Associate Cybersecurity Specialist
Vulcan Elements · Benson, NC · 4 wk ago
On-siteEngineeringFull-time
Responsibilities
- Support the maintenance and continuous improvement of NIST 800-171 controls across IT and OT environments working alongside our external CMMC compliance partner.
- Aid in tracking the Plan of Action and Milestones (POA&M) and help drive closure of open items.
- Keep the System Security Plan (SSP) current and accurate.
- Learn to map controls to actual systems, configurations, and personnel as you develop familiarity with the environment.
- Identify and document security risks across IT and OT systems.
- Apply risk-based prioritization that accounts for OT safety constraints and production impact.
- Support implementation and monitoring of security controls across IT infrastructure and OT environments including MES, historians, and network boundary devices.
- Monitor security events across IT and OT environments.
- Investigate alerts under guidance, assist in incident response efforts, and document findings.
- Assist with vulnerability scanning across IT systems and help coordinate safe assessment approaches for OT assets.
- Track remediation items with system owners.
- Support delivery of security awareness training.
- Ensure personnel with Controlled Unclassified Information (CUI) access understand their responsibilities under CMMC policy.
- Support third-party CMMC assessments and internal audits.
- Assist in gathering and organizing evidence of control implementation.
Qualifications
- 2+ years in an IT, cybersecurity, or related technical role. Internship or lab experience considered.
- Mechanical or manufacturing exposure is a plus but not required.
- Foundational understanding of cybersecurity concepts including access control, network security, logging, and incident response. Formal coursework, self-study, or hands-on lab experience accepted.
- Basic awareness of NIST 800-171 or CMMC framework. You do not need to have implemented controls, but you should know what they are and why they matter.
- Curiosity about how OT and IT systems work together.
- Willingness to learn Industrial Control Systems (ICS)/Supervisory Control and Data Acquisition (SCADA) concepts, industrial protocols, and the safety-first mindset required in a manufacturing environment.
- Comfortable working in Windows environments. Familiarity with Active Directory, networking basics, and security tooling (SIEM, endpoint protection, vulnerability scanners) a plus.
- Strong attention to detail and ability to maintain accurate documentation. Security compliance lives and dies on good records.
- Ability to work in a manufacturing environment. Occasional physical work in production or server areas may be required.
- CompTIA Security+ required within 6 months of hire if not already held.
- CCP (Certified CMMC Professional) supported and expected within 12-18 months.
- Must be a U.S. Person due to required access to U.S. export-controlled information or facilities.