Facility Security Officer (FSO) & Government Contract Compliance Administrator – (Top Secret)
Your Team
This individual contributor role sits within CohnReznick’s Government and Public Sector Advisory (GPSA) practice and combines two functions: (1) the role is responsible for managing and enforcing the Firm’s industrial security program under the National Industrial Security Program (NISP), and (2) administration of government contract compliance for GPSA’s federal contract portfolio. The role reports to GPSA leadership, with dotted-line coordination to Legal & Risk, and retains direct access to senior management on any matter affecting the facility clearance, classified information, reportable security events or the Firm’s standing under the NISP.
At onboarding, the two functions are expected to be evenly split. As the security program stabilizes, the balance is expected to shift toward compliance administration, which is anticipated to represent the substantial majority of the role at steady state. This allocation is directional and may vary based on business and regulatory needs. Regardless of the operational split at any given time, the FSO’s statutory responsibilities under 32 CFR Part 117 (NISPOM) regulations and Defense Counterintelligence and Security Agency (DCSA) requirements take priority whenever necessary to protect classified information and maintain the Firm’s facility security clearance (FCL).
The compliance administration component will initially support GPSA’s federal portfolio, including relevant proposals, prime contracts, task orders and subcontracts, with potential expansion to other Firm practices as supporting systems and governance mature.
Responsibilities
- NISP Compliance & Program Management: Supervise and direct security measures needed to protect classified information at the facility, ensuring compliance with the NISPOM and all DCSA directives. Maintain the facility clearance status, manage security documentation (e.g. Standard Practice Procedures), and implement policies and procedures for classified work. Act as the primary DCSA liaison for security audits, actions, and guidance.
- Personnel Security Clearances: Manage all personnel security clearance (PCL) processes, including initiating and maintaining employee clearances up to Top Secret. Use government systems such as DISS, NISS, and e-QIP to submit investigations, monitor clearance status, and ensure timely reinvestigations. Oversee onboarding and termination clearance procedures, including submitting Key Management Personnel (KMP) changes, handling SF-312 NDA execution and debriefs.
- Facility & Physical Security: Where the Firm holds classified material on-site, oversee physical security and safeguarding of classified materials and areas. Maintain controlled access to secure facilities, manage alarm systems and GSA-approved security containers, perform end-of-day checks, and enforce proper marking, storage, transmission, and destruction of classified documents. For non-possessing operations, administer safeguarding of government-furnished equipment and controlled access consistent with applicable contract security requirements. Implement visitor control procedures for classified visits and meetings, verifying clearances and need-to-know.
- Information Systems Security Coordination: Coordinate with the Information System Security Manager (ISSM)/ISSO and IT department to ensure classified information systems (if any) meet government cybersecurity requirements. Support accreditation processes (e.g., by DCSA or NIST RMF standards) for classified networks and verify that system users uphold all security policies for handling classified data.
- Security Training & Briefings: Conduct and document required security briefings and training for cleared personnel. Oversee initial security briefings for new cleared employees, annual refresher training (including insider threat, counterintelligence, and security best practices), foreign travel briefings, and exit debriefings upon termination. Foster a strong security awareness culture through ongoing education and compliance reminders.
- Audits, Self-Inspections & Assessments: Proactively manage readiness for DCSA security vulnerability assessments. Perform internal self-inspections at least annually to identify and correct any security deficiencies, prepare required reports and documentation for DCSA reviews, and lead the facility through formal security audits/inspections, ensuring any findings are promptly mitigated.
- Incident Reporting & Investigations: Monitor for and investigate security incidents or violations (e.g., loss/compromise of classified information, suspicious contacts) and report to DCSA and other authorities as required by NISPOM, ensuring proper documentation and corrective actions. Support insider threat program activities by reporting relevant information to the Insider Threat Program Senior Official (ITPSO) and assisting with insider threat inquiries, as needed.
- Continuous Security Program Improvement: Stay current with DCSA guidance and emerging security best practices. Recommend and implement enhancements to security procedures, and maintain meticulous records and audit trails for all security activities.
- Government Contracts Security & Compliance Administration: Administer recurring government contract compliance activities for GPSA’s federal contracts as a distinct course-of-business responsibility that complements, but does not replace, the regulated FSO function. Coordinate with Legal & Risk, Finance, Contracts, IT, HR, and engagement leadership, as needed.
- Compliance Calendar & Deliverable Tracking: Maintain a centralized calendar and obligation matrix covering contract-specific filings, certifications, training, reporting, renewals, flow-down requirements arising from solicitations, awards, task orders, and modifications, and other compliance deadlines; monitor status and escalate potential delays to the responsible owner.
- Certifications, Registrations & Representations Support: Coordinate and validate information supporting federal representations, certifications, responsibility determinations, entity registrations (e.g., SAM.gov), and related submissions, with formal ownership, submission, and approval remaining with the designated corporate function.
- Training & Onboarding Administration: Develop and administer contract-specific onboarding checklists, briefings, and points of contact for GPSA federal engagement teams, and track completion of required security, ethics, privacy, procurement-integrity, records-management, and contract-specific training for covered personnel.
- Audit Readiness & Issue Tracking: Maintain organized compliance files and evidence repositories; coordinate documentation for government inquiries and audits, and log identified compliance matters through to closure, promptly escalating significant or overdue items through established channels.
- Program Administration & Process Improvement: Operate as a self-directed program administrator within the current organizational structure. Use established systems and processes where available, identify gaps, develop practical checklists, responsibility matrices, and dashboards, and implement improvements following approval by the appropriate operational owner.
- Authority & Governance Boundaries: This component of the role coordinates, administers, documents, monitors, and escalates compliance activities. It does not independently provide legal interpretations, establish corporate policy, accept compliance risk, bind the Firm through representations or certifications, or override the authority of Legal & Risk, Finance, Contracts, IT, HR, engagement leadership, or other designated corporate owners.
Your Experience
- Security Clearance: U.S. citizenship required. Active Top Secret security clearance (or Top Secret eligibility with willingness to undergo investigation) required, with commitment to maintain clearance.
- Experience: 5+ years of experience in industrial security, government contract compliance administration, or a combination of both, within a cleared DoD contractor or federal contracting environment, including hands-on FSO or security management duties.
- Expertise: Demonstrated knowledge of 32 CFR Part 117 (NISPOM) and practical application of NISP security requirements, together with familiarity administering compliance calendars, contract obligation tracking, and audit-readiness documentation for U.S. federal contracts. In-depth understanding of personnel security clearance processing and facility clearance. Proficiency with U.S. government security systems and databases (DISS, NISS, e-QIP, etc.) to manage clearances and facility records. Strong grasp of classified document control, handling and marking procedures, and physical security standards for classified material.
- Training: Completion of (or ability to complete promptly upon hire) DCSA/CDSE FSO training appropriate to the facility type, such as “FSO Program Management for Possessing Facilities” (if the Firm holds classified information on-site) or “FSO Orientation for Non-Possessing Facilities.”
- Education: Bachelor’s degree in Security Management, Criminal Justice, or related field – or equivalent professional experience in industrial security or government contract compliance.
- Skills: Exceptional organizational and record-keeping skills, with attention to detail and accuracy in compliance documentation. Excellent communication and interpersonal skills – able to effectively interface with employees, executives, and government security officials. Proven ability to work independently as a self-starter, managing a comprehensive security program and compliance program without direct supervision. Uncompromising integrity, ethics, and discretion in handling sensitive information.
Preferred Qualifications
- Advanced Certifications