IonQ logo
IonQ

Our mission: to build the world’s best quantum computers to solve the world’s most complex problems.

Governance, Risk, and Compliance Engineer

ComplianceComplianceFull TimeRemoteMid LevelTeam 201-500Since 2015H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

$83.4K - $109.2K / year

Seniority

Mid Level

Bachelor Degree2 yrs expEnglishCloudCyber Security

Job Description

Governance, Risk, and Compliance Engineer

IonQ

• Own end-to-end CMMC implementation and audit readiness, including scoping, control mapping, SSP and POA&M development, evidence collection, and remediation tracking. • Interpret and apply DFARS clause requirements, including DFARS 252.204-7012, 252.204-7019, and 252.204-7020, translating contractual obligations into operational controls and maintaining accurate SPRS submissions. • Conduct recurring internal audits of NIST 800-171 security controls on a defined cadence to validate continued compliance, and support preparation for C3PAO assessments including evidence packages and assessment logistics. • Assess CUI environments to meet CMMC boundary requirements, including network segmentation, access control, media protection, and FIPS-validated encryption, and evaluate cloud environments against CMMC scoping guidance. • Implement technical controls across NIST 800-171 practice families, including MFA, audit logging, configuration management, incident response, and vulnerability management. • Serve as a CMMC subject matter resource, contributing to compliance roadmaps, facilitating readiness workshops, and advising on DFARS flow-down requirements for subcontractors. • Collaborate with legal and contracts teams to review FAR/DFARS clauses in new and existing contracts, flagging CUI obligations and CMMC level requirements, and coordinate on ITAR and EAR obligations as they intersect with CUI handling. • Support the organization’s GRC platform for evidence management, POA&M tracking, and risk register maintenance, and contribute to compliance dashboards for leadership.

Job Requirements

  • 2–4 years of professional experience in cybersecurity, compliance, or IT security, with direct exposure to NIST SP 800-171 or CMMC compliance programs.
  • Experience developing or contributing to SSPs, POA&Ms, and assessment artifacts, and participating in CUI environment scoping.
  • Working knowledge of DFARS cybersecurity clauses (7012, 7019, 7020) and the CMMC 2.0 framework.
  • A technical background in systems administration, cloud security, or security engineering sufficient to engage with IT and engineering teams on control implementation.
  • Bachelor’s degree in Computer Science, Information Security, or equivalent practical experience.

Benefits

  • Comprehensive medical, dental, and vision plans
  • Matching 401K
  • Unlimited PTO and paid holidays
  • Parental/adoption leave
  • Legal insurance
  • Home technology stipend

Related Categories

Related Job Pages

More Compliance Jobs

IonQ logo

Senior Governance, Risk, and Compliance Engineer

IonQ

Our mission: to build the world’s best quantum computers to solve the world’s most complex problems.

Compliance3 days ago
Full TimeRemoteTeam 201-500Since 2015H1B Sponsor

• Architect and own end-to-end CMMC implementation and audit readiness, including scoping strategy, control mapping, SSP and POA&M development, evidence collection, and remediation tracking across the organization. • Interpret and apply DFARS clause requirements, including DFARS 252.204-7012, 252.204-7019, and 252.204-7020, translating contractual obligations into operational controls and owning accurate SPRS submissions. • Lead recurring internal audits of NIST 800-171 security controls and drive end-to-end preparation for C3PAO assessments, including evidence packages, assessment logistics, and assessor coordination. • Architect CUI environments to meet CMMC boundary requirements, including network segmentation, access control, media protection, and FIPS-validated encryption; lead evaluation of cloud environments against CMMC scoping guidance. • Drive implementation of technical controls across NIST 800-171 practice families, including MFA, audit logging, configuration management, incident response, and vulnerability management, engaging directly with engineering teams. • Serve as the primary CMMC subject matter expert at IonQ, developing compliance roadmaps, facilitating readiness workshops, and providing authoritative guidance on DFARS flow-down requirements for subcontractors. • Partner with legal and contracts teams to review FAR/DFARS clauses in new and existing contracts, flagging CUI obligations and CMMC level requirements, and lead coordination with regulatory teams on ITAR and EAR obligations as they intersect with CUI handling. • Develop and operate a formal risk management program covering IT systems and infrastructure, maintain a risk register, and provide regular executive-level reporting on posture, open risks, and remediation progress. • Own and mature the organization’s GRC platform to support evidence management, POA&M tracking, and risk register maintenance, and build compliance dashboards for leadership visibility.

United States
$110.3K - $144.5K / year
Saks logo

International Trade Compliance Coordinator

Saks

The premier digital platform for luxury fashion

Compliance3 days ago
Full TimeRemoteTeam 1,001-5,000Since 1924H1B Sponsor

• The Import Coordinator will be responsible for overseeing the delivery of incoming goods • Classifying import documentation from multiple Brokers/Carriers/etc. • Acting as liaison to warehouse/store stakeholders as well as external brands/brokers • Lead meetings w/ team and other groups • Create reporting for key department metrics and analyze for trends/outliers.

