Job Closed

This listing is no longer active.

Dragonfli Group logo
Dragonfli Group

CyberSecurity as a Solution: Enabling Secure Business.

Information System Security Officer

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

60 days ago

Salary

0

Seniority

Mid Level

Bachelor Degree2 yrs expEnglish

Job Description

Information System Security Officer

Dragonfli Group

• Execute and maintain all RMF lifecycle activities for assigned federal information systems: categorization, control selection, implementation, assessment, authorization, and continuous monitoring • Develop, maintain, and update system security documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Authorization to Operate (ATO) packages • Coordinate with Information System Owners (ISOs), Authorizing Officials (AOs), and Security Control Assessors (SCAs) to drive ATO decisions on schedule • Monitor security controls on an ongoing basis; identify, document, and track deviations and vulnerabilities to closure • Conduct and support continuous monitoring activities including log review, vulnerability scan analysis, and configuration compliance validation • Support incident response activities including documentation, escalation, and remediation tracking • Maintain system inventory, hardware/software baselines, and interconnection agreements • Ensure compliance with applicable federal directives including FISMA, OMB A-130, and agency-specific security policies • Participate in security reviews, audits, and inspections as required

Job Requirements

  • 1-3 years of direct ISSO or ISSO-support experience in a US Federal environment
  • Hands-on experience with NIST RMF (SP 800-37) and NIST SP 800-53 security controls
  • Demonstrated ability to develop and maintain ATO documentation packages independently
  • Familiarity with federal compliance tools such as eMASS, Xacta, or equivalent GRC platforms
  • Strong written communication skills; federal documentation standards experience required

Benefits

  • Insurance - health, dental, and vision
  • PTO & Federal Holidays (paid)
  • 401(k) match

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 51-200Since 2008H1B No Sponsor

• You will take a key role in technical customer support for our vulnerability management solutions as part of our Presales Consulting team. • You act as a technical point of contact on equal footing — with deep IT security expertise combined with the ability to understand complex customer requirements, facilitate discussions, and channel insights into product development. • You build long-term technical relationships with security stakeholders in large enterprises and federal agencies, understand their challenges, and translate them into concrete recommendations — both for customers and internally for our product teams. • Support the sales process with technical expertise and thorough feasibility analyses. • Technical lead for selected strategic customers (enterprise/federal agencies). • Advise and support customers in building, operating, and advancing their vulnerability management programs. • Conduct technical deep dives, workshops, and health checks to continuously improve the deployment of Greenbone solutions. • Closely coordinate with the Product Department to evolve our vulnerability management solutions based on customer feedback. • Analyze complex infrastructures and support architecture decisions and scaling strategies. • Establish a reliable trust relationship as a technical sparring partner for CISOs, SOC leads, and IT security managers. • Represent the company at international conferences, including as a speaker on technical topics.

Germany
Job Closed
Full TimeRemoteTeam 501-1,000Since 1974H1B No Sponsor

• Planning and implementation of security measures for preventive threat mitigation at our events • Execution of protection and security measures • Identifying and assessing legal violations and potential threat situations • Communicating and cooperating with clients, colleagues, the police and authorities • Protecting and securing people, property and assets • Investigating, clarifying and documenting security-related incidents • Driving security-related processes with a results-oriented approach • Offering security services • Analyzing security risks and planning and carrying out appropriate countermeasures

Germany
€1.4K - €1.5K / month
Job Closed
Froedtert logo

Cybersecurity GRC Manager, FCH - IT - SECURITY

Froedtert

The Froedtert & the Medical College of Wisconsin regional health network is a partnership between Froedtert Health and the Medical College of Wisconsin supporting a shared mission of patient care, innovation, medical research and education. Our health network operates eastern Wisconsin's only academic medical center and adult Level I Trauma center engaged in thousands of clinical trials and studies. The Froedtert & MCW health network, which includes ten hospitals, nearly 2,000 physicians and more than 45 health centers and clinics draw patients from throughout the Midwest and the nation.

