Responsibilities
- Actively participate and lead meetings to review and assess compliance of systems and technology
- Perform risk assessments based on Federal guidelines and industry best practices
- Assist teams in identifying vulnerabilities and providing recommendations to reduce cybersecurity risk
- Create and mature control-specific procedures for RMF control families by interpreting NIST requirements, identifying system-specific implementation needs, and developing effective procedural documentation that supports both mission operations and defensible compliance.
- Articulate and report on cybersecurity risk and compliance to executives and senior leaders
- Understand Vulnerability details, both technical and control-based, and craft actionable remediation plans and mitigation strategies
- Create, maintain, and track POA&Ms – working with system owners and technical teams to identify corrective actions, document mitigations, monitor remediation progress, and support timely closure of security findings.
- Support remediation of control-based POA&Ms by analyzing control weaknesses, recommending corrective actions or mitigations, coordinating with technical teams, and reviewing closure evidence to confirm the weakness has been resolved.
- Author A&A documentation to create foundational RMF documentation to support system authorization
- Continually improve the cybersecurity risk assessment and POA&M process and program
- Aggregate and track cybersecurity POA&Ms and risks across projects, teams, and programs
- Respond to and triage security incidents as a key member of the incident response team
- Communicate cybersecurity best practices based on policies, standards, and controls
Requirements
- 5+ years of cybersecurity and compliance experience
- Active Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification
- Strong leadership and interpersonal skills to facilitate effective collaboration across a variety of stakeholders
- Demonstrated ability to function independently and define the proper methods & procedures
- Understanding of guiding cybersecurity principles and control guidance
- Effective writing skills to capture issues and recommendations
- Strong customer relationship building ability
- Bachelor's degree
- Minimum of 5 years of overall experience
- Minimum of 5 years of specific experience in field
- Secret clearance to start
- US Citizenship
Work Arrangement
Hybrid
Additional Information
- Travel: Little (less than 10%)
- Telecommute Options: Yes, Hybrid (2-3 days onsite)
- On-call: Required periodically, with annual coverage varying up to 3-4 months
- Clearance: Secret to start
- Work Status: US Citizenship