ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION OVERVIEW Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure ...
ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION OVERVIEW Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure ...
ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION OVERVIEW Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure ...
ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION OVERVIEW Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure ...
ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE)POSITION OVERVIEWZermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure that ...
Quick apply
ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE)POSITION OVERVIEWZermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure that ...
National Security Compliance Analyst
$145K - $185K/yr
Medical
Life
Retirement
We have an immediate need for a National Security Compliance Analyst to provide onsite support at the Mark Center in Alexandria, VA. Responsibilities ISAG has a need for an experienced legal expert ...
National Security Compliance Analyst
$145K - $185K/yr
Medical
Life
Retirement
We have an immediate need for a National Security Compliance Analyst to provide onsite support at the Mark Center in Alexandria, VA. Responsibilities ISAG has a need for an experienced legal expert ...
Information Security Compliance Coordinator
Washington, DC ยท Remote
$60K - $75K/yr
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
Quick apply
Information Security Compliance Coordinator
Washington, DC ยท Remote
$60K - $75K/yr
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
Quick apply
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
Information Security Compliance Coordinator
Washington, DC ยท Remote
$60K - $75K/yr
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
Information Security Compliance Coordinator
Washington, DC ยท Remote
$60K - $75K/yr
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
About the Information Security Compliance Specialist position We are looking for a talented cybersecurity professional to join our team in Suitland, MD. You will provide information security support ...
About the Information Security Compliance Specialist position We are looking for a talented cybersecurity professional to join our team in Suitland, MD. You will provide information security support ...
Information Security Compliance Coordinator
Washington, DC ยท On-site
$55K - $65K/yr
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
Information Security Compliance Coordinator
Washington, DC ยท On-site
$55K - $65K/yr
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in ...
National Security Compliance Analyst
Alexandria, VA ยท On-site
$145K - $185K/yr
Medical
Life
Retirement
We have an immediate need for a National Security Compliance Analyst to provide onsite support at the Mark Center in Alexandria, VA. Responsibilities ISAG has a need for an experienced legal expert ...
National Security Compliance Analyst
Alexandria, VA ยท On-site
$145K - $185K/yr
Medical
Life
Retirement
We have an immediate need for a National Security Compliance Analyst to provide onsite support at the Mark Center in Alexandria, VA. Responsibilities ISAG has a need for an experienced legal expert ...
About the Information Security Compliance Specialist position We are looking for a talented cybersecurity professional to join our team in Suitland, MD. You will provide information security support ...
About the Information Security Compliance Specialist position We are looking for a talented cybersecurity professional to join our team in Suitland, MD. You will provide information security support ...
About the Information Security Compliance Specialist position We are looking for a talented cybersecurity professional to join our team in Suitland, MD. You will provide information security support ...
Quick apply
About the Information Security Compliance Specialist position We are looking for a talented cybersecurity professional to join our team in Suitland, MD. You will provide information security support ...
National Security Compliance Analyst
Alexandria, VA ยท On-site
$145K - $185K/yr
Medical
Life
Retirement
We have an immediate need for a National Security Compliance Analyst to provide onsite support at the Mark Center in Alexandria, VA. Responsibilities ISAG has a need for an experienced legal expert ...
National Security Compliance Analyst
Alexandria, VA ยท On-site
$145K - $185K/yr
Medical
Life
Retirement
We have an immediate need for a National Security Compliance Analyst to provide onsite support at the Mark Center in Alexandria, VA. Responsibilities ISAG has a need for an experienced legal expert ...
This role combines security compliance, controls engineering, and automation to improve the efficiency, accuracy, and scalability of our federal security program. You will identify opportunities to ...
This role combines security compliance, controls engineering, and automation to improve the efficiency, accuracy, and scalability of our federal security program. You will identify opportunities to ...
This role combines security compliance, controls engineering, and automation to improve the efficiency, accuracy, and scalability of our federal security program. You will identify opportunities to ...
This role combines security compliance, controls engineering, and automation to improve the efficiency, accuracy, and scalability of our federal security program. You will identify opportunities to ...
This role combines security compliance, controls engineering, and automation to improve the efficiency, accuracy, and scalability of our federal security program. You will identify opportunities to ...
This role combines security compliance, controls engineering, and automation to improve the efficiency, accuracy, and scalability of our federal security program. You will identify opportunities to ...
They are seeking a Senior Security Compliance Automation Engineer to enhance security compliance and FedRAMP operations through automation and analytics, while collaborating with various teams to ...
They are seeking a Senior Security Compliance Automation Engineer to enhance security compliance and FedRAMP operations through automation and analytics, while collaborating with various teams to ...