Full TimeRemoteTeam 10,001

Discover. Achieve. Succeed. #BeHere Location: US:WI:MENOMONEE FALLS at our WOODLAND PRIME 400 facility. This job is REMOTE. FTE: 1.000000 Standard Hours: 40.00 Shift: Flexible 1st shift between 7 am and 5 pm Shift Details: Holidays: Weekends: Job Summary: Healthcare security isn’t a compliance checkbox problem — it’s a patient safety problem. At Froedtert ThedaCare, the Cybersecurity GRC Manager owns the program that connects our governance posture to real-world risk outcomes for patients, clinicians, and the communities we serve across Wisconsin. This is a high-visibility, high-autonomy leadership role inside a Cybersecurity & Infrastructure team that operates with strategic intent and operational rigor. You will build and run a team of 5+ GRC professionals, serve as the internal subject matter authority on compliance and risk, and translate complex regulatory requirements into actionable programs that the broader organization can execute against. If you’ve built GRC programs from scratch (or rebuilt ones that needed it), know your way around a HIPAA gap analysis and a third-party risk assessment in equal measure, are people-focused, and lead with clarity rather than bureaucracy — this is the role for you People Leadership •Lead, mentor, and grow a team of 5+ GRC analysts and specialists across compliance, risk, policy, and awareness domains •Establish clear role expectations, development pathways, and performance standards for each team member •Foster a team culture that balances rigor with pragmatism — we care about outcomes, not just documentation HIPAA & Healthcare Compliance •Serve as the organization’s functional lead for HIPAA Privacy and Security Rule compliance, including ongoing gap assessment and remediation tracking •Coordinate with Legal, Privacy, and Clinical Operations to ensure compliance obligations are understood and operationalized across the enterprise •Oversee preparation for and response to regulatory inquiries, OCR investigations, and audit activity Risk Management & Third-Party Risk •Own the enterprise cybersecurity risk register, ensuring risks are identified, assessed, prioritized, and tracked to resolution •Lead the third-party risk management program, including vendor onboarding assessments, ongoing monitoring, and risk-tiering across the supply chain •Develop risk reporting for executive and board audiences, translating technical risk into business impact language Policy & Controls Frameworks •Own the cybersecurity policy lifecycle: authorship, review cadence, version control, approval workflows, and exception management •Maintain alignment to NIST CSF, managing control mapping, evidence collection, and control effectiveness measurement •Drive continuous improvement of the controls environment based on assessment findings, threat intelligence inputs, and regulatory changes Audit & Assessment Management •Serve as the primary point of contact and program lead for internal and external cybersecurity audits and assessments •Coordinate evidence collection, manage stakeholder readiness, and oversee finding remediation tracking through to closure •Develop and maintain audit-ready documentation across all GRC domains Security Awareness & Phishing Simulation • Own the enterprise security awareness program, including curriculum development, delivery scheduling, and effectiveness measurement • Manage the phishing simulation program end-to-end: scenario design, cadence, metrics, and targeted follow-up training for at-risk populations • Tailor awareness content for diverse audiences — from clinical staff to executive leadership — with a voice that educates rather than shames EXPERIENCE DESCRIPTION: • A minimum of six year experience in a related field. • Prefer 3+ years leading or managing a team in a GRC, compliance, or risk management capacity • Prefer experience in a healthcare or other highly regulated industry, with direct exposure to HIPAA compliance obligations • Demonstrated experience managing a third-party risk program, including vendor assessments and risk tiering • Prefer prior experience building or significantly maturing a GRC program, not just maintaining one • Prefer experience managing external audits or assessments (SOC 2, HITRUST, OCR, internal audit, etc.) EDUCATION DESCRIPTION: A Bachelors degree is required. Bachelors in Computer Science or similar degree is preferred. SPECIAL SKILLS DESCRIPTION: • In-depth knowledge of cybersecurity frameworks including but not limited to NIST CF, HITRUST CSF, ISO 27001. • Experience in managing or leading security organizations responsible for GRC, Cybersecurity, Medical Device Security, Security Operations Centers. • Understanding of general security concepts including but not limited to cryptography, DLP, Security Operations Center, Security Managed Services, SEM, FW, Audit. • Demonstrated record of managing third party security services, preferably with the cloud providers. • Experience in Healthcare industry is preferred. • Ability to communicate and represent IT Security organization with all business partners and third party vendors. • Strong oral, presentation, writing skills. and demonstrated record to deliver results. • Ability to build relationships with business stakeholders of the IT Security program • Familiarity with HIPAA Privacy and Security Rules and their operational implications for a large health system • Ability to develop and present executive-level risk reporting that communicates risk in business impact terms • Comfort operating in a matrixed environment with multiple stakeholder groups including Legal, HR, IT, Clinical Operations, and executive leadership Certifications • Prefer CISSP, CISM, CRISC, HCISPP, or equivalent certification • Prefer Certified in Healthcare Privacy and Security (CHPS) or equivalent Compensation, Benefits & Perks at Froedtert Health Pay is expected to be between: (expressed as hourly) $49.15 - $84.07. Final compensation is based on experience and will be discussed with you by the recruiter during the interview process. Froedtert Health Offers a variety of perks & benefits to staff, depending on your role you may be eligible for the following: - Paid time off - Growth opportunity- Career Pathways & Career Tuition Assistance, CEU opportunities - Academic Partnership with the Medical College of Wisconsin - Referral bonuses - Retirement plan - 403b - Medical, Dental, Vision, Life Insurance, Short & Long Term Disability, Free Workplace Clinics - Employee Assistance Programs, Adoption Assistance, Healthy Contributions, Care@Work, Moving Assistance, Discounts on gym memberships, travel and other work life benefits available The Froedtert & the Medical College of Wisconsin regional health network is a partnership between Froedtert Health and the Medical College of Wisconsin supporting a shared mission of patient care, innovation, medical research and education. Our health network operates eastern Wisconsin's only academic medical center and adult Level I Trauma center engaged in thousands of clinical trials and studies. The Froedtert & MCW health network, which includes ten hospitals, nearly 2,000 physicians and more than 45 health centers and clinics draw patients from throughout the Midwest and the nation. We are proud to be an Equal Opportunity Employer who values and maintains an environment that attracts, recruits, engages and retains a diverse workforce. We welcome protected veterans to share their priority consideration status with us at 262-439-1961. We maintain a drug-free workplace and perform pre-employment substance abuse testing. During your application and interview process, if you have a need that requires an accommodation, please contact us at 262-439-1961. We will attempt to fulfill all reasonable accommodation requests.

