This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Regulatory & Compliance Manager (Defense Programs) is responsible for interpreting and operationalizing U.S. defense-related regulatory requirements including, but not limited to ITAR, EAR, CMMC, DFARS cybersecurity clauses, and related DoD information-protection requirements. This role leads the development implementation, and ongoing governance of company-wide policies, procedures, training programs, and assessment activities to ensure proper governance, classification, protection, and exportability determinations for Controlled Unclassified Information (CUI), Controlled Technical Information (CTI), and ITAR/EAR-controlled data. This position serves as the primary compliance authority supporting program execution, audits, pre-contract reviews, and routine departmental operations to mitigate regulatory, contractual and security risk.
Job Responsibility:
Serve as the company’s subject matter expert on ITAR, EAR, CMMC, DFARS cybersecurity clauses, and DoD-specific controlled information categories
Develop and maintain corporate policies, operating procedures, standards, and guidance related to data protection, export controls, and information governance
Maintain a regulatory intelligence function tracking changes to relevant U.S. government requirements
Lead classification and marking reviews for CUI, CTI, ITAR/EAR technical data, and company proprietary information
Establish and administer processes for data handling, storage, transmission, and access authorization
Develop annual and role-based training programs for CUI, export controls, cybersecurity compliance, and sensitive data handling
Support internal readiness assessments for CMMC and NIST 800-171
Participate in program reviews, contract kickoff meetings, and export-related technical reviews
Conduct periodic audits of data storage locations, document repositories, and file-sharing platforms
Provide guidance on jurisdiction and classification (USML/ECCN) for technical data and defense articles
Coordinate with legal counsel on export license requirements and technology control plans (TCPs)
Enforce access restrictions and ensure adequate technical safeguards for export-controlled information
Partner with HR, IT, Security, Engineering, Operations, and Program Management to integrate compliance requirements
Serve as point of contact during audits, inspections, and external assessments
Support incident response involving potential mishandling of controlled information
Requirements:
5-10+ years of experience in defense-sector compliance, cybersecurity, export controls, or related governance roles
Strong understanding of ITAR, EAR, CMMC 2.0, NIST 800-171, and DFARS 7012/7019/7020/7021
Experience creating policies, procedures, and training content
Demonstrated ability to perform controlled-information classification and export-control evaluations
Bachelor’s degree in business, cybersecurity, information systems, or related field
U.S. Citizenship Required
Must be able to successfully pass an initial background screening
Must be able to obtain and maintain an active Department of Defense (DoD) security clearance
Must be able and willing to travel domestically and, on occasion, internationally
Applicants and employees are subject to pre-employment and random drug testing
Nice to have:
Experience supporting DoD contracts as part of a DIB contractor
Familiarity with ISO 9001/AS9100, quality systems, and configuration management
Compliance-centric certifications such as CMMC Certified Professional (CCP), Certified Compliance & Ethics Professional (CCEP), Certified Information Privacy Professional (CIPP/US), or similar
Existing security clearance or clearance eligibility