Job Closed
This listing is no longer active.
Cybersecurity Subject Matter Expert (Remote)
Location
United States
Posted
91 days ago
Salary
0
Seniority
Mid Level
No structured requirement data.
Job Description
Cybersecurity Subject Matter Expert (Remote)
ESM
Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Project Manager for an exciting remote opportunity. Job Description and Responsibilities Support the Defense Travel Management Office's (DTMO) compliance with cybersecurity rules, regulations, and policies in accordance with NIST policy. Support DTMO's requirements to maintain current and achieve new Authorities to Operate (ATOs) and Authorities to Connect (ATCs) for all DTMO systems using the DoD Risk Management Framework (RMF). Perform System-Level Information System Security Officer (S-ISSO) responsibilities. Required Knowledge, Skills and Abilities (KSA) - Knowledge of cybersecurity principles, risk management practices, and defense-in-depth strategies for protecting information systems and networks. - Knowledge of federal cybersecurity frameworks and standards, including guidance from NIST Risk Management Framework, NIST Cybersecurity Framework, and NIST SP 800-53 security controls. - Knowledge of U.S. federal cybersecurity compliance requirements - Knowledge of security technologies and architectures, including network security, identity and access management, encryption, endpoint protection, and cloud security. - Knowledge of threat detection, vulnerability management, and incident response processes used to identify, assess, and mitigate cybersecurity threats. Desired KSA - Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations - Candidate must communicate effectively with team members, team lead, management, and government customer - Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision Minimum Training, Education, and Certifications - Bachelor's degree in a relevant field - Five (5) years experience in cybersecurity with executing Risk Management Framework - Specific Experience with: - RMF process and documentation, PIAs, SORNs, ATOs and ATCs - CSSP vulnerability assessments, CORA, DoD IG audits - POAM management - Vulnerability and patch management - STIG and IAVM compliance - Support for internal/external audits, pen testing, red team testing and other security reviews Minimum Clearance - Top Secret Physical Requirements - Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus. Additional Requirements - Other duties as assigned ESM provides equal employment opportunity to all individuals regardless of race, color, creed, religion, gender, age, sexual orientation, national origin or ancestry, disability, genetic information, veteran status, gender identification or any other characteristic protected by state, federal or local law.
Job Requirements
- Knowledge of cybersecurity principles, risk management practices, and defense-in-depth strategies for protecting information systems and networks.
- Knowledge of federal cybersecurity frameworks and standards, including guidance from NIST Risk Management Framework, NIST Cybersecurity Framework, and NIST SP 800-53 security controls.
- Knowledge of U.S. federal cybersecurity compliance requirements.
- Knowledge of security technologies and architectures, including network security, identity and access management, encryption, endpoint protection, and cloud security.
- Knowledge of threat detection, vulnerability management, and incident response processes used to identify, assess, and mitigate cybersecurity threats.
- Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations.
- Candidate must communicate effectively with team members, team lead, management, and government customer.
- Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision.
- Bachelor's degree in a relevant field.
- Five (5) years experience in cybersecurity with executing Risk Management Framework.
- Specific Experience with:
- RMF process and documentation, PIAs, SORNs.
- ATOs and ATCs.
- CSSP vulnerability assessments, CORA, DoD IG audits.
- POAM management.
- Vulnerability and patch management.
- STIG and IAVM compliance.
- Support for internal/external audits, pen testing, red team testing and other security reviews.
- Top Secret clearance required.
- Physical Requirements
- Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus.
