
Business Information Security & Compliance Officer
Scientific Research Corporation
- North Charleston, SC
- Permanent
- Full-time
- Advising and supporting the business unit in the implementation and documentation of cybersecurity controls aligned with DFARS, NIST SP 800-171, and CMMC requirements
- Conducting or supporting gap assessments, defining remediation actions, tracking progress through POAMs, and supporting the maintenance of accurate System Security Plans (SSPs)
- Supporting the development, implementation, and maintenance of cybersecurity policies and procedures in compliance with FAR, DFARS, NIST SP 800-171, and CMMC
- Serving as a trusted partner to business stakeholders, helping to interpret security requirements and balance risk and compliance with operational needs
- Guiding the division on security best practices, emerging threats, and compliance obligations
- Collaborating with cross-functional teams including IT, Contracts, Procurement, Engineering, and Program Management to support secure and compliant operations
- Assisting in preparation for audits or assessments, including internal reviews and external CMMC evaluations
- Staying informed on evolving industry trends, regulatory requirements, threat landscape changes, emerging cybersecurity risks, and technologies to ensure the organization remains at the forefront of federal cybersecurity practices
- Contributing to the continuous improvement of the organization’s cybersecurity and compliance posture by identifying inefficiencies and proposing enhancements
- Bachelor’s degree in Information Security, Information Systems, Information Technology, Cybersecurity or a related field
- 10+ years of work experience in Information Security, Cybersecurity, IT Security, or Governance, Risk and Compliance functions
- 3+ years of hands-on experience implementing or supporting NIST SP 800-171/171A and/or 800-53 controls withing a corporate or program environment
- 2+ years of experience in an organization with at least 1000 employees
- Strong understanding of information security principles, practices, and technologies, including network security, application security, cloud security and endpoint security
- Experience reviewing and defining security policies, procedures and solutions that support compliance and business objectives
- Experience conducting risk assessments, compliance gap assessments and control remediation
- Prior experience as a liaison between business units and information security and compliance teams
- Demonstrated ability to understand and interpret business and programs security and compliance needs, and translate security and compliance requirements into practical, business-aligned solutions
- Excellent communication, presentation, and interpersonal skills to collaborate directly with business stakeholders, technical teams, and compliance staff
- Effective time management and organizational skills, capable of managing multiple projects and priorities
- Demonstrated professional growth and career progression with increasing levels of responsibility
- Working knowledge of DFARS 252.204-7012/7020/7021
- Experience supporting or preparing for Cybersecurity Maturity Model Certification (CMMC) assessments
- Previous experience creating, maintaining, or supporting System Security Plans (SSP) and Plans of Action and Milestones (POAM)
- Experience supporting or preparing for third-party cybersecurity audits, such as SOC 2, ISO/IEC 27001, FedRAMP, HIPAA, PCI-DSS
- Experience working in Microsoft O365 hybrid environment
- Familiarity with AI and emerging security technologies
- Previous experience as information security consultant or auditor
- Prior experience as a DoD contractor
- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified Information Security Manager (CISM)
- Up to 10% of the time