Senior Security Compliance Specialist
Description

About Fortem Technologies

Fortem Technologies is the global leader in airspace security, delivering advanced solutions that protect against today’s autonomous aerial threats while ensuring the safety of tomorrow’s advanced air mobility. Fortem’s AI-powered SkyDome® Family of Systems combines TrueView™ sensors, command-and-control software, and autonomous DroneHunter® interceptors to defend military, government, and commercial operations worldwide from hostile or unauthorized drones. Fortem is the only company authorized to deploy a drone-on-drone kinetic interceptor in U.S. airspace, and its technology has been validated in operational deployments across Europe, the Middle East, and East Asia.


Headquartered in Lindon, Utah, Fortem is privately held and backed by Lockheed Martin, DCVC, Toshiba, AE Industrial Partners, AIM13, Signia Venture Partners, and others.



Position Overview  

We are seeking an experienced IT Security Compliance Specialist to lead our organization's implementation, certification, and ongoing maintenance of Cybersecurity Maturity Model Certification (CMMC) Level 2 controls. This role owns the technical and administrative work required to protect Controlled Unclassified Information (CUI) in accordance with NIST SP 800-171, prepare the organization for its C3PAO assessment, and sustain continuous compliance across the contract lifecycle. The ideal candidate combines hands-on IT/security engineering skills with a strong understanding of DFARS 252.204-7012, CMMC assessment methodology, and federal contracting security requirements. 


Key Responsibilities  

Technical Security Controls & Infrastructure: Designing, deploying, and managing the technical backbone of the compliance program. 

  • Design, configure, and implement technical controls across access control, audit/accountability, configuration management, identification/authentication, incident response, media protection, physical security, risk assessment, system/communications protection, and system/information integrity domains. 
  • Deploy and manage supporting technologies: MFA, endpoint detection and response (EDR), SIEM/log management, data loss prevention, encryption (at rest and in transit), privileged access management, and network segmentation/enclaving for CUI. 

Compliance Readiness & Regulatory Engagement: Maintaining the compliance ecosystem required to demonstrate and sustain compliance and staying current with evolving requirements. 

  • Maintain the System Security Plan (SSP), Plan of Action and Milestones (POA&M), Network/Data Flow Diagrams, and control implementation evidence. 
  • Author and maintain required policies and procedures (Incident Response Plan, Access Control Policy, Configuration Management Plan, etc.) mapped to each control family. 
  • Maintain a centralized compliance evidence repository sufficient to support a C3PAO assessment. 
  • Manage recurring compliance activities: annual affirmations, periodic risk assessments, vulnerability scanning/patching cadence, access reviews, and audit log reviews. 
  • Establish a continuous monitoring program to track control effectiveness, configuration drift, and emerging vulnerabilities; track and remediate assessment findings within required timeframes. 
  • Serve as the primary technical point of contact during the CMMC Level 2 Certification Assessment (C3PAO) or Self-Assessment, as applicable. 
  • Coordinate with external assessors, consultants, and Registered Practitioner Organizations (RPOs) as needed. 
  • Maintain compliance through system changes, new vendor/subcontractor relationships (flow-down requirements), and IT infrastructure updates. 
  • Monitor changes to CMMC/DFARS/NIST 800-171 requirements and update the compliance program accordingly. 
  • Develop and deliver security awareness and role-based training required under CMMC. 
  • Partner with HR/Legal on insider threat and personnel security requirements tied to CUI access. 
  • Partner with Procurement/IT vendors to ensure third-party services (cloud, MSP, SaaS) meet CMMC/FedRAMP requirements. 

Other duties as required and assigned in line with IT Security Compliance 

Requirements

 Required Skills/Experience: 

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or equivalent experience. 
  • 3–5+ years of IT security/compliance experience, including direct experience with NIST SP 800-171, NIST SP 800-53, or CMMC frameworks. 
  • Working knowledge of DFARS 252.204-7012, FAR 52.204-21, and CUI handling requirements. 
  • Experience with Microsoft 365 GCC High, Azure Government, AWS GovCloud, or similar CUI-capable environments strongly preferred. 
  • Hands-on proficiency with core security tooling: MFA, EDR/antivirus, SIEM, vulnerability scanning, and patch management. 
  • Strong documentation and technical writing skills with high attention to detail; comfortable sustaining long-term, documentation-intensive compliance work. 
  • Analytical and solution-oriented; able to translate complex compliance requirements into actionable technical controls. 
  • Clear communicator capable of presenting technical and compliance concepts to non-technical stakeholders and senior leadership. 
  • Self-directed and organized; able to independently manage a long-term compliance program while balancing competing contract-driven deadlines. 

Preferred Experience 

  • Prior role supporting a Defense Industrial Base (DIB) contractor through a CMMC Level 2 certification. 
  • Experience working with a C3PAO or RPO during a formal assessment. 
  • Familiarity with NIST SP 800-171A assessment procedures.