Manager - Information Security Compliance
Reston, VA ยท Hybrid
$135K - $183K/yr
Verisign is seeking a hands-on technical manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. In this role, you will support an enterprise-wide governance ...
Manager - Information Security Compliance
Reston, VA ยท Hybrid
$135K - $183K/yr
Verisign is seeking a hands-on technical manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. In this role, you will support an enterprise-wide governance ...
Information Security Compliance Specialist
Washington, DC ยท On-site
Medical
Life
The Information Systems Compliance Specialist will conduct Security Assessment and Authorization (A&A) support for USSS IT systems. This candidate must have the ability to work onsite at customer HQ ...
Information Security Compliance Specialist
Washington, DC ยท On-site
Medical
Life
The Information Systems Compliance Specialist will conduct Security Assessment and Authorization (A&A) support for USSS IT systems. This candidate must have the ability to work onsite at customer HQ ...
Manager - Information Security Compliance
Reston, VA ยท On-site
$135K - $183K/yr
Verisign is seeking a hands-on technical manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. In this role, you will support an enterprise-wide governance ...
Manager - Information Security Compliance
Reston, VA ยท On-site
$135K - $183K/yr
Verisign is seeking a hands-on technical manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. In this role, you will support an enterprise-wide governance ...
Security Compliance information
See Silver Spring, MD salary details
$33.6K - $42.2K
6% of jobs
$42.2K - $50.7K
0% of jobs
$50.7K - $59.3K
6% of jobs
$65.4K is the 25th percentile. Wages below this are outliers.
$59.3K - $67.8K
17% of jobs
The median wage is $75.9K / yr.
$67.8K - $76.4K
21% of jobs
$76.4K - $84.9K
7% of jobs
$84.9K - $93.5K
9% of jobs
$93.5K - $102K
7% of jobs
$102.4K is the 75th percentile. Wages above this are outliers.
$102K - $110.6K
12% of jobs
$110.6K - $119.1K
6% of jobs
$119.1K - $127.7K
7% of jobs
$33.6K
$83.9K
$127.7K
How much do security compliance jobs pay per year?
What is security compliance?
What are the key skills and qualifications needed to thrive as a security compliance professional?
How does a security compliance professional typically collaborate with other departments to ensure adherence to regulations?
What is the difference between Security Compliance vs Security Analyst?
| Aspect | Security Compliance | Security Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CISSP, CEH, Security+ |
| Work Environment | Policy development, audits, regulatory adherence | Monitoring, threat analysis, incident response |
| Employer & Industry Usage | Organizations ensuring regulatory compliance | Organizations analyzing security threats and vulnerabilities |
Security Compliance focuses on ensuring organizations meet security standards and regulations through policies and audits. Security Analysts actively monitor and respond to security threats. While both roles require security certifications, Compliance emphasizes policy adherence, whereas Analysts focus on threat detection and incident management.
How to become a security compliance officer?
Is a career in security compliance worth it?
What are popular job titles related to Security Compliance jobs in Silver Spring, MD?
For Security Compliance jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Security Compliance jobs in Silver Spring, MD look for?
The top searched job categories for Security Compliance jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Security Compliance jobs?
Cities near Silver Spring, MD with the most Security Compliance job openings:

Full-time
Re-posted 16 hours ago
Job description
POSITION OVERVIEW
Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure that federal information systems comply with Information Assurance and cybersecurity standards. The SCE ensures that federal information systems are secure in operation, not merely compliant with documentation. This role directly contributes to mission assurance by identifying, validating, and mitigating real-world cybersecurity risks across enterprise environments.
The SCE operates at the intersection of compliance, engineering, and mission operations, transforming federal mandates (e.g., NIST RMF, FISMA, EO 14028, OMB directives) into measurable, technically enforced security outcomes. Rather than relying solely on static assessments, the role requires continuous evaluation of the system's security posture by directly analyzing configurations, logs, architectures, and control implementations.
This position is designed for individuals with foundational technical expertise across multiple domains, including cloud platforms, network architecture, operating systems, identity systems, and databases. You must be able to independently assess systems, identify exploitable conditions, and validate whether implemented controls effectively reduce risk in real-world scenarios.
The role is a core component of Zermount's Modern GRC mindset, emphasizing:
- Continuous monitoring of system compliance responsibilities
- Real-time risk identification and prioritization
- Direct integration with system teams to drive remediation
- Elimination of "check-the-box" compliance practices
You will be responsible for producing decision-quality outputs that enable system owners, ISSOs, and leadership to make informed, risk-based decisions. This includes identifying control failures, recommending technically sound remediation strategies, and validating that corrective actions are effective and sustainable.
