×
Register Here to Apply for Jobs or Post Jobs. X

Compliance Specialist, IT​/Tech

Job in Tucson, Pima County, Arizona, 85718, USA
Listing for: Winsor Consulting Group, LLC
Full Time position
Listed on 2026-03-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 60000 - 80000 USD Yearly USD 60000.00 80000.00 YEAR
Job Description & How to Apply Below

Job Description

Winsor Consulting Group is seeking a detail‑oriented Compliance Specialist to support the execution and delivery of client‑facing compliance engagements. This role is responsible for developing structured documentation, supporting governance, risk, and compliance (GRC) initiatives, and assisting clients in achieving and maintaining CMMC and other regulatory compliance requirements.

Department:
Security & Compliance

Reports to:

Director of Compliance

Job Duties
  • Support CMMC Level 1 and Level 2 readiness assessments, including control validation and gap analysis.
  • Conduct CUI flow discovery sessions to identify how Controlled Unclassified Information (CUI) is processed, stored, and transmitted within client environments.
  • Develop and maintain formal CUI Flow Diagrams and data flow documentation aligned to defined CMMC assessment scope boundaries.
  • Assist in defining CMMC assessment scope based on documented CUI flows and asset categorization.
  • Develop and maintain System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), policies, standards, and structured compliance documentation.
  • Assist in translating CMMC and NIST SP 800171 requirements into actionable administrative and technical controls.
  • Conduct control walkthroughs and collect objective evidence aligned to NIST SP 800171A assessment objectives.
  • Track remediation activities and support structured POA&M management through to closeout.
  • Perform cross‑framework control mapping for CMMC, HIPAA, and CJIS where applicable.
  • Maintain compliance evidence repositories and ensure documentation accuracy, completeness, and version control.
  • Collaborate with engineering teams to validate implementation of technical safeguards supporting regulatory requirements.
  • Assist with third‑party assessment coordination, including preparation for C3

    PAO engagements.
  • Support client‑facing meetings and provide compliance status reporting under the direction of the Director of Compliance.
  • Monitor regulatory updates and assist in updating internal compliance templates and methodologies.
  • Contribute to standardized compliance delivery processes and internal quality assurance efforts.
Preferred Skills
  • Strong working knowledge of CMMC 2.0 and NIST SP 800171 requirements.
  • Experience developing SSPs, POA&Ms, CUI flow diagrams, and formal security policies aligned to federal frameworks.
  • Familiarity with evidence collection and documentation practices supporting audit readiness.
  • Ability to perform cross‑framework control mapping (CMMC ↔ HIPAA ↔ CJIS).
  • Strong documentation, analytical, and organizational skills.
  • Working understanding of security technologies (e.g., MFA, logging, encryption, vulnerability management) and their role in compliance.
  • Ability to clearly communicate compliance requirements to technical and non‑technical stakeholders.
  • Experience working within an MSP or consulting environment preferred.
Experience
  • 37 years of experience in cybersecurity compliance, risk management, or governance.
  • Direct experience supporting CMMC or NIST SP 800171 implementations preferred.
  • Experience conducting CUI flow identification and documenting system scope boundaries.
  • Experience drafting and maintaining formal security documentation.
  • Experience supporting external audits or regulatory assessments preferred.
  • Experience supporting DoD contractors or other regulated environments highly preferred.
Preferred Certifications

Relevant professional certifications such as CMMC RP, CCP, CompTIA Security+, CySA+, or similar foundational security certifications.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary