次の仕事の機会を見つけましょう

職種、スキル、勤務地で求人を検索できます。応募書類を準備する前に募集要件を確認しましょう。

魅力的な職種名を見つけることは、仕事探しの出発点です。業務内容、応募条件、働き方を自分の経験と照らし合わせましょう。このガイドでは、候補の絞り込み、応募書類の準備、提出先の確認を順番に進めるためのポイントを紹介します。

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

条件をクリア

検索結果: 7,991

Security/Compliance SMEKoniag Government ServicesRemote (United States)USD 105000-140000 per annualリモート勤務求人を見る ↗Sr. Software EngineerCentralReachRemote (United States)USD 140000-180000 per annualリモート勤務求人を見る ↗SENIOR AI SOLUTIONS ANALYST-REMOTE (REMOTE, NY, US, REMOTE)Compass Group USARemote (United States)USD 130000-140000 per annualリモート勤務求人を見る ↗Corporate Account Executive III - NACamundaRemote (Worldwide)リモート勤務求人を見る ↗Events Marketing Manager, EMEACustomer.ioRemote (Afghanistan, Albania, Algeria, Andorra, Angola, Antarctica, Armenia, Austria, Azerbaijan, Bahrain, Belarus, Belgium, Benin, Bosnia and Herzegovina, Botswana, Bouvet Island, Bulgaria, Burkina Faso, Burundi, Cabo Verde, Cameroon, Central African Republic, Chad, Comoros, Congo, Congo, The Democratic Republic of the, Cook Islands, Croatia, Curaçao, Cyprus, Czechia, Côte d'Ivoire, Denmark, Djibouti, Egypt, Equatorial Guinea, Eritrea, Estonia, Eswatini, Ethiopia, Faroe Islands, Finland, France, French Guiana, French Southern Territories, Gabon, Gambia, Georgia, Germany, Ghana, Gibraltar, Greece, Greenland, Guadeloupe, Guernsey, Guinea, Guinea-Bissau, Heard Island and McDonald Islands, Holy See (Vatican City State), Hungary, Iceland, Iran, Iraq, Ireland, Isle of Man, Israel, Italy, Jersey, Jordan, Kazakhstan, Kenya, Kosovo, Kuwait, Kyrgyzstan, Latvia, Lebanon, Lesotho, Liberia, Libya, Liechtenstein, Lithuania, Luxembourg, Madagascar, Malawi, Mali, Malta, Martinique, Mauritania, Mauritius, Mayotte, Moldova, Monaco, Montenegro, Morocco, Mozambique, Namibia, Netherlands, Niger, Nigeria, North Macedonia, Norway, Oman, Palestine, State of, Poland, Portugal, Qatar, Romania, Russian Federation, Rwanda, Réunion, Saint Barthélemy, Saint Helena, Ascension and Tristan da Cunha, Saint Martin (French part), Saint Pierre and Miquelon, San Marino, Sao Tome and Principe, Saudi Arabia, Senegal, Serbia, Seychelles, Sierra Leone, Sint Maarten (Dutch part), Slovakia, Slovenia, Somalia, South Africa, South Sudan, Spain, Sudan, Svalbard and Jan Mayen, Sweden, Switzerland, Syrian Arab Republic, Tajikistan, Tanzania, Togo, Tunisia, Turkey, Turkmenistan, Uganda, Ukraine, United Arab Emirates, United Kingdom, Uzbekistan, Western Sahara, Yemen, Zambia, Zimbabwe, Åland Islands)USD 93000-110000 per annualリモート勤務求人を見る ↗Sr. Member Engagement ManagerCarrot FertilityRemote (Worldwide)USD 125000-140000 per annualリモート勤務求人を見る ↗Patient Access Appeals Case ManagerNoctrix HealthRemote (Worldwide)リモート勤務求人を見る ↗Senior Technology Auditor, QAParexelRemote (India)リモート勤務求人を見る ↗
← 検索結果に戻る

Security/Compliance SME

Koniag Government Services

リモート勤務

勤務地
Remote (United States)
報酬
USD 105000-140000 per annual
勤務時間
Full Time
掲載日
2026年10月7日

応募する前に、企業のウェブサイトで現在も募集中かどうかと詳しい条件を確認してください。

仕事内容

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

This position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible. Koniag IT Systems, LLC a Koniag Government Services company, is seeking a Security/Compliance SME with a Secret security clearance to support KITS and our government customer. The position is remote. Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement. Koniag IT Systems, LLC a Koniag Government Services company, is seeking an experienced Security / Compliance Subject Matter Expert (SME) to support the Department of the Air Force (DAF) in advancing its enterprise Identity, Credential, and Access Management (ICAM) capabilities. This position will provide dedicated cybersecurity, compliance, and policy expertise across three concurrent System Enhancement Studies under Task Order 0003, covering Contested, Degraded, and Operationally Limited (CDO-L) ICAM environments, Non-Person Entity (NPE) Governance and Management, and the DAF365 Joiner, Mover, Leaver (JML) Transformation Framework. The ideal candidate is a seasoned cybersecurity and compliance professional with deep knowledge of DoD and DAF security policy frameworks, Zero Trust Architecture, and Defense ICAM compliance requirements who can ensure that all study architectural recommendations, governance frameworks, and implementation roadmaps are grounded in current regulatory requirements and defensible against Government security review. Note, this is study is for 120 days. All personnel assigned to this effort must hold a final Secret security clearance. The Security / Compliance SME will serve as the primary authority on cybersecurity policy, regulatory compliance, and security architecture alignment across all three studies within the DAF ICAM System Enhancement Studies effort. Working in close coordination with the Program Manager, Study Lead Engineers, and Identity Architects, the Security / Compliance SME will ensure that every architectural recommendation, governance workflow, and implementation roadmap produced across the three studies is fully aligned with applicable DoD, DAF, and Federal security mandates, Zero Trust requirements, and audit standards. The Security / Compliance SME will contribute substantive compliance and security content to each study's Technical Study Report and will serve as the authoritative reference point for all policy interpretation questions arising during the study period. Principal responsibilities will include but are not limited to: Serve as the authoritative policy and compliance reference across all three System Enhancement Studies, ensuring study outputs are aligned with applicable DoD, DAF, and Federal cybersecurity and identity management mandates throughout the study period. Review and interpret all applicable Government-Furnished Information (GFI) and regulatory references relevant to the studies, including NIST SP 800-63 (IAL, AAL, AMR), DoDI 8520.04, DoDI 8510.01, CJCSI 6510.01 audit standards, DAFMAN 17-1304, DAFGM2025-01, DoD/DoW X.509 Certificate Policy, and the DoD Zero Trust Reference Architecture. Provide security and compliance guidance to the CDO-L Study Lead Engineer to ensure the CDO-L edge identity architecture, disconnected operational procedures, break-glass access controls, PKI certificate validation approaches, and synchronization methodologies are fully aligned with DoD Zero Trust requirements and applicable classification-level security controls. Assess and document security posture management requirements for CDO-L edge node operations, including how endpoint security telemetry integrates with the identity layer and how autonomous access revocation can be enforced in the absence of enterprise policy directives, in alignment with DAF Zero Trust continuous verification requirements. Evaluate and document the Authority to Operate (ATO) implications of proposed CDO-L edge components, including accreditation requirements for new edge compute platforms operating in classified NIPRNet and SIPRNet environments, and provide realistic Government review and accreditation timeline inputs for the CDO-L implementation roadmap. Provide security and compliance guidance to the NPE Governance Study Lead Engineer to ensure proposed NPE attribute schemas, governance workflows, credential management policies, and target architecture are fully aligned with DoD PKI policy, NIST SP 800-63, DoDI 8520.04, and DAF ICAM governance mandates. Review and validate proposed NPE credential management governance rules, including PKI certificate and token-based authentication transition requirements, 90-day credential rotation enforcement, enterprise secret vault storage mandates, and hardcoded credential prohibition controls, against applicable DoD and DAF policy requirements. Assess Zero Trust Architecture alignment of the proposed NPE governance framework, including workload identity integration within the DoD ZTA framework, dynamic access control via Policy Decision Points (PDPs), and continuous authentication requirements for non-person entity populations. Define compliance requirements for NPE audit logging and monitoring, including integration of NPE activity logs with the Security Operations Center (SOC) and Enterprise Log Information, Coordinated Security, and Audit Repository (ELICSAR), and application of UEBA/AI-driven anomaly detection in alignment with CJCSI 6510.01 audit standards. Provide security and compliance guidance to the JML Transformation Framework Study Lead Engineer to ensure proposed attribute sanitization workflows, direct Microsoft Entra ID integration architecture, JML event-driven group management workflows, and base-level administrator delegation frameworks are aligned with DAF ICAM policy, Zero Trust continuous verification requirements, and applicable data handling standards. Review and validate the Leaver revocation architecture against DoD data retention policy requirements, including automated mailbox handling procedures, DAF365 license reclamation, Entra ID session token revocation, and Okta identity disablement sequencing, to ensure the architecture eliminates the window of exposure between member separation and full digital access revocation. Assess delegated provisioning frameworks for base-level administrators against applicable least-privilege, separation of duties, and audit trail requirements, ensuring that delegated provisioning capabilities are scoped appropriately and that all administrator actions are fully auditable. Conduct cross-study compliance gap analysis to identify areas where proposed architectures or governance frameworks require additional security controls, policy waivers, or ATO actions prior to implementation. Contribute compliance and security policy sections to all three Technical Study Reports, ensuring each report includes a clear regulatory compliance mapping that allows Government security reviewers to confirm alignment without extensive cross-referencing. Advise the Program Manager and Study Lead Engineers on emerging DoD and DAF cybersecurity policy developments that may affect study recommendations during the study period. Support the preparation of draft Performance Work Statements for subsequent implementation Task Orders, providing security and compliance requirement language suitable for inclusion in Government acquisition documents. Verify that all assigned personnel hold the required security clearances prior to engagement and notify the Government immediately of any clearance status changes. Education and Experience: Required: Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Systems, or a related field from an accredited college or university. 