Supermicro
Supermicro
5,001 – 10,000 Employees
ConsultingLogisticsManufacturing
Supermicro develops high-performance computing solutions centered on server technology and advanced infrastructure for enterprise applications. Its work spans the computing sector, combining hardware innovation with the operational expertise needed to support demanding technology environments. For professionals exploring roles in server engineering, enterprise computing, manufacturing, logistics, consulting, and related functions, Supermicro offers opportunities to contribute to products and systems used in modern data infrastructure.

Security Compliance Specialist – Supermicro, San Jose, CA (Onsite)

Lead security compliance for Supermicro’s federal hardware and manufacturing operations, with responsibility for CMMC, NIST SP 800-171, DFARS, and ITAR readiness. The role covers audit preparation, control validation, incident response, controlled-data protection, and compliance evidence management.

Description

  • Manage daily federal compliance operations, security assurance, and audit readiness for SMCI Federal
  • Maintain NIST SP 800-171 assessments, scoring, and SPRS submissions
  • Own and update the System Security Plan and Plan of Action & Milestones
  • Monitor control deficiencies and drive remediation within agreed SLAs
  • Keep incident-response processes ready for DFARS 72-hour reporting obligations
  • Lead annual incident-response tabletop exercises and coordinate accurate security-event reporting
  • Assess GCC High and SMCI-operated systems against NIST SP 800-171 safeguarding requirements
  • Administer Technology Control Plans and access restrictions for controlled technical data
  • Run deemed-export prevention processes across engineering, sales, and manufacturing
  • Verify physical safeguards at the dedicated federal facility, including badges, visitors, and CUI protection
  • Collaborate with Facilities and Security on controls for CUI- and ITAR-controlled workspaces
  • Prepare the program for independent CMMC Level 2 certification assessments
  • Independently test technical controls while preserving separation of duties
  • Coordinate required CUI, ITAR, and insider-threat training completion
  • Support insider-threat access lifecycle controls and reporting with HR and Security
  • Manage the compliance evidence repository and CUI-environment asset inventory
  • Help assess GRC platforms as the compliance program develops

Requirements

  • Bachelor’s degree in computer science, information technology, cybersecurity, or a related technical discipline
  • At least five years of practical experience in security risk management, compliance auditing, or technical GRC within a highly regulated setting
  • Hands-on experience with NIST SP 800-171, CMMC Level 2, DFARS 252.204-7012/7019/7020, and ITAR compliance
  • Strong knowledge of IAM, access control matrices, audit logging, encryption, and other technical safeguards
  • Working knowledge of NIST SP 800-171 physical protection requirements in controlled facilities
  • Excellent technical writing ability for SSPs, POA&Ms, control documentation, and audit evidence
  • Preferred certifications include CISSP, CISA, CISM, CRISC, or CMMC Registered Practitioner
  • Preferred experience with hardware manufacturers, server or data-center infrastructure, or DIB suppliers
  • Preferred experience automating evidence collection and using ServiceNow, Jira, or cloud-based GRC platforms

Benefits

  • Comprehensive benefits package
  • Possible eligibility for bonus programs
  • Possible eligibility for equity awards

Related Jobs

FHI 360

Associate Director of Procurement, Administration and Logistics

FHI 360

Leads procurement, administration, logistics, and operations for FHI 360’s country office in the Democratic Republic of the Congo. Supervises functional leads and maintains compliance with donor, government, and supply chain requirements.

Open