Security & Compliance SpecialistThe Security & Compliance Specialist is responsible for reducing security risk and incidents across Spinen and all client environments by defining, enforcing, and sustaining strong baseline security standards.This role focuses on closing remaining gaps in Spinen’s security posture (with CIS IG1 as the baseline standard), preventing drift over time, and driving real remediation in client environments. The Specialist operates as an opinionated senior individual contributor who works closely with Pods, clients, vendors, and internal teams to ensure security controls are implemented, automated where possible, and measurable.This is a hands-on, client facing role with authority to lead incident response, define standards, and drive remediation — without management responsibilities.Core ResponsibilitiesSecurity Standards & Baseline EnforcementDefine, document, and evolve Spinen’s baseline security standards (CIS IG1 as the minimum for all clients)Ensure CIS IG1 is implemented and sustained across 100% of client environments, with no permanent exceptionsDesign and maintain layered security and compliance standards (e.g., SOC 2, CMMC) for Compliance and Service clientsConduct research and evaluation of security tools and approaches, selecting and standardizing solutions in close collaboration with Pod leadershipWork with Pods to ensure standards are implemented consistently and efficiently across environmentsClient Environment Oversight & RemediationProactively assess client environments to identify security gaps, risks, and drift from established standardsActively drive remediation plans with Pods and clients to close identified gapsEngage directly with clients as a peer advisor to explain security risks, required controls, and necessary changesSupport Pods during client pushback by clearly articulating risk, necessity, and tradeoffsIncident Response LeadershipLead security incident response efforts during active compromises or material security eventsCoordinate Pods and internal teams during investigation, containment, and recoveryEnsure incidents result in meaningful improvements to standards, controls, and processesMaintain accurate incident documentation and reporting for internal leadership and clientsMeasurement, Evidence & ReportingDefine what “done” means for security controls: implemented, automated where possible, and measurableShare responsibility with Pods for evidence and measurement, while remaining accountable for unresolved gapsContinuously assess security posture and control effectivenessProvide formal quarterly reporting to leadership focused on:Risk reductionGap closureDrift preventionPrioritization of security workAutomation PartnershipAct as the product owner and internal client for security and compliance automationDefine automation requirements and success criteriaPartner with Spinen’s automation team to ensure automation meaningfully reduces risk and operational effortCollaboration & AdvisoryWork closely with Pods, vendors, and internal teams to ensure secure and compliant solutionsCommunicate Spinen’s security standards, expectations, and best practices clearly and consistentlySupport Tier 2/3 escalations related to security specific issuesRequired Skills & AbilitiesProven experience in IT security operations, incident response, or security program managementStrong understanding of security frameworks and controls (CIS, SOC, CMMC, etc.)Experience working across multiple client environments (MSP or similar)Ability to translate technical risk into clear, practical guidance for clients and internal teamsComfortable delivering informed opinions, leading discussions, and driving decisions without direct authorityStrong analytical, organizational, and communication skillsProficient in Microsoft OfficeEducation & ExperienceBachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience3+ years of experience in IT security or compliance within an MSP or multiclient environment (preferred)Industry certifications (CISSP, CISM, CEH, CompTIA Security+) are a plusPhysical RequirementsProlonged periods of sitting and working on a computerAbility to lift up to 50 lbs as neededMay be required to work outside normal business hours during security incidents
Security & Compliance Specialist in macon at Unknown Company
This position is listed as full time and onsite.