DUTIES & RESPONSIBILITIES
General Duties
- Execute RMF lifecycle (Prepare-Monitor) while validating controls directly in operational environments
- Identify and document real-time risks through analysis of logs, telemetry, configurations, and architecture
- Validate implementation of security controls (STIGs, MFA, encryption, access control) using system-level evidence
- Identify exploitable misconfigurations, weak trust boundaries, and gaps across cloud, network, OS, and database layers
- Drive POA&M actions by prioritizing risk based on exploitability and mission impact, ensuring closure within defined timelines
- Perform continuous monitoring (ISCM/CDM) with emphasis on actual system behavior vs. reported compliance
- Translate NIST, EO 14028, OMB, and TIC 3.0 requirements into specific technical remediation actions
- Validate remediation actions with repeatable verification methods (not documentation review)
- Produce executive-quality outputs (risk findings, remediation plans, executive summaries)
- Maintain system artifacts and documentation only as a byproduct of validated technical work
SUBJECT MATTER EXPERTISE (SME)
SME Area #1 - Primary Expertise: Technical Risk Validation (Modern GRC Execution)
Expert-level means:
- Ability to independently assess systems using direct technical inspection techniques, leveraging logs, configs, architecture documents, etc.
- Deep working knowledge of critical frameworks and directives such as:
- NIST RMF (800-37, 800-53, etc.)
- FISMA, EO 14028, OMB M-21-31 / M-22-09
- FIPS 199/200
- TIC 3.0 and Zero Trust principles (CISA ZT MM, NIST 800-207, etc.)
- Ability to identify threat surfaces within specific systems, not just control gaps
- Ability to convert compliance requirements into specific and actionable remediation actions that the system teams can be used to successfully remediate findings
Required Tools Experience:
- Vulnerability scanning tools such as: Tenable, Qualys, CrowdStrike, etc.
- Log analysis platforms such as: Splunk, Microsoft Sentinel, IBM QRadar, etc.
- Configuration and system inspection tools such as: Ansible, Terraform, Puppet etc.
- GRC platforms such as: Archer, ServiceNow, etc.
SME Area #2 - Secondary Expertise: Multi-Domain Technical Depth
You must have deep knowledge of one or more of the following technical domains and must demonstrate the ability to leverage this experience to inform and complete compliance-related tasks.
Technical Domains
- Cloud: AWS/Azure (IAM, logging, network security, misconfigurations)
- Network: Segmentation, firewalls, boundary protections, Zero Trust enforcement points
- Systems: Windows/Linux hardening, identity systems (AD, MFA)
- Databases/Data: Access control, encryption, auditing
QUALIFICATIONS
Minimum Requirements
- 5+ years of cybersecurity experience supporting U.S. Government systems
- 4+ years performing RMF, ISSO, Assessment, or GRC functions with direct technical validation responsibilities
- Demonstrated hands-on experience in at least two technical domains (cloud, network, systems, or databases)
- Proven ability to analyze:
- System configurations, ATOs, and other supporting security documentation
- Logs/telemetry
- Architecture documentation and data flow diagrams
Preferred Qualifications
- Experience implementing or assessing Zero Trust architectures
- Experience with CDM, ISCM, and enterprise logging programs
- Familiarity with threat-informed defense concepts
- Experience in hybrid cloud environments
Competency
- Technical risk identification and prioritization
- Independent problem-solving in ambiguous environments
- Ability to translate policy into technical action
- Clear communication with both engineers and leadership
Education & Certifications
- Bachelor of Science (B.S.) in Computer Science, IT, Cybersecurity, or a related field, and a minimum of 5 years of IT cybersecurity experience, including direct support for the US Government and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role.
- Without a B.S. in a relevant field - A minimum of 10 years of IT Cybersecurity experience, including direct support for the US Government, and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role.
- At least one of the following security certifications is required:
- Certified Authorization Professional (CAP)
- Certified Information Security Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP), or Certified Chief Information Security Officer (CCISO)
- Governance Risk & Compliance Certification (CGRC)
- Or alternatively approved certifications
Clearance Level
Minimum of active Secret Clearance and ability to obtain and maintain DHS suitability
WORK LOCATION
- The position is primarily remote - Continental U.S only
- Primary location when on site: Arlington, VA, and Springfield, VA
- Must be willing to travel - Not to exceed 10% of the time
HOURS OF OPERATION
- 8:00 am EST - 4:30 pm EST
- Times may fluctuate based on client and business requirements
REPORTING STRUCTURE
- Reports To: Security Compliance Engineering Team Lead
- Direct Reports: N/A
About Zermount
Sourced by ZipRecruiter
Industry
Network security
Company size
11 - 50 Employees
Headquarters location
Arlington, VA, US
Year founded
2013