Security Compliance Industry Specialist

Super Micro Computer, Inc.San Jose, CaliforniaOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

Job Req ID: 30369

About Supermicro:

Supermicro® is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop/ Big Data, Hyperscale, HPC and IoT/Embedded customers worldwide. We are the #5 fastest growing company among the Silicon Valley Top 50 technology firms. Our unprecedented global expansion has provided us with the opportunity to offer a large number of new positions to the technology community. We seek talented, passionate, and committed engineers, technologists, and business leaders to join us.

Job Summary:

Supermicro is seeking a Security Compliance Industry Specialist to drive day-to-day federal compliance execution, security assurance, and audit readiness for SMCI Federal. Reporting to the Director of Federal Compliance, this high-impact, hands-on role ensures our advanced hardware platforms, manufacturing environments, and technical data adhere strictly to CMMC Level 2, NIST SP 800-171, DFARS cybersecurity reporting obligations, and ITAR compliance standards. This role acts as an independent compliance validator separate from technical implementation teams, providing critical execution capacity to safeguard and grow federal revenue across public sector, prime contractor, and government accounts.

Essential Duties and Responsibilities:

CMMC & NIST SP 800-171 Program Execution

- Self-Assessment & Scoring: Complete and maintain NIST SP 800-171 self-assessment scoring and Supplier Performance Risk System (SPRS) submissions.

- SSP & POA&M Ownership: Own, manage, and update the System Security Plan (SSP) and Plan of Action & Milestones (POA&M), ensuring 100% of control gaps are tracked and closed against defined SLAs.

DFARS Safeguarding, Incident Response & Cloud Control Validation

- Incident Response: Maintain operational incident response readiness in compliance with DFARS 72-hour reporting requirements; lead annual incident response tabletop exercises and ensure rapid, accurate reporting of security events.

- Shared-Responsibility Validation: Validate that technical safeguarding controls delivered through GCC High and any SMCI-operated systems are correctly configured against NIST SP 800-171 requirements, confirming the platform's shared-responsibility boundary is properly understood and implemented rather than assumed.

ITAR & Controlled Technical Data Administration

- Technology Control Plan: Establish and administer Technology Control Plans (TCP) and technical access controls for controlled technical data.

- Deemed-Export Prevention: Operate deemed-export prevention processes to restrict unauthorized access to controlled technical data across engineering, sales, and manufacturing operations.

Physical Security & Facility Controls

- Physical Protection Controls: Support the implementation and validation of physical protection controls (NIST SP 800-171 Physical Protection family) at the dedicated federal facility, including badge access, visitor management, and physical safeguarding of CUI.

- Facility Partnership: Partner with Facilities and Security functions on control design for any space where CUI or ITAR-controlled technical data is discussed, stored, or processed.

Audit Readiness & Independent Validation

- Assessment Readiness: Deliver a fully documented, “assessment-ready” posture ahead of third-party CMMC Level 2 certification audits.

- Separation of Duties: Serve as an independent validator of technical security controls, ensuring separation of duties between the teams implementing controls and the function validating them.

Training, Insider Threat & Compliance Operations

- Training Program: Partner with cross-functional teams to drive and track 100% completion of mandatory CUI, ITAR, and insider-threat training programs across all in-scope personnel.

- Insider Threat Program: Support the broader insider threat program beyond training alone — including personnel access-lifecycle controls and a defined reporting channel — in partnership with HR and Security.

- Evidence & Tooling: Maintain the compliance evidence repository and supporting asset inventory for the CUI environment, and support evaluation of GRC tooling to manage this at scale as the program matures.

Qualifications:

- Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related technical field.

- Experience: 5+ years of hands-on experience in security risk management, compliance auditing, or technical GRC execution within a highly regulated environment.

- Regulatory & Technical Expertise: Direct experience managing NIST SP 800-171, CMMC Level 2, DFARS (252.204-7012/7019/7020), and ITAR compliance frameworks. Proven understanding of technical security controls including Identity and Access Management (IAM), access control matrices, audit logging, and data encryption.

- Working familiarity with physical security control requirements (NIST SP 800-171 Physical Protection family) as they apply to a controlled facility.

- Communication: Exceptional written skills for drafting SSPs, POA&Ms, technical control documents, and audit artifacts.

Preferred Qualifications

- Credentials: CISSP, CISA, CISM, CRISC, or CMMC Registered Practitioner (RP).

- Environment: Experience supporting hardware manufacturers, server/data center infrastructure, or defense industrial base (DIB) suppliers.

- Tooling: Experience automating compliance evidence collection and utilizing ticketing/GRC tools (e.g., ServiceNow, Jira, or cloud-based GRC platforms).

Salary Range

​$133,000 - $165,000

The salary offered will depend on several factors, including your location, level, education, training, specific skills, years of experience, and comparison to other employees already in this role. In addition to a comprehensive benefits package, candidates may be eligible for other forms of compensation, such as participation in bonus and equity award programs.
​

EEO Statement

Supermicro is an Equal Opportunity Employer and embraces diversity in our employee population. It is the policy of Supermicro to provide equal opportunity to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or special disabled veteran, marital status, pregnancy, genetic information, or any other legally protected status.