7+ years of experience in cybersecurity, information assurance, or security compliance in Defense or Federal government IT environments. Demonstrated experience interpreting and applying DoD and Federal cybersecurity policy frameworks including NIST SP 800-53, NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, and related mandates to enterprise IT system design and governance. Experience supporting Authority to Operate (ATO) processes for Defense information systems, including RMF package development, security control assessment, and accreditation timeline management. Active Secret security clearance (final adjudication required prior to assignment). Preferred: Master's degree in Cybersecurity, Information Assurance, or a related technical field. 10+ years of experience in Defense cybersecurity, information assurance, or ICAM compliance supporting DoD or Federal agency programs. Experience supporting security compliance for DAF, Air Force, Space Force, or other DoD component ICAM or identity management modernization programs. Direct experience with DAF-specific security mandates including DAFMAN 17-1304, DAFGM2025-01, and DAF Zero Trust implementation guidance. Required Skills and Competencies: Deep knowledge of DoD and Federal cybersecurity and identity management policy frameworks, including NIST SP 800-63, NIST SP 800-53, DoDI 8520.04, DoDI 8510.01, CJCSI 6510.01, DAFMAN 17-1304, and the DoD Zero Trust Reference Architecture. Strong understanding of Zero Trust Architecture (ZTA) principles and their application to enterprise ICAM systems, disconnected edge environments, non-person entity governance, and identity lifecycle management. Experience with the DoD Risk Management Framework (RMF) and Authority to Operate (ATO) process, including security control selection, continuous monitoring requirements, and accreditation timeline management for classified Defense information systems. Knowledge of PKI-based authentication, certificate lifecycle management, DoD/DoW X.509 Certificate Policy, and Common Access Card (CAC) authentication security requirements. Familiarity with enterprise ICAM platforms including Okta and SailPoint IdentityIQ sufficient to assess security control implementation, audit logging configurations, and governance workflow compliance. Knowledge of DoD audit standards and log management requirements, including CJCSI 6510.01 and integration with SIEM and SOC environments. Experience performing compliance gap analysis against DoD and Federal security mandates and documenting findings in formal technical reports suitable for Government review. Ability to interpret and apply complex, sometimes conflicting regulatory requirements across multiple applicable policy frameworks simultaneously. Experience advising technical engineers and architects on security and compliance requirements in a manner that enables practical, implementable solutions rather than creating design obstacles. Strong technical writing skills with the ability to produce formal compliance assessments, regulatory mapping documentation, and security requirement sections of technical study reports and draft Performance Work Statements. Ability to work collaboratively across cross-functional technical teams including study lead engineers, identity architects, cost analysts, and program managers. Exceptional communication skills in English—both written and oral—with the ability to communicate complex security and compliance requirements clearly to both technical engineers and senior non-technical Government stakeholders. Ability to obtain and maintain a Secret security clearance. Desired Skills and Competencies: Experience supporting security compliance for disconnected, air-gapped, or tactically deployed Defense IT systems, including CDO-L or DDIL environment accreditation requirements. Familiarity with DISA Security Technical Implementation Guides (STIGs) and their application to enterprise identity platform components including Okta and SailPoint deployments in classified environments. Knowledge of non-person entity (NPE) security governance requirements, including machine identity management, workload identity Zero Trust integration, and service account security policy. Experience assessing and documenting compliance requirements for AI-driven tools, AI Agents, and automated orchestration platforms operating within DoD environments under least-privilege and continuous authorization frameworks. Familiarity with enterprise secret vault platforms such as HashiCorp Vault or CyberArk and their associated security control and compliance requirements in DoD environments. Knowledge of DoD data retention policy requirements and their application to enterprise collaboration platform offboarding, including Microsoft 365 mailbox handling and litigation hold procedures. Experience contributing security and compliance content to draft Performance Work Statements or other Government acquisition documents for Defense IT programs. CISSP (Certified Information Systems Security Professional) certification. CISM (Certified Information Security Manager) certification. CAP (Certified Authorization Professional) or equivalent RMF-focused certification. Experience supporting DAF, Air Force, or Space Force cybersecurity, ICAM, or IT modernization programs. Familiarity with Agile development methodologies and their intersection with continuous ATO, ongoing authorization, and DevSecOps security compliance frameworks. Knowledge of emerging DoD cybersecurity policy developments relevant to ICAM, Zero Trust, and machine identity governance. Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at or by calling 703-488-9377 to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com. Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352 Originally posted on Himalayas

