Security, RMF Lead

🕒 vor 2 Monaten

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Essnova Solutions, Inc.

Essnova Solutions, Inc.

11 - 50 Mitarbeiter

Gegründet 2005

💼 Beratung

🏥 Gesundheitswesen

📦 Logistik

Consulting • Healthcare • Logistics

Essnova Solutions, Inc. ist ein Technologie- und Beratungsunternehmen, das IT-Lösungen, Mehrwert-Reseller-Dienste (VAR/ITVAR), geospatiale und umwelttechnische Lösungen, Personalverstärkung sowie Unterstützung im Gesundheitswesen und digitale Bürger- und Kundenerfahrungsdienste für Bundes-, Landes- und Kommunalbehörden, Bildungsinstitutionen, Gewerbe- und Gesundheitskunden bietet. Das Unternehmen ist ein zertifiziertes 8(a) und HUBZone Kleinunternehmen mit mehreren GSA-Vertragsfahrzeugen und konzentriert sich auf Cloud-Migration, Big Data und KI, Informations- und Cybersicherheit, Programm- und Projektmanagement sowie die vollständige Implementierung und den Support von Technologien.

Beschreibung

• Maintain System Security Plans (SSPs) as living documents for all NCHS systems, ensuring timely updates after security-impacting changes. • Manage Plan of Action & Milestones (POA&Ms) with quarterly progress reviews, closure evidence, and remediation tracking. • Remediate vulnerabilities within mandated timelines, track findings through closure, and provide retesting evidence. • Prepare Authorization to Operate (ATO) packages—including SSPs, POA&M status, assessment results, and risk analysis—for Authorizing Official review. • Conduct annual security assessments of one-third-plus-key-controls using CSAM or equivalent tools. • Submit monthly authenticated vulnerability and application scan results by the fifth business day. • Coordinate among developers, system owners, and security staff, and liaise with CDC CSPO, NCHS SSPO, and CDC Enterprise Architects. • Follow CDC CSPO Change Management SOP, including security impact analysis for post-ATO changes. • Support implementation of the Risk Management Framework (RMF), FISMA compliance, and OMB directives. • Produce security-related EPLC artifacts for governance and stage-gate reviews. • Lead SSP development during the 30-day transition-in activation sequence and support SSP submission within 30 days of contract award. • Support PTA/PIA activities with CDC privacy officials.

🎯 Anforderungen

• Bachelor's degree in cybersecurity, information assurance, computer science, or a related field • 6+ years of federal information security experience applying NIST RMF (NIST SP 800-37) • Experience developing and maintaining SSPs, POA&Ms, and ATO packages for FIPS 199 Moderate or higher systems • Experience using vulnerability scanning results to track remediation to closure (including retesting evidence) in a federal environment • Hands-on experience with federal security management tools (CSAM and eMASS) • Working knowledge of NIST SP 800-53 Rev. 5 and NIST SP 800-53A • Knowledge of FISMA 2014 reporting and OMB security directives • Knowledge of Privacy Act and E-Government Act privacy provisions, including PTA/PIA processes • Experience coordinating with federal ISSOs/CISOs and security authorization officials • Active Tier 4 / High Risk / Public Trust Level 6+ clearance at proposal submission • Eligibility for HSPD-12/PIV • Availability to work during Eastern Time (ET) business hours

🏖️ Vorteile

• Medical, dental, and vision insurance • 401(k) with company match • Paid time off + federal holidays • Fast-track growth in a high-accountability culture

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 2 Monaten

Keeper Security, Inc.

501 - 1000

🔒 Cybersecurity

☁️ SaaS

🏢 Unternehmen

🇺🇸 Vereinigte Staaten – Remote

💰 Private Equity Round - Keeper Security im 2023-05

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 2 Monaten

Baker Tilly US

5001 - 10000

🏗️ Bauwesen

🏥 Gesundheitswesen

📦 Logistik

Join Baker Tilly as an IT Audit, Cybersecurity & Risk Senior Consultant. Manage financial and operational technology risks while collaborating with client executives and teams.

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cloud

Cyber Security

🕒 vor 2 Monaten

GuidePoint Security

201 - 500

💼 Beratung

🏥 Gesundheitswesen

📦 Logistik

Senior Cyber Security Consultant providing compliance services for clients across the U.S. Delivering assessments, advisory services, and maintaining industry standards for security.

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cloud

Cyber Security

🕒 vor 2 Monaten

Caesars Entertainment

10.000+ Mitarbeiter

💼 Beratung

📣 Marketing

✈️ Reisen

Lead Cloud Security Architect at Caesars protecting cloud infrastructure and applications. Collaborate with teams to integrate security into development lifecycle and mitigate emerging threats.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 2 Monaten

ePlus Technology Solutions

51 - 200

🔌 API

🤖 Künstliche Intelligenz

☁️ SaaS

IAM Lead Technical Architect at ePlus responsible for enterprise Identity and Access Management solutions. Leading and mentoring a team while collaborating for modern IAM systems.

🇺🇸 Vereinigte Staaten – Remote

💵 $125.000 - $170.000 / Jahr

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich