Search Remote Jobs

Principal, Public Sector SecOps, GRC

πŸ”₯ 51 minutes ago

Apply Now
Find Similar Remote Jobs

πŸ“Š Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Consensus Cloud Solutions

Consensus Cloud Solutions

501 - 1000 employees

πŸ₯ Healthcare

☁️ SaaS

πŸ€– Artificial Intelligence

πŸ’° $225M Post-IPO Debt - Consensus Cloud Solutions on 2025-07

Healthcare β€’ SaaS β€’ Artificial Intelligence

Consensus Cloud Solutions is a public company (NASDAQ: CCSI) that started as a digital cloud faxing organization over 20 years ago and spun off from J2 Global (Ziff Davis) in October 2021. It is described as the global leader of digital cloud fax technology and provides solutions that transform unstructured digital documents into secure, advanced healthcare standard HL7/FHIR structured data. The company leverages Natural Language Processing and AI to create analytics-ready data for clinicians, enabling secure handling of healthcare documents and integration with healthcare data standards. It focuses on the healthcare industry, emphasizing secure cloud fax and document-to-data transformation.

πŸ“‹ Description

β€’ Serve as the central security and compliance leader for all public sector engagements β€’ Lead the design, implementation, and oversight of a unified security framework that aligns with NIST 800-53 Rev. 5 controls, FedRAMP High authorizations, GovRAMP, CMMC, and emerging SLED requirements β€’ Ensure timely threat mitigation, streamlined audit processes, and secure delivery of cloud services to government agencies β€’ Compile and submit Monthly Continuous Monitoring (ConMon) reports, including vulnerability scans, POA&M trackers, and asset inventories β€’ Oversee threat hunting and vulnerability remediation to ensure compliance with strict federal timelines β€’ Escalate unremediated vulnerabilities and initiate Plan of Action and Milestones (POA&M) creation within 7 days of issue identification β€’ Coordinate and lead Annual 3PAO Security Assessments, including penetration testing and red team exercises β€’ Manage and maintain a compliant, hosted secure repository for storing, retrieving, and provisioning access to security packages and artifacts β€’ Manage third parties performing public sector security functions and direct project management support for these programs β€’ Serve as System Steward for the VA-F package in eMASS β€’ Submit and maintain accurate documentation for marketplace listings β€’ Oversee actionable incident response testing every 6 months β€’ Manage background checks and reinvestigations for personnel requiring system access β€’ Maintain current SaaS platform architecture diagrams and submit Security Change Requests (SCRs) β€’ Contribute to non-FedRAMP commercial compliance frameworks β€’ Provide security and compliance guidance to IT, engineering, and development teams β€’ Identify, evaluate, and implement GRC and SecOps tools β€’ Assist with responses to customer security assessments β€’ Mentor junior staff or cross-functional team members β€’ Support business continuity planning, disaster recovery documentation, and live operational exercises.

🎯 Requirements

β€’ Bachelor's degree in computer science, information technology, or cybersecurity. β€’ Active Certified Information Systems Security Professional (CISSP) and Project Management Professional (PMP) certification. β€’ Undergo a Public Trust Background Investigation with a favorable suitability determination. β€’ 8+ years of experience in information security governance, risk, and compliance, with at least 5 years specifically supporting FedRAMP High, FISMA, NIST SP 800-53 rev 5, or RMF. β€’ 5+ years in the ISSM or ISSO role managing the security package for federal government agencies high-impact systems. β€’ 5+ years of experience managing or supporting security assessments with Third Party Assessment Organizations (3PAOs). β€’ 3+ years of hands-on experience using GRC platforms (e.g., RSA Archer, ServiceNow GRC, OneTrust) and vulnerability management platforms (e.g., Tenable, Qualys, Rapid7). β€’ 2+ years direct experience mapping controls and leading assessments for GovRAMP, CMMC (Level 2+), and StateRAMP/SLED requirements. β€’ 2+ years of experience with identity and access management systems (e.g., Okta, Azure AD) for access control governance. β€’ Demonstrated experience working within cloud environments such as AWS GovCloud or Azure Government, including cloud-native security controls. β€’ Proficiency with AWS CLI, PowerShell and scripting automated compliance tasks in Windows and Linux systems tools, Nessus Pro, Burp Suite, Splunk, AWS IAM, Jira, FortiGate firewalls, eMASS, Box.com for Gov, and Okta for Gov Identity Provider. β€’ Demonstrates strong analytical skills to assess complex security risks, interpret compliance requirements, and evaluate technical vulnerabilities. β€’ Builds and refines repeatable, auditable processes for security governance, risk management, and compliance activities. β€’ Communicates clearly and effectively with technical and non-technical stakeholders, including auditors, developers, and executive leadership. β€’ Ability to implement continuous monitoring and assessment programs to identify and address security threats in real-time, maintaining a proactive SecOps stance.

πŸ–οΈ Benefits

β€’ Annual performance bonus β€’ ESPP β€’ Enhanced time off packages

Apply Now

Similar Jobs

πŸ•’ Yesterday

LUX Infusion

2 - 10

πŸ₯ Healthcare

πŸ’Š Pharmaceuticals

Security Operations Manager responsible for cybersecurity operations within healthcare at LUX Infusion. Leading security assessments, incident response, and regulatory compliance.

πŸ•’ Yesterday

Edged

51 - 200

🀝 B2B

⚑ Energy

Director of Security, Risk & Compliance Operations at Edged managing security programs in North America. Overseeing physical security, compliance, and business continuity across data centers.

πŸ•’ Yesterday

jrni

51 - 200

☁️ SaaS

🀝 B2B

🏒 Enterprise

Director of Information Security and Operations at jrni, a customer engagement solutions provider. Leading InfoSec and TechOps teams while ensuring operational excellence and security compliance.

πŸ•’ 4 days ago

Echo Global Logistics

1001 - 5000

πŸ“¦ Logistics

πŸš— Transport

☁️ SaaS

Manager of Security Operations leading AI-powered threat detection and incident response at Echo Global Logistics. Overseeing SOC operations and mentoring analysts to improve security outcomes.

πŸ•’ July 21

Allstate

10,000+ employees

πŸ’Ό Consulting

πŸ“¦ Logistics

πŸ›‘οΈ Insurance

Service Manager overseeing Supplier Security Due Diligence & Monitoring Service at Allstate. Leading a specialized service intersecting cybersecurity, legal, and business strategy.