Texas
$46K - $58K / year
University Health Partners of Hawai'i (UCERA) logo

Contracts & Compliance Specialist

University Health Partners of Hawai'i (UCERA)

The faculty practice of the John A. Burns School of Medicine and the UH Health Sciences. #WEAREUHPHAWAII

Compliance3 days ago
Part TimeRemoteTeam 201-500Since 2005H1B No Sponsor

• Provides contracting, compliance, and general legal support services to organization primarily with support to the CEO & Chief Compliance Officer (GC & CCO) and Paralegal/Contracts Administrator • Assists with the review and execution of all UHP employment agreements, service agreements, and other agreements. • Administers contracting process; maintains procedures for tracking contracts; drafts contracts and contract amendments as assigned; reviews agreements for unacceptable language, terms and conditions; negotiates terms as necessary with other party. • Ensures agreements and terms are in compliance with federal, state, and other applicable laws and with internal UHP policies. • Organizes, tracks, and maintains database on agreements. • Assists with the administration and implementation of the corporate compliance program, including the training and education program. • Assists with the development and maintenance of the policies and procedures surrounding the overall compliance program, with an emphasis on privacy compliance. • Manages special projects and programs related to healthcare compliance. • Supports the Compliance Officer and Privacy Officer with management of the compliance program, including communication and dissemination of documents. • Performs research as assigned, including both library and internet-based research. • Screens legal inquiries and provides routine advice and referral to reference sources when assistance of Counsel is not required to address issues. • Prepares reports, correspondence, forms as needed. • Reviews legal forms for accuracy. • Complies with all legal requirements and company policies. • Performs all other duties as assigned.

Hawaii
$0 - $40 / hour
Lumen Technologies logo

CMMC Compliance Analyst

Lumen Technologies

Lumen Technologies is self-described as a global company of 40,000+ professionals empowering businesses, government, and communities to “produce amazing things.” Driven by the

Compliance3 days ago
Full TimeRemoteTeam 10,001

Role Description The CMMC Compliance Analyst must have advanced practical experience in managing all phases of security integration to assist the Security Manager and Director with managing the personnel, physical, information, and information systems (IS) security requirements for DoD, SCI and SAP activities as applicable to the program supported. They will write all standard operating procedures, maintain fixed facility checklists (FFCs), and author systems security plans in accordance with ICDs, DCIDs, and NISPOM requirements. They will serve as a liaison to government program security officers (PSO), information systems security counterparts, and Lumen internal and external clients. Conduct initial and recurring training, prepare and process access requests, conduct indoctrinations and debriefings, and investigate and report security violations. Conduct self-inspections, maintain associated security paperwork and media control records, conduct virus scanning and computer security briefings, and provide data containment support, including coordinating clean-up efforts and reporting requirements. Location This is a remote opportunity open to candidates located anywhere in the U.S. Main Responsibilities - Execute continuous monitoring activities across a CMMC L2 enclave, ensuring ongoing compliance with NIST SP 800-171 controls - Maintain audit-ready evidence repositories, including policies, procedures, and technical artifacts - Perform periodic control assessments, validation, and remediation tracking - Support POA&M management, including identification, documentation, and closure of findings - Leverage GRC tools to manage controls, track compliance status, and maintain evidence - Collaborate with system owners, engineers, and ISSOs to ensure proper control implementation and sustainment - Prepare for and support C3PAO assessments, surveillance reviews, and re-certification activities - Track and report compliance status, risks, and metrics to leadership - Assist in updating SSPs, network diagrams, data flow diagrams, and supporting documentation Qualifications - CMMC Registered Practitioner Advanced (RPA) - CMMC Certified Professional (CCP) certification within the first six months - Demonstrated experience supporting a successful CMMC Level 2 C3PAO assessment - Experience with continuous monitoring, audit preparation, and compliance documentation - Strong working knowledge of NIST SP 800-171 controls and assessment objectives - Working knowledge of FAR, DFARS, and CMMC-related cybersecurity and contracting requirements for Defense Industrial Base contractors - Familiarity with evolving CMMC requirements - Experience integrating GRC platforms into continuous monitoring workflows and reporting - Familiarity with POA&M management and remediation processes - Ability to work in a structured, compliance-driven environment with strong attention to detail Preferred Qualifications - CMMC Certified Assessor (CCA) certification - Experience supporting FedRAMP Moderate or High ATO environments - Hands-on experience using GRC tools such as ServiceNow IRM, Diligent, Archer, or similar platforms - Understanding of cloud environments (Azure Gov, AWS GovCloud) in regulated enclaves Compensation This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. - $105,786 - $141,047 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, WY - $111,074 - $148,099 in these states: CO, HI, MI, MN, NC, NH, NV, OR, RI - $116,364 - $155,152 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, WA Benefits Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process. Life at Lumen Life at Lumen is human and connected, even in a fast moving, AI‑focused organization. We set clear expectations and trust people to meet them. With real support and shared accountability, teams collaborate better, move faster, and deliver meaningful outcomes. Our Lumen 8 behaviors guide how we interact, make decisions, and work together, shaping a culture built to perform and win. Background Screening If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page. Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis. Equal Employment Opportunities We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training. Privacy Notice Lumen is committed to protecting the privacy and security of personal information collected during the recruitment and hiring process. Our Privacy Notice explains how we collect, use, disclose, and protect applicant information, as well as how individuals may request access to or deletion of their personal data. Disclaimer The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.

United States
$105.8K - $155.2K / year