- Additional Requirements
- Other duties as assigned.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Surveillance Investigator
CoventBridge GroupCoventBridge Group offers a full range of investigative services for clients around the world. The company provides surveillance, counter-fraud services, and cl
Overview Surveillance Investigator - Full Time Winston-Salem, NC Area CoventBridge Group is growing—and we’re looking for licensed investigators to join our elite surveillance team. In this role, you’ll conduct discreet, vehicle-based field investigations to help uncover insurance fraud and deliver trusted results to our clients. As a leader in the fraud investigation industry, CoventBridge offers the opportunity to work remotely with flexible scheduling, advanced tools, and the support of a nationwide team. Responsibilities/ Requirements Key Responsibilities: - Case Prep: Use social media and database tools to conduct initial research and gather intel on subjects. - Surveillance in the Field: Carry out discreet, mobile and stationary surveillance—track movements and capture high-quality video evidence. - Reporting: Write thorough, court-ready reports that clearly document key activities and findings. - Evidence Submission: Wrap up each day by uploading reports and video footage from your personal laptop. - Team Collaboration: Stay connected with your field supervisor for ongoing support, guidance, and mentorship. Essentials for this Role: - PI License: Must currently hold—or be eligible to obtain—Private Investigator licenses in multiple states, including North Carolina and surrounding jurisdictions. - Driver's License: Active driver's license that is not currently suspended or revoked. - Personal Vehicle: A well-maintained vehicle that is always reliable (preferably with tinted windows). Proof of auto insurance coverage is required. - Travel Expectations: While we aim to keep assignments within a reasonable drive of your residence, occasional further travel and overnight stays (covered by the company) may be required. - Technology: A reliable laptop, cell phone, and internet service are needed for communication and administrative tasks. - Required Skills: Strong computer & internet proficiency. Excellent communication, verbal & writing skills. Possess or is willing to purchase covert camera, digital video camera with uploading capabilities, and laptop computer with Windows Operating System with access to Microsoft Word Additional Responsibilities: Duties and responsibilities include essential functions of positions assigned to this classification. Depending on assignment, the employee may perform a combination of some or all the following duties: - Conduct Fixed and Mobile Video Surveillance: Capture high-quality video footage of subjects to assist in case investigations. - Gather Evidence: Obtain videotaped documentation, photos, and audio recordings as part of thorough surveillance. - Background and Activity Checks: Perform courthouse research, background checks, and monitor subject activities to build robust case reports. - Investigative Reporting: Draft clear, concise, and detailed investigative reports summarizing findings and evidence. - Evidence Management: Upload all video, photographic, and audio evidence into the case management system in a timely and organized manner. - Drive Safely and Responsibly: Remain alert and practice safe driving while traveling to and from investigation sites. Working Conditions: - Most surveillance cases start at 6:00AM. End time can vary depending on activity. - Weekends/holidays are common workdays as claimants are more likely to be active. - This is an independent role often requiring long hours alone in your vehicle, regardless of weather conditions. - Must remain alert with no external distractions, ready to use videography equipment to document subjects. Benefits Compensation & Perks That Work For You: We believe great work deserves great rewards. Here’s what you can expect when you join our team: Competitive Pay On-the-Road Support: - Monthly vehicle allowance - Company fuel card - Company-issued cell phone - Monthly internet stipend - Travel & report writing compensation - Fast, hassle-free expense reimbursements (minimal out-of-pocket costs) Full Coverage Benefits: - Medical, dental, and vision insurance - Employer-paid life insurance, short-term & long-term disability Future-Focused Perks: - Company-matching 401(k) to help you build for the future - Paid time off to recharge and reset - Company-paid investigator licensing fees Career Growth: - Ongoing paid training and advancement opportunities to help you grow your skills and your career About Us: CoventBridge Group is the global leader in full-service investigations providing: Surveillance, SIU and Compliance, Claims Investigation, Counter-Fraud Programs, Desktop Investigations, Social Media, Record Retrieval, Canvasses and Vendor Management programs. The company provides top tier data privacy and security practices, deploys robust case management technology customized to clients’ needs and delivers worldwide coverage via its 1000 employees and affiliates worldwide. CoventBridge Group is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, caste, disability, veteran status, and other legally protected characteristics and maintains a drug-free workplace. CoventBridge Group is committed to the full inclusion of all qualified individuals. As part of this commitment, CoventBridge will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact: Human Resources; 888-932-7364; humanresources@coventbridge.com. At this time, CoventBridge is not considering candidates who require visa sponsorship, currently or in the future, including but not limited to H-1B, H-2B, E-3, TN, O-1, F-1 (OPT/CPT, or J-1 Visa Statuses.) License #: BPN0072064PM
Security Control Assessor
Harmonia Holdings Group, LLCHarmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction. Here at Harmonia we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification
Harmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction. Description Title: Security Control Assessor Location: Remote Terms: Full-time Clearance: Public Trust Travel: <10% Position Description We have an opening for a full-time Security Control Assessor to join our talented, dynamic team in support of the Department of Veterans Affairs. As a Security Control Assessor, you will be trusted to support the delivery of our cybersecurity solutions and services. In this role, you will be a part of a security control assessment team working on the tasks outlined below. Veterans are encouraged to apply. Responsibilities: - Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37). - Plans and conducts security authorization reviews and assurance case development for initial installation of systems and networks. - Reviews authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. - Verifies that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. - Develops security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). - Performs security reviews and identifies security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. - Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. - Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Requirements - Bachelor's degree in computer science, electronics engineering or other engineering or technical discipline is required, and will accept relevant experience in lieu of degree. - 1+ years hands-on experience with Cybersecurity policy, risk management, or security and privacy control assessments. - Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). - Knowledge of system and application security threats and vulnerabilities. - Knowledge of Personally Identifiable Information (PII), Payment Card Industry (PCI), and Personal Health Information (PHI) data security standards. Desired - Experience with security control assessments within the VA using the NIST Risk Management Framework (RMF) is a plus. - Certifications such as SCA and CISA are a plus. - Exceptional written and verbal communication skills. - Strong planning, organizational, and time management skills. - Exceptional analytical and conceptual thinking skills. - Ability to work collaboratively with a team of peers. ___________________________________________________________________________________________________________ Here at Harmonia we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: - Recognized as a Top 20 "Best Place to Work in Virginia" - Recipient of Department of Labor's HireVets Gold Medallion - Great Place to Work Certification for five years running - A Virginia Chamber of Commerce Fantastic 50 company - A Northern Virginia Technology Council Tech 100 company - Inc. 5000 list of fastest growing companies for eleven years - Two-time SBA SBIR Tibbett's Award winner - Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Harmonia family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to - Traditional and HSA- eligible medical insurance plans - 100% employer-paid dental and vision insurance options - 100% employer-sponsored STD, LTD, and life insurance - 5% 401(k) company matching - Flexible-schedules and teleworking options - Paid holidays and PTO Accrual Plans - Paid Parental Leave - Professional development and career growth opportunities - Team and company-wide events, recognition, and appreciation-- and so much more! Check out our LinkedIn, Facebook, and Instagram to find out a little more about who we are and if we are the right next step for your career! Harmonia is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Harmonia does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@harmonia.com.
Lead Security Control Assessor
Harmonia Holdings Group, LLCHarmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction. Here at Harmonia we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification
Harmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction. Description Title: Security Control Assessor Location: Remote Terms: Full-time Clearance: Public Trust Travel: <10% Position Description We have an opening for a full-time Security Control Assessor to join our talented, dynamic team in support of the Department of Veterans Affairs. As a Security Control Assessor, you will be trusted to support the delivery of our cybersecurity solutions and services. In this role, you will be a part of a security control assessment team working on the tasks outlined below. Veterans are encouraged to apply. Responsibilities: - Lead a small team in coordinating and conducting security control assessment activities, stakeholder interviews, and report generation. - Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37). - Plans and conducts security authorization reviews and assurance case development for initial installation of systems and networks. - Reviews authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. - Verifies that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. - Develops security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). - Performs security reviews and identifies security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. - Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. - Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Requirements - Bachelor's degree in computer science, electronics engineering or other engineering or technical discipline is required, and will accept relevant experience in lieu of degree. - 2+ years hands-on experience with Cybersecurity policy, risk management, or security and privacy control assessments. - Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). - Knowledge of system and application security threats and vulnerabilities. - Knowledge of Personally Identifiable Information (PII), Payment Card Industry (PCI), and Personal Health Information (PHI) data security standards. Desired - Experience with security control assessments within the VA using the NIST Risk Management Framework (RMF) is a plus. - Certifications such as SCA and CISA are a plus. - Exceptional written and verbal communication skills. - Strong planning, organizational, and time management skills. - Exceptional analytical and conceptual thinking skills. - Ability to work collaboratively with a team of peers. ___________________________________________________________________________________________________________ Here at Harmonia we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: - Recognized as a Top 20 "Best Place to Work in Virginia" - Recipient of Department of Labor's HireVets Gold Medallion - Great Place to Work Certification for five years running - A Virginia Chamber of Commerce Fantastic 50 company - A Northern Virginia Technology Council Tech 100 company - Inc. 5000 list of fastest growing companies for eleven years - Two-time SBA SBIR Tibbett's Award winner - Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Harmonia family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to - Traditional and HSA- eligible medical insurance plans - 100% employer-paid dental and vision insurance options - 100% employer-sponsored STD, LTD, and life insurance - 5% 401(k) company matching - Flexible-schedules and teleworking options - Paid holidays and PTO Accrual Plans - Paid Parental Leave - Professional development and career growth opportunities - Team and company-wide events, recognition, and appreciation-- and so much more! Check out our LinkedIn, Facebook, and Instagram to find out a little more about who we are and if we are the right next step for your career! Harmonia is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Harmonia does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@harmonia.com.
