View job listing
This is an advisory compliance role, not a 24x7 operational cybersecurity role. It emphasizes documentation, AI governance, and audit readiness within IGC’s authorized scope. The Contracting Officer approves AI use, and Government security, privacy, legal, and civil-liberties determinations remain Government functions.
Apply to Cybersecurity and AI Compliance Specialist
Position overview
Info Gain Consulting (IGC) is seeking a Cybersecurity and AI Compliance Specialist to provide advisory cybersecurity, sensitive-information safeguarding, access-readiness, and responsible-AI governance support for an advisory engagement serving a federal law-enforcement and intelligence customer. You will own the AI Compliance and Risk Management Plan, maintain the AI tool and use-case approval inventory, support Controlled Unclassified Information (CUI) controls, and coordinate training, nondisclosure, PIV, encryption, incident-reporting, and Section 508 activities.This is an advisory compliance role, not a 24x7 operational cybersecurity role. It emphasizes documentation, AI governance, and audit readiness within IGC’s authorized scope. The Contracting Officer approves AI use, and Government security, privacy, legal, and civil-liberties determinations remain Government functions.
Key responsibilities
- Advise the program on safeguarding CUI, PII, SPII, and other sensitive information consistent with contract requirements and Government direction.
- Develop and maintain baseline cybersecurity-compliance procedures, checklists, artifact inputs, and marking and handling guidance.
- Coordinate tracking of required training, Rules of Behavior, nondisclosure agreements, background-investigation actions, PIV steps, and access readiness.
- Maintain incident-reporting procedures aligned to the contract’s one-hour initial reporting requirement and support Government-directed response.
- Advise on FIPS-validated encryption, secure transmission, storage, access control, and data-handling practices.
- Own, draft, submit through the Program Manager, and maintain the AI Compliance and Risk Management Plan.
- Maintain a current inventory of proposed and approved AI and generative-AI tools, use cases, data flows, and approval status.
- Ensure restricted Government data is not entered into AI tools absent express written authorization and applicable safeguards.
- Define AI safeguards including role-based access, logging, encryption, human review, bias mitigation, non-discrimination, and misuse prevention.
Required qualifications
- Bachelor’s degree in cybersecurity, information assurance, information systems, computer science, privacy engineering, risk management, or a related field; four additional years of directly relevant experience may substitute for the degree.
- At least 7 years in cybersecurity compliance, information-system security, CUI or sensitive-information protection, security authorization support, or AI governance.
- Working knowledge of NIST security and privacy controls, FIPS-validated encryption, incident reporting, access control, and CUI handling.
- Demonstrated experience creating or maintaining security-compliance plans, procedures, checklists, inventories, or audit evidence.
- Understanding of DHS 4300A or comparable policy and the distinction between advisory compliance support and system-operation or authorizing-official responsibilities.
- Experience assessing AI or automated-system use cases for data handling, access, human review, bias, misuse, or non-discrimination risks.
- Strong analytical writing, policy interpretation, incident communication, and records-management skills.
- Proficiency with Microsoft 365, secure collaboration tools, and compliance trackers.
Preferred qualifications
- Experience supporting DHS, CBP, another federal law-enforcement or intelligence organization, or a comparable secure mission environment.
- CISSP, CGRC/CAP, CISM, Security+, or comparable credential aligned to actual duties.
- Experience developing AI governance plans, model or use-case inventories, approval workflows, or responsible-AI controls.
- Familiarity with Section 508, supply-chain risk management, PIV/HSPD-12, privacy documentation, or CUI programs.
- Experience supporting security authorization or ATO documentation while preserving the distinction between contractor support, independent assessment, and Government authorization.
