embed them into the organization’s mission and goals
  • Provides expert guidance on cyber threats (phishing, ransomware, insider threat) and network security methodologies (firewalls, IDS/IPS, segmentation) as outlined in NIST SP 800‑171 families SC and SI
  • Collaborates with General Counsel, External Affairs, and business units to ensure that new and existing systems, services, and vendor practices comply with DFARS 252.204‑7012 CUI safeguarding, privacy obligations, and organizational consent/authorization requirements
  • Crafts clear, role‑based policies, SOPs, and instructional materials that align privacy objectives with security controls and satisfy CMMC 2.0 practice statements
  • Translates complex technical and planning information into concise briefings for non‑technical stakeholders to secure buy‑in for NIST and CMMC initiatives
  • Monitors advancements in information privacy laws, accreditation standards, CMMC updates, and privacy‑enhancing technologies to adapt organizational controls and maintain compliance
  • Works across IT, Legal, HR, and other departments to integrate privacy and security objectives, ensuring business processes support both CUI protection and operational goals
  • Determines whether security incidents constitute privacy breaches under applicable legal standards and coordinates necessary legal and regulatory actions
  • Other duties as required

Supervisory Responsibilities: 

  • Oversees and manages compliance activities including other compliance staff 
     

Qualifications, Knowledge, Skills, and Abilities: 

Education:

  • High School Diploma or GED, required
  • Bachelor's degree in computer science, cybersecurity, information technology, software engineering, information systems, or computer engineering, preferred
  • Annual 40 hours of continuous learning, (may include professional memberships, forums, lunch and learns, roundtables, online training courses, and maintaining certifications), required

Experience:

  • Five (5) or more years of relevant experience, required

License/Certifications:

  • Industry‑recognized certifications, such as CISM, CASP +, CISSP, CISA, Security +, or other IT credentials demonstrating knowledge management fundamentals, preferred

Other Knowledge, Skills, and Abilities: 

  • Knowledge of FedRAMP, NIST SP 800-53, NIST SP 800-171, NIST CSF, Cybersecurity Maturity Model Certification (CMMC)
  • Knowledge of computer networking concepts and protocols, and network security methodologies
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk)
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy
  • Knowledge of cybersecurity and privacy principles
  • Knowledge of cyber threats and vulnerabilities
  • Knowledge of specific operational impacts of cybersecurity lapses
  • Knowledge of applicable business processes and operations of customer organizations
  • Knowledge of Privacy Impact Assessments
  • Knowledge of applicable laws, statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code), Presidential Directives, executive branch guidelines, and/or administrative/criminal legal guidelines and procedures
  • Knowledge of what constitutes a "threat" to a network
  • Knowledge of who the organization's operational planners are, how, and where they can be contacted, and the expectation
  • Knowledge of privacy disclosure statements based on current laws
  • Skill in creating policies that reflect the business's core privacy objectives
  • Skill in communicating with all levels of management (e.g., interpersonal skills, approachability, effective listening skills, appropriate use of style and language for the audience)
  • Ability to develop clear directions and instructional materials
  • Ability to develop policy, plans, and strategy in compliance with laws, regulations, policies, and standards in support of organizational cyber activities
  • Ability to develop, update, and/or maintain standard operating procedures (SOPs).
  • Ability to select the appropriate implant to achieve operational goals
  • Ability to tailor technical and planning information to a customer's level of understanding
  • Ability to monitor advancements in information privacy laws to ensure organizational adaptation and compliance
  • Ability to work across departments and business units to implement organization's privacy principles and programs and align privacy objectives with security objectives
  • Ability to monitor advancements in information privacy technologies to ensure organizational adaptation and compliance
  • Ability to determine whether a security incident violates a privacy principle or legal standard requiring specific legal action
BDO USA Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
BDO USA DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of BDO USA
BDO USA CEO photo
Wayne Berson
Approve of CEO

Average salary estimate

$90000 / YEARLY (est.)
min
max
$80000K
$100000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
BDO USA Hybrid Tampa, Florida, United States
Posted yesterday

We're looking for an experienced Associate to elevate client experiences by expertly documenting and analyzing technical specifications.

GDI is looking for a skilled Team Lead, Applications Specialist to manage their Omni & Digital Support team and enhance application performance.

Posted 5 days ago

Become a key player at Fait Distribution as our IT Infrastructure Manager, leading dynamic teams in a supportive and innovative environment.

Photo of the Rise User
Posted 6 days ago

Join Airwallex as a GRC Specialist where you will play a pivotal role in enhancing enterprise security and compliance frameworks.

Parsons Hybrid US - VA, Fort Eustis
Posted 8 days ago

Join Parsons as a Senior Intelligence Threat Analyst where you will leverage your expertise in intelligence to support Army operations at Fort Eustis, VA.

Become a pivotal part of a leading global financial services firm as a Senior Cybersecurity Engineer specializing in container security.

Photo of the Rise User
AbbVie Hybrid North Chicago, IL
Posted 3 days ago

Become a pivotal part of AbbVie's mission as a Service Operations Lead in our Business Technology Solutions team, driving digital transformation in healthcare.

Photo of the Rise User
Medtronic Hybrid Northridge, California, United States of America
Posted 6 days ago

Lead ERP strategy and execution at Medtronic, focusing on innovation and excellence in diabetes care.

BCI Brands Hybrid No location specified
Posted yesterday

Join BCI in transforming the fashion industry as an IT Solutions Analyst, dedicated to enhancing customer experience through technical support.

Photo of the Rise User
Posted 8 days ago

Join Agile Defense as an Infrastructure Deployment Manager to lead IT deployment initiatives and support critical missions.

Abacus Technology seeks a Systems Administrator II to enhance Endpoint Security support for the Air Force's vital network operations.

Photo of the Rise User
Posted 10 days ago
Inclusive & Diverse
Collaboration over Competition
Growth & Learning
Mission Driven
Transparent & Candid

As a Security Analyst at Coinbase, you'll protect digital assets while collaborating with some of the best in the industry to enhance security measures and incident response strategies.

Seeking a knowledgeable Pharmacy Informatics Specialist to support clinical systems at Children's Mercy, enhancing pediatric care through technology.

Photo of the Rise User
Accenture Remote Cincinnati, 4th Street, Corp
Posted 6 days ago

Join Accenture as an Oracle Database Administrator and leverage your expertise to drive transformation in our clients’ businesses.

Providing trusted solutions in an ever changing world.

120 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 24, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!