Full-Time

IT Auditor

FISMA, FedRAMP

Posted on 2/23/2026

A-LIGN

A-LIGN

501-1,000 employees

Automates cybersecurity compliance audits with software

No salary listed

Remote in USA

Remote

Category
Legal & Compliance (1)
Required Skills
FedRAMP

Get referred to A-LIGN

See people who can refer or advise you

Requirements
  • Bachelor’s or Master’s degree in management information systems, information security, computer science, or relevant discipline; or combination of relevant education and work experience
  • 1 - 2 years of experience performing information security reviews
  • Experience performing security audits against published standards
  • Ability to meet deadlines with a high degree of motivation
  • Excellent communication skills
  • Thrives in a fast-paced environment
  • Ability to work individually as well as collaboratively
Responsibilities
  • Assist client with evidence review
  • Clearly communicate with clients regarding evidence
  • Review SSPs for testing
  • Communicate to management any potential issues
  • Manage time and provide weekly detailed project status reports to management
  • Draft quality reports to be reviewed by senior members of the team

A-LIGN is a cybersecurity and compliance solutions provider that combines automated software with audit services. Its flagship platform, A-SCEND, automates the audit process by handling evidence collection, policy management, and real-time compliance assessments, helping clients become audit-ready in about half the time and saving hundreds of hours. The company earns revenue from software sales and audit services and uses a single-provider model to offer an end-to-end compliance solution that scales with a business. A-LIGN differentiates itself through its extensive audit experience and claims to have issued more SOC 2 reports than any other provider. Its goal is to simplify and accelerate the process of achieving and maintaining cybersecurity compliance for organizations of all sizes.

Company Size

501-1,000

Company Stage

Acquired

Total Funding

$54.5M

Headquarters

Tampa, Florida

Founded

2009

Get referred to A-LIGN

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • November 2026 CMMC deadlines should drive urgent defense-contractor demand.
  • EvidenceIQ and Cross-Service improve retention by reusing audit evidence across frameworks.
  • London expansion targets fast-growing EMEA compliance demand across AI, NIS2, and DORA.

What critics are saying

  • Optro and Crowe now funnel CMMC buyers into a rival ecosystem.
  • SOC 2 commoditization pressures pricing as automation-first vendors replicate A-SCEND workflows.
  • A single failed independence or quality review would damage trust across every framework.

What makes A-LIGN unique

  • A-LIGN pairs A-SCEND software with licensed audit and certification services.
  • It is the #1 issuer of SOC 2 reports globally.
  • The firm holds FedRAMP, CMMC, HITRUST, ISO, and PCI accreditations.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Wellness Program

Mental Health Support

Gym Membership

Phone/Internet Stipend

Conference Attendance Budget

Family Planning Benefits

Fertility Treatment Support

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

-2%
Kiteworks
Jul 22nd, 2026
Kiteworks and A-LIGN partner to strengthen cybersecurity across the Defense Industrial Base.

Kiteworks and A-LIGN partner to strengthen cybersecurity across the Defense Industrial Base. Partnership helps organizations protect sensitive data, strengthen cyber resilience, and prepare for evolving compliance requirements, including CMMC 2.0. San Mateo, California | July 22, 2026 Kiteworks, which empowers organizations to effectively manage risk in every send, share, receive, and use of private data, today announced a strategic partnership with A-LIGN, a leading CMMC Third Party Assessor Organization (C3PAO), to help Defense Industrial Base (DIB) organizations strengthen their cybersecurity posture and navigate the path to CMMC 2.0 Level 2 certification. The Department of War suspended CMMC Phase II on July 13, 2026, and launched a 60-day review of the program, but the underlying responsibility has not changed: Phase I self-assessment requirements and DFARS 252.204-7012 obligations remain fully in force. The DoW has been explicit that it is reducing red tape, not cybersecurity expectations. Protecting the Controlled Unclassified Information handled by tens of thousands of DIB organizations remains essential to defending the supply chain against increasingly sophisticated threats. The Kiteworks and A-LIGN partnership is built around a shared goal of helping DIB contractors protect that data, whether they are beginning to build out their data exchange controls or already in the assessment process and stalled on control gaps or evidence deficiencies. Organizations deploy the Kiteworks Control Plane to implement a substantial majority of CMMC Level 2 requirements out of the box, covering domains that commonly surface as evidence gaps in third-party assessments. Then, they can separately engage A-LIGN to independently assess that evidence through its rigorous assessment process. A-LIGN's role in this partnership is limited to independent assessment: A-LIGN does not consult, remediate, or advise on control implementation, and DIB organizations remain free to engage any authorized or accredited C3PAO. Kiteworks is FedRAMP High In Process and FedRAMP Moderate Authorized, with nine consecutive years of annual 3PAO audits validating 325 NIST 800-53 controls since 2017. The platform is FIPS 140-3 validated and deploys as a hardened single-tenant virtual appliance, eliminating the CUI isolation failures that are among the most common reasons DIB organizations require remediation cycles before earning CMMC certification. In addition, Kiteworks supports Hold Your Own Key (HYOK) encryption, giving DIB customers full ownership of their cryptographic keys and reducing audit scope and third-party exposure. "Protecting the DIB was never about a single deadline, but rather about building data security practices durable enough to hold up no matter how the compliance timeline evolves," said Kurt Michael, Chief Revenue Officer, Kiteworks. "Kiteworks and A-LIGN share that same vision. Through our partnership, Kiteworks helps organizations put comprehensive controls at the data layer, and A-LIGN, a top C3PAO, brings the experience and rigor to help validate that work through independent assessment. Whether an organization is early in the process or already underway, Kiteworks helps them get the right controls in place so they can walk into the assessment room prepared." A-LIGN is one of the leading C3PAOs in the market and has conducted nearly 100 CMMC Level 2 assessments across DIB organizations of every size. The firm's assessors cover the full scope of CMMC Level 2, including the governance, personnel, physical, and organizational controls. Beyond CMMC, A-LIGN is also one of the top three FedRAMP assessors, with a team of auditors with deep, firsthand familiarity with how federal agencies expect compliance evidence to be documented and defended. "There's some uncertainty right now about when, and in what form, CMMC's third-party assessment requirements will return from the Department's review, but the underlying requirements haven't gone anywhere," said Nicholas Ludy, Chief Growth Officer, A-LIGN. "The commitment to securing the DIB doesn't hinge on any single implementation date. As CMMC requirements evolve, Kiteworks will keep giving DIB organizations a practical path to stronger data security and audit readiness, and A-LIGN will continue to deliver rigorous, independent assessments, so organizations are prepared whenever the certification timeline is finalized." About Kiteworks Kiteworks' mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies. About A-LIGN A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN has completed more than 36,000 audits. It is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. Founded in 2009, A-LIGN delivers high-quality, efficient audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST. To learn more, visit: https://www.a-lign.com. Additional Resources A-LIGN's recognition of this partnership does not constitute or imply partiality in its assessment activities. As a CMMC Third-Party Assessment Organization (C3PAO), A-LIGN applies the same rigor, scrutiny, and standardized processes to all assessments regardless of an organization's RPO affiliation, technology platform, or partner status. A-LIGN maintains a diverse portfolio of partnerships expressly to prevent any single relationship from creating dependencies that could impair its professional judgment, objectivity, or independence. All assessments are conducted in strict accordance with CMMC assessment guidelines and its impartiality obligations. A-LIGN provides assessment services only. It does not consult, remediate, or advise on control implementation; CMMC certification outcomes are determined solely by independent evaluation of evidence against 32 CFR Part 170 and NIST SP 800-171; and DIB organizations may engage any Authorized or Accredited C3PAO. Get started. It's easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

PR Newswire
Mar 5th, 2026
A-LIGN launches AI-powered EvidenceIQ in A-SCEND platform, appoints strategic advisor

A-LIGN, a cybersecurity compliance provider, has announced major updates to its A-SCEND audit management platform and appointed Steve Cochran as Strategic Advisor. The enhancements come as 97% of organisations now conduct at least two audits annually, according to A-LIGN data. The platform's new EvidenceIQ feature uses AI to assess audit readiness by evaluating submitted documentation against audit requirements, providing request-level scoring and identifying gaps before fieldwork begins. A-SCEND's Cross-Service functionality allows organisations to leverage existing evidence across multiple audits, reducing duplication and accelerating compliance expansion. Cochran, with over 20 years' experience as CTO and CPO at companies including ConnectWise, will help shape A-SCEND's product roadmap. A-LIGN is a leading provider of SOC 2, ISO 27001, and other cybersecurity compliance programmes.

