Federal contracting company specializing in technical, geospatial, healthcare, and administrative solutions.
Security, RMF Lead
Location
United States
Posted
66 days ago
Salary
0
Seniority
Senior
Job Description
Security, RMF Lead
Essnova Solutions, Inc.
• Maintain System Security Plans (SSPs) as living documents for all NCHS systems, ensuring timely updates after security-impacting changes. • Manage Plan of Action & Milestones (POA&Ms) with quarterly progress reviews, closure evidence, and remediation tracking. • Remediate vulnerabilities within mandated timelines, track findings through closure, and provide retesting evidence. • Prepare Authorization to Operate (ATO) packages—including SSPs, POA&M status, assessment results, and risk analysis—for Authorizing Official review. • Conduct annual security assessments of one-third-plus-key-controls using CSAM or equivalent tools. • Submit monthly authenticated vulnerability and application scan results by the fifth business day. • Coordinate among developers, system owners, and security staff, and liaise with CDC CSPO, NCHS SSPO, and CDC Enterprise Architects. • Follow CDC CSPO Change Management SOP, including security impact analysis for post-ATO changes. • Support implementation of the Risk Management Framework (RMF), FISMA compliance, and OMB directives. • Produce security-related EPLC artifacts for governance and stage-gate reviews. • Lead SSP development during the 30-day transition-in activation sequence and support SSP submission within 30 days of contract award. • Support PTA/PIA activities with CDC privacy officials.
Job Requirements
- Bachelor's degree in cybersecurity, information assurance, computer science, or a related field
- 6+ years of federal information security experience applying NIST RMF (NIST SP 800-37)
- Experience developing and maintaining SSPs, POA&Ms, and ATO packages for FIPS 199 Moderate or higher systems
- Experience using vulnerability scanning results to track remediation to closure (including retesting evidence) in a federal environment
- Hands-on experience with federal security management tools (CSAM and eMASS)
- Working knowledge of NIST SP 800-53 Rev. 5 and NIST SP 800-53A
- Knowledge of FISMA 2014 reporting and OMB security directives
- Knowledge of Privacy Act and E-Government Act privacy provisions, including PTA/PIA processes
- Experience coordinating with federal ISSOs/CISOs and security authorization officials
- Active Tier 4 / High Risk / Public Trust Level 6+ clearance at proposal submission
- Eligibility for HSPD-12/PIV
- Availability to work during Eastern Time (ET) business hours
Benefits
- Medical, dental, and vision insurance
- 401(k) with company match
- Paid time off + federal holidays
- Fast-track growth in a high-accountability culture
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Head of IT Security
NOVENTI Health SE / Berg-am-LaimNOVENTI ist der führende Anbieter von Abrechnung, Software, Finanzdienstleistungen und digitalen Plattformen im europäischen Gesundheitsmarkt. Gegründet vor 125 Jahren umfasst das Unternehmen mit Hauptsitz in München heute über 1.600 Mitarbeitende.
Role Description Sie möchten IT-Security nicht nur verwalten, sondern aktiv weiterentwickeln und strategisch mitgestalten? In dieser Rolle übernehmen Sie Verantwortung für den Ausbau der IT-Sicherheit, führen ein spezialisiertes Team und arbeiten eng mit internen Stakeholdern sowie externen Partnern zusammen. - Die fachliche und disziplinarische Führung eines IT-Security-Teams mit aktuell fünf Mitarbeitenden liegt in Ihrem Verantwortungsbereich. - Gemeinsam mit dem Head of IT-Services und in Abstimmung mit dem CISO entwickeln Sie die unternehmensweite IT-Security-Strategie weiter und sorgen für deren nachhaltige Umsetzung. - Definition, Pflege und kontinuierliche Optimierung von Sicherheitsrichtlinien, Standards und Prozessen. - Verantwortung für das IT-Security-Budget inklusive Investitionsplanung für Tools, Lizenzen und externe Dienstleister. - Interne Fachbereiche beraten in allen Fragestellungen rund um Informations- und Cybersicherheit und fördern eine unternehmensweite Sicherheitskultur. - Identifikation und Bewertung neuer Bedrohungslagen sowie Ableitung geeigneter Gegenmaßnahmen. - Verantwortung für die Sicherheitsarchitektur in den Bereichen Netzwerk, Endpoint, Cloud sowie Identity & Access Management. - Steuerung des externen Security Operations Centers (SOC) sowie externer Dienstleister, Vendoren und Beratungspartner im Security-Umfeld. - Unterstützung des Incident-Response-Prozesses inklusive Krisenkommunikation bei sicherheitsrelevanten Vorfällen. - Verantwortung für Vulnerability Management, Penetrationstests sowie Red- und