The mission of The New York Times is to seek the truth and help people understand the world. That means independent journalism is at the heart of all we do as a company. It’s why we have a world-renowned newsroom that sends journalists to report on the ground from nearly 160 countries. It’s why we focus deeply on how our readers will experience our journalism, from print to audio to a world-class digital and app destination. And it’s why our business strategy centers on making journalism so good that it’s worth paying for. About the Role The Workday Security Senior Analyst will be a strategic partner on the Workday Security Team. This person will work closely with business partners, analysts, and cross-functional teams to translate security requirements into the configuration. The configuration will enable role-based workflow and data security. You'll serve as a subject matter expert, leading teams on complex projects and mentoring team members. Responsibilities: - Partner with HR/Finance/Technology on Workday related projects, including system releases/upgrades, and configuration redesign. - End-to-end security support of Workday. - Define and update security groups. - Define and maintain domains and business process security policies. - Analyze and audit security policies and procedures and recommends improvements. - Support systems authentication, security compliance and change management controls. - Recommend Workday security design, configuration, workflow, and security administration procedures and improvements. - Document solutions to facilitate long-term operational support. - Document and transfer knowledge; develop capabilities of production support team for the gold tenant. - Serve as a point of contact to SMEs for their security needs and ensure best practices are effectively communicated and implemented. - Provide an exceptional level of customer service and support to all business units and other internal and external contacts and respond in a timely manner to customer service feedback. - Demonstrate support and understanding of our value of journalistic independence and a strong commitment to our mission to seek the truth and help people understand the world. - This role reports to the IT Workday Security Manager. Basic Qualifications: - 5+ years of related Workday Security experience - Familiarity with relevant regulatory guidelines, including SOX, GDPR, and PCI, and their associated compliance protocols Preferred Qualifications: - Pro or implementer certification in HCM, Finance or other Workday module REQ-018532 The annual base pay range for this role is between: $130,000—$160,000 USD For roles in the U.S., dependent on your role, you may be eligible for variable pay, such as an annual bonus and restricted stock. Benefits may include medical, dental and vision benefits, Flexible Spending Accounts (F.S.A.s), a company-matching 401(k) plan, paid vacation, paid sick days, paid parental leave, tuition reimbursement and professional development programs. For roles outside of the U.S., information on benefits will be provided during the interview process. The New York Times Company is committed to being the world’s best source of independent, reliable and quality journalism. To do so, we embrace a diverse workforce that has a broad range of backgrounds and experiences across our ranks, at all levels of the organization. We encourage people from all backgrounds to apply. We are an Equal Opportunity Employer and do not discriminate on the basis of an individual's sex, age, race, color, creed, national origin, alienage, religion, marital status, pregnancy, sexual orientation or affectional preference, gender identity and expression, disability, genetic trait or predisposition, carrier status, citizenship, veteran or military status and other personal characteristics protected by law. All applications will receive consideration for employment without regard to legally protected characteristics. The U.S. Equal Employment Opportunity Commission (EEOC)’s Know Your Rights Poster is available here. The New York Times Company will provide reasonable accommodations as required by applicable federal, state, and/or local laws. Individuals seeking an accommodation for the application or interview process should email reasonable.accommodations@nytimes.com. Emails sent for unrelated issues, such as following up on an application, will not receive a response. The Company encourages those with criminal histories to apply, and will consider their applications in a manner consistent with applicable "Fair Chance" laws, including but not limited to the NYC Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act. For information about The New York Times' privacy practices for job applicants click here. Please beware of fraudulent job postings. Scammers may post fraudulent job opportunities, and they may even make fraudulent employment offers. This is done by bad actors to collect personal information and money from victims. All legitimate job opportunities from The New York Times will be accessible through The New York Times careers site. The New York Times will not ask job applicants for financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who suggests they can provide employment with The New York Times. If you see a fake or fraudulent job posting, or if you suspect you have received a fraudulent offer, you can report it to The New York Times at NYTapplicants@nytimes.com. You can also file a report with the Federal Trade Commission or your state attorney general.