PR Newswire
Feb 25th, 2026
A-LIGN opens London office amid 45% EMEA growth driven by AI and regulatory compliance demand

A-LIGN, a cybersecurity compliance provider, has opened a London office following 45% year-over-year growth in new customer bookings and 60% growth in existing customer bookings across EMEA. The expansion comes amid rising regulatory pressure and increased demand for AI audits, with nearly 75% of companies seeking AI certifications. The company has increased its EMEA workforce by nearly 40% since 2024, appointing senior leaders including Darin Welfare as DVP of EMEA Sales, Helen Spicer as Head of International Marketing, and Harvey Flather as Director of Alliances EMEA. A-LIGN's customers include Synthesia, which recently achieved ISO/IEC 42001 certification for AI governance. The expansion aims to help organisations navigate emerging regulations including the EU AI Act, NIS2 and DORA.

PR Newswire
Feb 4th, 2026
A-LIGN appoints Adam Rudo as strategic advisor to support federal growth and CMMC strategy

A-LIGN, a cybersecurity compliance provider, has appointed Adam Rudo as strategic advisor to support its growth in the Department of Defense ecosystem and Defense Industrial Base. Rudo will guide the company's Cybersecurity Maturity Model Certification strategy, business development and partner engagement. A-LIGN has completed dozens of Level 2 CMMC certifications with hundreds in progress. The company employs over 20 CMMC-certified professionals and assessors. Rudo will also advise on A-LIGN's compliance management software to meet public sector requirements. Rudo brings decades of national security experience from senior roles at ManTech, General Dynamics Information Technology and Lockheed Martin. He led large-scale cyber and IT programmes supporting Intelligence Community and DoD missions. The appointment strengthens A-LIGN's position as organisations navigate evolving DoD cybersecurity requirements.

A-LIGN
Jan 13th, 2026
Steve Simmons Appointed President of A-LIGN

Steve Simmons appointed President of A-LIGN. by: A-LIGN 2 mins Tampa, Fla. (January 13, 2026) - A-LIGN, the leading provider in cybersecurity compliance, has appointed Steve Simmons to serve as President. Simmons, who joined A-LIGN in 2014, served as A-LIGN's Chief Operations Officer since 2021. "Steve has excelled at leading our business through many chapters and he is the right person to assume this new position," said Scott Price, CEO of A-LIGN. "His strong leadership and commitment to continuous improvement will be invaluable as we enter the next stage of A-LIGN's evolution and expand our capacity to meet the increasing global demand for our services." In his new role as President, Simmons will oversee a broadened scope of day-to-day operations with a focus on executing A-LIGN's 2026 strategic priorities. This includes driving international expansion across new geographies and services and further solidifying A-LIGN's leadership in the Cybersecurity Maturity Model Certification (CMMC) assessment market. He will be responsible for integrating elevated strategy with seamless execution to ensure A-LIGN stays ahead of the industry's most complex cybersecurity compliance needs. At the core of this growth is the continued evolution of A-SCEND, A-LIGN's proprietary audit management platform. "What excites me most is the opportunity to shape A-LIGN's future in a rapidly evolving landscape where technology and compliance are merging," said Simmons. "We are focused on unlocking new possibilities by leveraging A-SCEND's AI-powered automation to not only drive growth and innovation, but to ensure world-class retention." This leadership appointment comes as A-LIGN has completed a banner year in 2025 with a strategic investment from Hg, which confirmed its status as a unicorn and added new board members. This new organizational structure will empower Price to focus on external strategic priorities including customers and partners, while continuing to set overall vision, while Simmons' operational expertise provides the foundation for A-LIGN to scale its enterprise-grade audit experience through deeper GRC integrations and technology-led delivery. "I joined A-LIGN when we were fewer than 30 employees and being part of that journey has shaped my leadership," said Simmons. "As we look ahead, I'm excited to build on those lessons as we expand our services, enter new markets, and continue advancing our A-SCEND technology to elevate our goal of delivering a frictionless, high-quality experience that moves compliance from a point-in-time hurdle to a continuous strategic advantage for our clients." About A-LIGN A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN has completed more than 36,000 audits. It is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. Founded in 2009, A-LIGN delivers high-quality, efficient audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST. To learn more, visit: https://www.a-lign.com.

INACTIVE