Kryptek LLC

Compliance and Assurance Lead (Contract, 1099, Remote, US)

Herndon, VA • Posted 5 days ago • $70 - $83 per hour
Remote Contract General

Remote, United States Contract, full time

Reports to: Program Executive
Engagement type: Independent contractor, 1099
Term: Twelve months, with extension potential
Location: Fully remote within the United States. No travel required
Status: United States citizenship required. Engagement contingent on program start

ABOUT KRYPTEK

Kryptek LLC builds governed AI systems for clients operating under regulatory obligation. The work this role supports is agentic compliance monitoring at scale: pipelines that ingest public and client-furnished data, validate it against regulatory requirements using deterministic rules, detect drift over time, and assemble evidence packages a reviewer can defend months after the fact. The agentic layer drafts narratives, clusters findings to root cause, and reconciles conflicting sources. It never renders a determination. Every finding passes a recorded human review gate before it can leave the system. The platform runs on Amazon Bedrock inside AWS GovCloud (US) and is engineered to carry a federal Authority to Operate.

Kryptek also delivers managed detection and response, cloud security, and Zero Trust engineering on Microsoft Sentinel and Palo Alto Cortex XSIAM. We are a small, senior team, and the people we hire own their scope end to end rather than executing someone else's ticket queue.

YOUR CAREER

You will be responsible to carry the Authority to Operate, and you carry the regulatory spine of the platform. Those are two different jobs that this role holds together, and the reason they belong in one seat is that both come down to the same skill: turning a regulatory citation or a NIST control into something testable, evidenced, and defensible to someone who was not in the room. You will author the System Security Plan, own FIPS 199 categorization, procure and manage the third-party assessor, and submit the authorization package to the Authorizing Official. You will also own the requirements traceability matrix that every validation rule and every control implementation statement traces back to.

YOUR IMPACT

- Hold accountability for the authorization boundary definition, including opening an informal boundary discussion with the agency security office early enough that the formal boundary deliverable documents a boundary rather than discovering one
- Own FIPS 199 categorization and system scoping against a boundary in which the platform consumes only public and client-furnished reference data and holds no PII, PHI, or CUI
- Author the System Security Plan and the narrative control descriptions
- Write every control implementation statement, each carrying a named evidence identifier traceable to an artifact the Security and ATO Engineer produced and attested to. No statement enters the SSP without one, and you do not describe a control the engineer has not attested is implemented as described
- Procure, schedule, and coordinate the third-party assessment, then assemble and submit the authorization package to the Authorizing Official
- Author, track, and close the Plan of Action and Milestones
- Own the requirements traceability matrix, mapping each regulatory obligation to authoritative data source, deterministic rule identifier, test cases including negative cases, required evidence artifacts, severity and issue class, and the human review requirement, generated from the rule registry rather than maintained by hand
- Set the evidence sufficiency standard and author the supplemental rules governing population completeness and record currency, including the deterministic versus advisory confidence characterization that keeps the platform from overclaiming non-compliance where observable evidence is inherently partial
- Draft corrective action materials framed as advisory support that does not displace the client's regulatory discretion

YOUR EXPERIENCE

- 8 or more years in federal information security compliance and authorization
- You have authored a System Security Plan that went through a third-party assessment and reached an authorization decision. Reviewing one, or supporting someone who wrote one, is not the same thing
- NIST SP 800-53 control mapping at the Moderate baseline, the Risk Management Framework, and FISMA
- Plan of Action and Milestones authorship, tracking, and closure evidence production
- You have procured and managed a third-party assessor engagement, including scoping and schedule
- Experience in leading the submission and packaging of an Authority to Operate (ATO), Continuous Authority to Operate (cATO), or FedRAMP ATO
- Ability to read a regulatory citation and turn it into a rule with test cases and required evidence. Regulated-industry or healthcare regulatory familiarity is a strong plus and is not a prerequisite
- Federal civilian agency authorization experience preferred
- Certifications a plus: CISSP, CGRC or CAP, CISA
- Relevant bachelor's degree, equivalent military experience, or equivalent professional experience
- United States citizenship is required. No security clearance is required for this role at present

COMPENSATION AND ENGAGEMENT TERMS

Rate. $70 to $83 per hour, paid as an independent contractor engagement. Placement within the range depends on the depth of RMF authorship and assessment experience.

This position is contingent on program start. Kryptek has committed to seating every open role within 30 days of go-ahead.

Your resume will be submitted to the client for approval before you begin work, so the client sees the individual performing rather than a labor category.

Fully remote within the United States. No travel is required for this role.

United States citizenship is required. No security clearance is required at present.

Kryptek delivers services and does not operate as a staffing agency. You will own a defined scope on our side of the work, not fill a seat on someone else's team.

TO APPLY

Send a resume to with "Compliance and Assurance Lead" in the subject line. Include a short note on the one item in Your Experience above that you consider your strongest claim, and how you would evidence it.

Compliance and Assurance Lead (Contract, 1099, Remote, US) in Herndon at Kryptek LLC

Other openings
5

Kryptek LLC currently has 5 other roles open on LocalWork in Herndon. If this particular role is not the right fit, their other openings may be.

This position is listed as contract and able to be worked remotely. It was posted 5 days ago.

See all Kryptek LLC jobs on LocalWork →

Back to Job Search