検索して比較し、応募を準備しましょう

次の仕事で活かしたい職種やスキルから検索を始めましょう。勤務地と職種の条件を調整し、求人を開いて担当業務を比較してください。結果がない場合は、短い検索語を試すか、条件を一つずつ外してみましょう。

必須条件と歓迎条件を分けて確認し、勤務時間、報酬、勤務地が掲載されている場合は目を通しましょう。リモート勤務でも、居住国、就労資格、勤務時間帯が指定されることがあります。現在の募集状況と詳しい条件は企業に確認してください。

募集要件に関連する実際の経験を選び、自分の役割と貢献を説明しましょう。数値は根拠がある場合にのみ使ってください。企業の応募方法に従い、送信前に連絡先、内容、PDFの表示を確認しましょう。

応募前の確認リスト

仕事探しに関するよくある質問

英語の求人が表示されるのはなぜですか?

職種名や説明文は企業が作成したものです。条件や要件を変えないように原文を掲載しています。操作画面とこのガイドは日本語です。日本語の検索で見つからない場合は、「software engineer」のように、掲載言語の職種名やスキル名でも検索してみてください。検索語が自動翻訳されるわけではありません。

リモート求人なら、どの国からでも働けますか?

必ずしもそうではありません。居住国、就労資格、勤務時間帯が指定されている場合があります。元の求人ページで条件を確認してください。記載がない場合は、自分の居住地から応募できると判断する前に企業へ確認しましょう。リモートという表示だけでは、勤務地の制限がないことは分かりません。

検索結果が出ない場合はどうすればよいですか?

より一般的な職種名や一つのスキルで検索し、条件を一つずつ外してみてください。同じような仕事でも企業によって呼び方が異なります。特定の求人が見つからなくなった場合は、企業の採用ページで求人番号を探しましょう。検索条件を広げても、終了した募集が再開するわけではありません。

ResumizeAIから応募が送信されますか?

応募ボタンは外部サイトを開きます。企業または採用サービスの案内に従い、そのサイトで送信を完了してください。ResumizeAIで応募書類を作成しただけでは応募は送信されません。リンク先が企業のトップページの場合は、該当する募集を探してから手続きを進めましょう。

応募書類とカバーレターはどう調整すればよいですか?

募集要件と、自分が説明できるプロジェクト、業務、成果を結び付けます。経験していない技術や実績を加えず、関連する経験を分かりやすく示してください。カバーレターでは応募理由を具体例とともに伝えます。指定された言語とファイル形式に従い、送信前に両方の書類を確認しましょう。