ICAM Policy & Compliance Advisor

OSI VISION LLC

  • San Antonio, TX
  • Permanent
  • Full-time
  • 2 days ago
Job Summary:The Policy & Compliance Advisor ensures that application onboarding processes align with Department of Defense (DoD) and Department of the Air Force (DAF) Identity, Credential, and Access Management (ICAM) policies, Risk Management Framework (RMF), and audit requirements. This role involves interpreting relevant policies, developing compliance documentation, maintaining audit trails, and supporting compliance testing during User Acceptance Testing (UAT) and validation cycles. The Advisor will also recommend policy improvements and collaborate with internal teams and auditors to ensure compliance and security standards are met.Job Duties:
  • Interpret and apply DoD/DAF ICAM policies, including DoDI 8500, DoDI 8520.04, IAM SRG, NIST 800-63, and related directives.
  • Develop and maintain compliance documentation, including System Security Plans (SSP), Security Assessment Reports (SAR), and Plans of Action & Milestones (POA&M) for each onboarded application.
  • Maintain a comprehensive audit trail of changes, approvals, and logs to support compliance and audit requirements.
  • Support compliance testing during UAT and validation cycles to ensure adherence to security standards.
  • Recommend updates and improvements to ICAM policies and compliance processes.
  • Collaborate with onboarding teams, security staff, and auditors to ensure clear communication and alignment with compliance requirements.
Required Qualifications:
  • Extensive experience in Risk Management Framework (RMF) compliance and Authority to Operate (ATO) package creation.
  • In-depth knowledge of DoD ICAM compliance frameworks and directives, including DoDI 8500, DoDI 8520.04, and NIST 800-63.
  • Proven experience preparing systems for Financial Improvement and Audit Readiness (FIAR) and ICAM-related audits.
  • Proficiency with governance tools such as Archer and eMASS, and familiarity with SailPoint and Okta compliance configurations.
  • Experience using collaboration tools (MS Teams, SharePoint) and documentation management systems.
  • Strong communication skills for engaging with auditors, security staff, and onboarding teams.
  • Active Security+ CE certification.
  • Active Secret clearance.
Preferred Qualifications:
  • Certifications: CISSP, GSLC, CASP, or CISM.
  • Advanced experience in developing SSPs, SARs, and POA&Ms for DoD environments.
  • Familiarity with supporting ICAM-related audits and interacting with auditor teams.
  • Expertise in recommending policy improvements to enhance compliance processes.

OSI VISION LLC