Back to jobs

Security Compliance and Oversight Subject Matter Expert (SME)

Colorado Springs, CO

ABOUT NOOKS

Are you seeking an exciting and unique opportunity to grow and support our national security? As a startup, we are offering a limited-time opportunity to be an equity owner in a pioneering new industry. Nooks is pioneering Classified Infrastructure-as-a-Service (CIaaS) to provide government and industry partners with the fastest, most efficient access to classified infrastructure. We are building a nationwide network of accredited classified spaces and systems, ensuring that the best technologies equip our nation’s warfighters. At Nooks, we value innovation, collaboration, and a service-first mindset.

ABOUT THE ROLE

We are seeking a highly experienced and strategic Security Compliance and Oversight Subject Matter Expert (SME) to drive the integrity and continuous improvement of the US Space Force classified security posture. This enterprise-level role focuses on auditing, continuous monitoring, and regulatory reporting for all security disciplines: Personnel Security (PERSEC), Physical Security (PHYSEC), Information Security (INFOSEC), and Industrial Security (INDUSEC).

The SME will serve as the authoritative compliance resource for the HQ Special Security Officer (SSO) and Command leadership, responsible for developing and running a standardized internal inspection program and ensuring rigorous adherence to all Intelligence Community Directives (ICDs), Security Executive Agent Directives (SEADs), and DoD security regulations across the USSF enterprise.

KEY RESPONSIBILITIES:

1. Enterprise Auditing and Inspection Program Management

  • Program Design & Implementation: Design, implement, and manage a robust security self-inspection and internal auditing program that covers all security domains (PHYSEC, PERSEC, INFOSEC, INDUSEC) across all USSF facilities.
  • Compliance Assessments: Conduct recurring and unscheduled compliance vulnerability assessments and deep-dive gap analyses to identify systemic risks and ensure the USSF Enterprise meets all mandated security standards.
  • Documentation Control: Serve as the final oversight authority for all security documentation, ensuring Standard Operating Procedures (SOPs), DD-254s, Facility Clearance Certificates (FFCs), and System Security Plans (SSPs) are current, accurate, and standardized across the entire enterprise.
  • Remediation Management: Develop, manage, and track the remediation of all identified security weaknesses using a formal Plan of Action and Milestones (POA&M) approach, driving accountability across functional security leads.

2. Government Audit Readiness and Liaison

  • Lead Coordinator: Serve as the lead coordinator and preparer for all external government security inspections, audits, and assessments (e.g., DCSA Security Assessments, IC Inspector General audits, Customer Audits).
  • Reporting and Metrics: Synthesize complex security data and metrics from all domains to prepare comprehensive, auditable security records and reports for senior leadership and external government agencies.
  • Audit Management: Act as the primary security liaison during external reviews, managing the flow of information, coordinating facility access, and ensuring timely responses to all findings.

3. Continuous Monitoring and Regulatory Reporting

  • Continuous Monitoring (CM) Strategy: Develop and oversee the Continuous Monitoring strategy for all administrative, physical, and technical security controls across the enterprise, ensuring effective detection of security risks.
  • Trend Analysis and Risk Identification: Analyze security data trends harvested from PERSEC (CE Alerts), INFOSEC (incident reports), and PHYSEC (IDS/ACS logs) to identify systemic, cross-domain risks and inform high-level risk mitigation strategies.
  • Mandatory Reporting: Ensure all mandatory security reporting (e.g., adverse information, security violations, changes in status) to the Cognizant Security Authority (CSA) and other government security organizations is complete, accurate, and submitted within required regulatory timelines.

4. Policy, Standardization, and Training Oversight

  • Policy Standardization: Serve as the expert on regulatory interpretation, reviewing, vetting, and standardizing all site-specific security SOPs to ensure uniformity and consistent compliance across the multi-site enterprise.
  • Training Integrity: Collaborate with the functional security SMEs (Personnel, Physical, Information) to ensure all security training and awareness materials accurately reflect current enterprise policies and regulatory compliance requirements.
  • Change Management: Participate in the change management process to proactively assess the security impact of new business initiatives, facility construction/modifications, and major IT system deployments.

THE SKILLSET:

  • Experience: Minimum 10 years of dedicated professional experience in a security compliance, audit, or oversight role within the U.S. Defense or Intelligence Community.
  • Clearance: Must possess and maintain an Active Top Secret (TS) / Sensitive Compartmented Information (SCI) eligibility security clearance. U.S. Citizenship is required.
  • Regulatory Expertise: Expert-level knowledge of the entire security landscape, including NISPOM (32 CFR Part 117), ICD 705 (Physical), ICD 503 (Information), SEAD 4 (Foreign Contact), and the Risk Management Framework (RMF) for classified systems.
  • Auditing & Systems: Proven track record of leading and successfully preparing for DCSA and/or IC Security Assessments. Proficiency with government security databases (DISS/NBIS, NISS, Scattered Castles) sufficient to verify and audit data integrity.
  • Skills: Exceptional organizational, analytical, and written/verbal communication skills, with a proven ability to manage complex compliance projects and brief senior command leadership.

PREFERRED QUALIFICATIONS:

  • Certification: Current security certification such as SPeD, Industrial Security Professional (ISP®) or Security Fundamentals Professional Certification (SFPC).
  • Experience: Direct, embedded experience supporting the US Space Force or a similar Combatant Command SSO in an oversight or compliance role.
  • Education: Bachelor’s degree in a relevant field (e.g., Security Management, Information Systems).

This position requires the ability to travel to USSF and partner facilities, work in Sensitive Compartmented Information Facilities (SCIFs), and involves physical requirements such as climbing stairs/ladders or working in confined spaces to complete facility inspections and assessments.

This employment offer is contingent upon continued funding of the underlying government contract. Should the contract be modified, or terminated, or if funding is reduced or eliminated, the employer reserves the right to adjust or rescind the offer accordingly. 

Salary Range for all departments

Salary Range

$140,000 - $170,000 USD

Create a Job Alert

Interested in building your career at Nooks? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Nooks’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.