Cyber Security Risk & Compliance Specialist
About Us
EF Johnson Technologies, Inc. is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands.
EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products.
______________________________________________________________________________
As a Cyber Security Risk & Compliance Specialist, you’ll focus on maintaining the appropriate operational security posture for our organization. This is an Information Security Systems Officer (ISSO) role, responsible for developing and maintaining the Assessment and Authorization (A&A) documentation, which adheres to NIST 800-37 standards throughout the system life cycle, to assess risk and achieve Authority to Operate for our Mission Critical Radio and Infrastructure Systems.
Key Responsibilities
-
Create and Maintain A&A documentation needed for Certification and Accreditation, including SSP, SAR, and RAR documents.
-
Create, track and manage the Plan of Action & Milestones (POA&Ms) for identified security vulnerabilities and deficiencies.
-
Ensure compliance with organizational security policies
-
Support system owners in completing security-related responsibilities
-
Implement and enforce security controls as documented in the SSP
-
Conduct regular assessments to verify proper operation
-
Identify security controls tailored to security objectives
-
Continuous monitoring responsibilities, including reviewing security logs, analyzing vulnerabilities, and tracking remediation efforts.
-
Partner with infrastructure, radio, network, and software teams to embed security and compliance into system design.
-
Additional duties as required.
-
Agrees to abide by the established Approval Matrix.
Qualifications
-
Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or a related field (master’s preferred).
-
CompTIA Security+ required.
-
CISSP or equivalent certification preferred.
-
Experience conducting Nessus Security scans
-
Demonstrated experience authoring SSPs, policies, procedures, and audit evidence.
-
Familiarity with log collection, analysis, and security monitoring.
-
Experience working through the NIST SP 800-37 Risk Management Framework Accreditation Process
-
Knowledge of public-safety radio systems, LMR, or P25 infrastructure
-
Federal Experience bringing suppliers through Authorization to Operate (ATO)
-
Linux and Windows administration
-
Configuration management
-
Documentation tooling (version control, document management systems)
What We’re Looking For
-
Strong technical security acumen
-
Exceptional written documentation skills
-
Ability to translate technical systems into audit-ready narratives
-
Analytical mindset with strong attention to detail
-
Collaborative and communicative across engineering teams
-
Ability to prioritize compliance fundamentals under right timelines
Travel Requirements
What We Offer
-
Competitive salary
-
Health, dental, and vision benefits
-
Additional supplemental benefits
-
401K + employer match
-
Tuition reimbursement
-
12 paid holidays + additional PTO
-
Supportive- team-driven environment
-
Opportunities to work on mission-critical projects that make a real impact
Equal Opportunity Statement
EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.