United States + 243 moreAll locations: United States | Afghanistan | Åland Islands | Albania | Algeria | American Samoa | Andorra | Angola | Anguilla | Antarctica | Antigua And Barbuda | Argentina | Armenia | Aruba | Australia | Austria | Azerbaijan | Bahamas | Bahrain | Bangladesh | Barbados | Belarus | Belgium | Belize | Benin | Bermuda | Bhutan | Bolivia | Bosnia And Herzegovina | Botswana | Bouvet Island | Brazil | British Indian Ocean Territory | Brunei | Bulgaria | Burkina Faso | Burundi | Cambodia | Cameroon | Canada | Cabo Verde | Cayman Islands | Central African Republic | Chad | Chile | China | Christmas Island | Cocos (keeling) Islands | Colombia | Comoros | Congo | Democratic Republic of the Congo | Cook Islands | Costa Rica | Côte D'ivoire | Croatia | Cuba | Cyprus | Czechia | Denmark | Djibouti | Dominica | Dominican Republic | Ecuador | Egypt | El Salvador | Equatorial Guinea | Eritrea | Estonia | Ethiopia | Falkland Islands (malvinas) | Faroe Islands | Fiji | Finland | France | French Guiana | French Polynesia | French Southern Territories | Gabon | Gambia | Georgia | Germany | Ghana | Gibraltar | Greece | Greenland | Grenada | Guadeloupe | Guam | Guatemala | Guernsey | Guinea | Guinea-bissau | Guyana | Haiti | Heard Island And Mcdonald Islands | Vatican City | Honduras | Hong Kong | Hungary | Iceland | India | Indonesia | Iran | Iraq | Ireland | Isle Of Man | Israel | Italy | Jamaica | Japan | Jersey | Jordan | Kazakhstan | Kenya | Kiribati | North Korea | South Korea | Kuwait | Kyrgyzstan | Laos | Latvia | Lebanon | Lesotho | Liberia | Libya | Liechtenstein | Lithuania | Luxembourg | Macao | North Macedonia | Madagascar | Malawi | Malaysia | Maldives | Mali | Malta | Marshall Islands | Martinique | Mauritania | Mauritius | Mayotte | Mexico | Micronesia | Moldova | Monaco | Mongolia | Montenegro | Montserrat | Morocco | Mozambique | Myanmar | Namibia | Nauru | Nepal | Netherlands | New Caledonia | New Zealand | Nicaragua | Niger | Nigeria | Niue | Norfolk Island | Northern Mariana Islands | Norway | Oman | Pakistan | Palau | Palestine | Panama | Papua New Guinea | Paraguay | Peru | Philippines | Pitcairn | Poland | Portugal | Puerto Rico | Qatar | Réunion | Romania | Russia | Rwanda | Saint Barthélemy | Saint Helena, Ascension And Tristan Da Cunha | Saint Kitts And Nevis | Saint Lucia | Saint Martin | Saint Pierre And Miquelon | Saint Vincent And The Grenadines | Samoa | San Marino | Sao Tome And Principe | Saudi Arabia | Senegal | Serbia | Seychelles | Sierra Leone | Singapore | Slovakia | Slovenia | Solomon Islands | Somalia | South Africa | South Georgia And The South Sandwich Islands | Spain | Sri Lanka | Sudan | Suriname | Svalbard And Jan Mayen | Eswatini | Sweden | Switzerland | Syria | Taiwan | Tajikistan | Tanzania | Thailand | Togo | Tokelau | Tonga | Trinidad And Tobago | Tunisia | Turkey | Turkmenistan | Turks And Caicos Islands | Tuvalu | Uganda | Ukraine | United Arab Emirates | United Kingdom | United States Minor Outlying Islands | Uruguay | Uzbekistan | Vanuatu | Venezuela | Vietnam | Virgin Islands, British | Virgin Islands, U.s. | Wallis And Futuna | Western Sahara | Yemen | Zambia | Zimbabwe
$49 - $84 / hour
Full TimeRemoteTeam 201-500Since 2012H1B No Sponsor

• Proyecto con modalidad remota • Colaboración con un equipo de profesionales de consultoría tecnológica • Optimización de rentabilidad empresarial a través de tecnologías de la información

Spain