Blue-Team-Aktivitäten. - Begleitung interner und externer Audits sowie Zertifizierungen und strukturierte Vor- und Nachbereitung. - Enge Zusammenarbeit mit IT-Infrastruktur, IT-Governance, IT-Entwicklung sowie weiteren Fachbereichen. Qualifications - Mehrjährige Berufserfahrung im IT-Security-Umfeld – idealerweise mindestens drei bis fünf Jahre. - Abgeschlossenes Studium im Bereich Informatik, IT-Security oder einer vergleichbaren Fachrichtung oder entsprechende praktische Erfahrung. - Erste Führungserfahrung, beispielsweise in der Leitung eines kleineren Teams. - Weiterbildungen oder Zertifizierungen im Security-Umfeld sind wünschenswert. - Erfahrung in regulierten Branchen wie Factoring oder Financial Services. - Vertrautheit mit regulatorischen Anforderungen und Standards wie DORA, NIS2 oder CRA. - Erfahrung in der Zusammenarbeit mit externen Partnern, Dienstleistern und Vendoren. - Strategisches Denken und Motivation, IT-Security-Strukturen aktiv weiterzuentwickeln. - Kommunikationsstärke, Durchsetzungsvermögen sowie souveränes Auftreten auf unterschiedlichen Ebenen. - Strukturierte Arbeitsweise, Verantwortungsbewusstsein und ausgeprägte Teamfähigkeit. - Reisebereitschaft innerhalb Deutschlands. Benefits - Altersversorgung. - Speziell auf unsere Branche zugeschnittene Konzepte und attraktive Zuschüsse. - Belonio Gutscheine. - Monatliches Guthaben von bis zu 50€ für namhafte Gutscheinpartner. - Individuell planbarer Brauchtumstag als zusätzlichen freien Tag. - NOVENTI bezuschusst das Deutschlandticket mit 25€. - Vergünstigte Mitgliedschaft für Bewegung, Ausgleich und Gesundheit (EGYM WELLPASS). - Fahrradleasing eines hochwertigen (E-)Bikes mit Steuervorteil. - Profitiere von attraktiven Mitarbeiter-Rabattprogrammen. - Frei an Heiligabend und Silvester (HASI-Tag). - 15 Tage pro Jahr mobiles Arbeiten im europäischen Ausland (Workcation). Company Description NOVENTI ist der führende Anbieter von Abrechnung, Software, Finanzdienstleistungen und digitalen Plattformen im europäischen Gesundheitsmarkt. Gegründet vor 125 Jahren umfasst das Unternehmen mit Hauptsitz in München heute über 1.600 Mitarbeitende.
Security Engineer I
UiPathCommitted to shaping a world where AI enhances human potential & #agentic automation transforms how businesses operate.
• Triage and investigate incidents across SIEM, EDR, network, identity, and cloud telemetry; support containment, eradication, and incident communications under senior guidance. • Contribute to root cause analysis and close the loop with Threat Intelligence and Detection Engineering to produce durable detections, controls, or playbook updates. • Participate in proactive threat hunting across enterprise and cloud telemetry under the direction of senior analysts. • Help maintain IR playbooks and runbooks and participate in drills and tabletop exercises. • Recommend and help tune the detection and response tooling stack (SIEM, EDR, SOAR, case management) in both environments • Actively seek mentorship from senior IR engineers and grow toward independent ownership of incidents over time. • Follow strict procedures and requirements for but not limited to the authorized IR Plan, NIST 800-53 IR controls, CISA notifications, chain of custody, data classification handling, and event classification and reporting requirements.
Head of Security & Risk
decircleTalent Partner for decentralized organizations and projects that are building Web3.
• Build M0’s enterprise risk program from scratch covering security, operational, regulatory, and counterparty risk, including the risk register, annual assessments, scenario analyses, and escalation framework across all entities. • Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks — driving all non-technical workstreams (policy writing, auditor coordination, vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization audit-ready at all times. • Design and maintain M0's incident response framework, ISMS documentation, and security policies — own external security vendor relationships, facilitate tabletop exercises covering IR, BCP, and DR scenarios, and drive the selection of a security advisory firm for on-call support. • Serve as M0's primary point of contact for institutional partner security due diligence and inbound security questionnaires, build and maintain the reusable documentation package for responding to partner requests, and coordinate with Senior Counsel on information security representations in commercial agreements. • Design and own M0's security awareness training program, ensure all employees understand their security obligations, and build a proactive security culture across engineering, operations, legal, and business teams.
Title: Cybersecurity Safeguards Governance Specialist Location: Sydney Australia Job Description: About this role As a key Line 2 cybersecurity governance expert, you'll shape and maintain the standards and frameworks that define "what good looks like" across our technology environment, with specialist focus on data and AI security, identity and cloud security. You'll guide capability maturity, influence cybersecurity strategy, monitor emerging tech risks, and ensure our governance frameworks are practical, current and adopted across the group. You'll work closely with peers across the risk and governance landscape, providing authoritative guidance to Line 1 teams and escalating key issues where needed. Sitting within nib's second line of defence, you'll define the rules - acting as a trusted adviser to ensure our security requirements align with industry best practice and regulatory expectations. Key areas of contribution include: - Maintain clear, practical and up to date cybersecurity standards, frameworks & guidance, including linkages into the ISMS. - Provide expert governance advice on data and AI security risks across platforms and programs. - Monitor and communicate emerging technology risks to guide capability maturity uplift and strategic planning. - Help define meaningful cybersecurity and tech risk metrics that show control alignment and standards adherence. - Document and escalate framework gaps, standards positions and risk findings through governance channels. - Work with Line 1 teams and security partners to build strong safeguards, uplift maturity and embed positive risk culture. About you You bring a genuine love of technology and a curiosity that drives you to dig beneath the surface - understanding not just what the risks are, but how and why things work the way they do. That intellectual curiosity underpins your strong understanding of current and emerging technologies and the cybersecurity risks that come with them, along with hands on experience assessing risk and recommending fit- for-purpose security technologies and services. Your background includes working closely with stakeholders to develop, define and mature security frameworks and standards, helping to drive a culture of security and IT risk awareness across large and distributed organisations. You also understand that the best way to protect a system is to first understand how it can be broken - and that attacker's mindset informs the rigour you bring to every standard, framework and safeguard you develop. You have deep knowledge of cloud, identity, data and AI security governance and associated best practice standards, complemented by a solid grasp of core security concepts such as vulnerability scanning, intrusion detection, incident response, access control, MFA, device mobility, data protection, and network and application security. Your pragmatic, risk-based approach - informed by a habit of thinking critically about how controls actually function in practice - ensures security safeguards are both effective and adaptable in fast-changing technology environments. You also bring working knowledge of PCI DSS requirements, along with a strong understanding of leading information security standards and frameworks such as ISO 27001, ISO42001, ETSI EN 304 223, NIST CSF, the ASD Essential 8 and the SANS Critical Security Controls - enabling you to align governance guidance with recognised best practice. Furthermore, we're seeking: - Have / are working towards information security industry certification(s). Beneficial qualifications and professional certifications may include: - ISC2 certifications - CRISC - SANS / GIAC / OCSP certifications - Experience working with stakeholders to maintain or implement new risk processes in a collaborative enterprise setting - A working understanding and familiarity with current cyber security controls and concepts - A working understanding of data and AI risk and relevant, commensurate safeguards to manage AI risks - A working understanding of contemporary cloud technologies, including the shared responsibility model (desired) We know some people only apply when they meet every requirement. We're always on the lookout for curious, tech-passionate individuals who will add to the culture - so if this role resonates with you and you have relevant experience, we'd love to hear from you! Who we are nib is a leader in private health insurance, disability support and health services, reshaping the industry through bold innovation, strategic disruption and trusted partnerships. We deliver great value health insurance and support services to protect, connect and empower you to access healthcare when and where you need. We have a mission and vision of people enjoying better health. Through our success, we aspire to more prosperous and sustainable communities, helping members and travellers make more informed healthcare decisions and generally live healthier lives. Diversity, equity and inclusion We embrace a flexible working environment and welcome candidates who reflect the diversity of the communities in which we operate. We're committed to an environment where everyone has the autonomy and freedom to be their authentic selves, every day. We encourage Aboriginal and Torres Strait Islander peoples, people living with disability, veterans, LGBTQIA+ as well as culturally diverse community members to apply for open roles. nib Group is committed to creating an accessible recruitment process and employment experience. If you identify as a person living with disability and require adjustments to our online application, recruitment, selection and/or assessment process, or would like this advertisement in an alternative format, please contact us at nibemployment @nib.com.au. Working at nib Our hybrid working model offers flexibility to work from home or our purpose - built office Hubs, designed for focus, connection, and collaboration. We're committed to coming together with purpose. Other benefits to support you at work (and play) include: - New starter benefit to help set up a functional home workspace - 50% discount on employee health insurance + 35% off travel insurance - The opportunity to give back to the community through paid leave for volunteering through nib foundation - Access to our nib Well Program and corporate fitness discounts - Access to employee share plans, short - term incentive program and life and salary continuance insurance benefits - 18 weeks paid parental leave for all new parents regardless of carer status, 5 days paid cultural leave for First Nations peoples and 4 weeks paid gender affirmation leave for trans, gender diverse and intersex employees The fine print All your information will be kept confidential according to EEO guidelines. Successful applicants will be required to complete a background check (including criminal history and bankruptcy check) prior to commencement of employment. We acknowledge Aboriginal and Torres Strait Islander peoples as the Traditional Custodians of the lands where we live, learn and work.


