Security Compliance Industry Specialist
SuperMicroComputer · San Jose, California, United States · On-site
Pay: USD 133,000 – 165,000 a year
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Job Req ID: 30369
About Supermicro:
Supermicro® is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop/ Big Data, Hyperscale, HPC and IoT/Embedded customers worldwide. We are the #5 fastest growing company among the Silicon Valley Top 50 technology firms. Our unprecedented global expansion has provided us with the opportunity to offer a large number of new positions to the technology community. We seek talented, passionate, and committed engineers, technologists, and business leaders to join us.
Job Summary:
Supermicro is seeking a Security Compliance Industry Specialist to drive day-to-day federal compliance execution, security assurance, and audit readiness for SMCI Federal. Reporting to the Director of Federal Compliance, this high-impact, hands-on role ensures our advanced hardware platforms, manufacturing environments, and technical data adhere strictly to CMMC Level 2, NIST SP 800-171, DFARS cybersecurity reporting obligations, and ITAR compliance standards. This role acts as an independent compliance validator separate from technical implementation teams, providing critical execution capacity to safeguard and grow federal revenue across public sector, prime contractor, and government accounts.
Essential Duties and Responsibilities:
CMMC & NIST SP 800-171 Program Execution
Self-Assessment & Scoring: Complete and maintain NIST SP 800-171 self-assessment scoring and Supplier Performance Risk System (SPRS) submissions.
SSP & POA&M Ownership: Own, manage, and update the System Security Plan (SSP) and Plan of Action & Milestones (POA&M), ensuring 100% of control gaps are tracked and closed against defined SLAs.
DFARS Safeguarding, Incident Response & Cloud Control Validation
Incident Response: Maintain operational incident response readiness in compliance with DFARS 72-hour reporting requirements; lead annual incident response tabletop exercises and ensure rapid, accurate reporting of security events.
Shared-Responsibility Validation: Validate that technical safeguarding controls delivered through GCC High and any SMCI-operated systems are correctly configured against NIST SP 800-171 requirements, confirming the platform's shared-responsibility boundary is properly understood and implemented rather than assumed.
ITAR & Controlled Technical Data Administration
Technology Control Plan: Establish and administer Technology Control Plans (TCP) and technical access controls for controlled technical data.
Deemed-Export Prevention: Operate deemed-export prevention processes to restrict unauthorized access to controlled technical data across engineering, sales, and manufacturing operations.
Physical Security & Facility Controls
Physical Protection Controls: Support the implementation and validation of physical protection controls (NIST SP 800-171 Physical Protection family) at the dedicated federal facility, including badge…