Leidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.
Risk Assurance SME
Location
United States
Posted
2 days ago
Salary
$87.1K - $157.5K / year
Seniority
Senior
Job Description
Risk Assurance SME
Leidos
• Engage with engineering stakeholders to explain DHA risk assessment processes and ensure high-quality risk assessment packages for review and approval for submission to the DHMSM ISSOs and DHA RMED for review and approval • Coordinate and review risk assessment artifacts (POAMs, STIG/SRG Checklists, False Finding artifacts), providing feedback to engineering teams • Track and support risk assessments in collaboration with the Cyber Assurance Lead • Lead internal and external project meetings, providing updates on progress and milestones • Support the development and maintenance of the Integrated Master Schedule (IMS) for projects, where applicable • Leverage established intake processes for new risk assessments, ensuring proper coordination with engineering teams and the DHMSM Cyber team • Coordinate and oversee risk assessment activities involving third-party resources to ensure alignment with program objectives • Implement tools and solutions to automate and visualize metrics, reporting, and dashboards • Facilitate daily meetings with stakeholders as needed, using a scrum approach for escalated risk assessments • Assess and report on identified and anticipated project risks
Job Requirements
- US Citizen with current U.S. Government Secret clearance (contract requirement)
- Bachelor’s degree and 4–8 years of relevant experience
- DoD 8570 IAM Level 1 or IAT Level 2 certification, or ability to obtain within 6 months of hire
- Excellent written and verbal communication skills
- Strong critical thinking and analytical skills
- Ability to organize and prioritize multiple requests in a fast-paced, deadline-driven environment
- Proficiency in Microsoft Office tools and project management tools such as JIRA
- Experience identifying applicable STIG checklists based on assessed technologies, conducting STIG compliance reviews, and analyzing Check Text and Fix Text to validate security control implementation and remediation requirements
- Ability to review POA&M data for accuracy and appropriateness, ensuring findings, remediation details, and statuses are correctly documented
Benefits
- competitive compensation
- Health and Wellness programs
- Income Protection
- Paid Leave
- Retirement
Related Guides
Related Categories
Related Job Pages
More Risk Jobs
• Provides second line oversight for designated front line business areas. • Supports stakeholder development initiatives in Archer GRC platform. • Develops strong partnerships with second- and third-line business units and stakeholders. • Serves as Archer GRC system subject matter expert to consult and provide advice for module customization activities. • Assists outside business unit partners in creating and maintaining the change management process in Archer GRC. • Provides oversight to user acceptance testing for proposed changes in system lower environments. • Coordinates deployment release schedule with IT resources and project stakeholders. • Performs User Access Reviews to determine group and role appropriateness for Archer system users across the enterprise. • Enhances and automates reporting functions of second line business partners. • Supports creation of Archer Governance Committee materials as well as monitoring and presentation of system development progress. • Facilitates documentation and approval of Committee meeting minutes with executive stakeholders. • Collaborates with other Risk Management employees on continuous improvement of risk management programs, activities and oversight in the company. • Supports assigned operational functions of the Risk Management Division, which may include: Execution and planning of Risk Operations Program Roadmap initiatives as assigned Execution and planning of Archer Development Roadmap initiatives as assigned Developing and maintaining departmental procedures and program-related reporting as assigned Performing administration and project management duties as needed. May develop, facilitate and/or support training for business lines on the Archer end user experience, operational risk topics, current industry practices, and/or risk and control standards.
Director, Strategy – Risk Adjustment
Highmark HealthCreating remarkable health experiences, freeing people to be their best.
• Lead strategic planning cycles, facilitate goal-setting, and manage cross-functional processes within RAAM • Oversee the coordination of all RAAM team activities, including meeting content development, communications, team-building initiatives • Support and manage key cross-functional projects critical to RAAM's objectives, such as business case development, process reviews, regulatory support • Provide strategic oversight and drive execution for significant RAAM programs, such as support for Clinical Programs that support Risk Adjustment accuracy • Manage the RAAM budget, including purchase approvals and budget development
Principal Professional – Governance and Risk
IntelanceEnterprise Architecture. Cybersecurity. AI Operating Models. We build strategic systems for the future of business.
• Lead independent cyber governance and risk reviews for large, complex and regulated organisations. • Assess risk appetite, risk ownership, control effectiveness and risk-treatment decisions. • Review policies, risk registers, control mappings, assurance evidence and governance arrangements. • Judge whether evidence supports the conclusions presented to senior leaders. • Explain cyber risks and control gaps clearly to boards, executives and non-technical stakeholders. • Lead interviews and workshops with CISOs, risk owners and control owners. • Produce clear, defensible, client-ready governance and risk reports. • Complete scheme-specific training and participate in internal quality reviews where required.
Senior Identity and Access Governance, IGA Consultant – Contract
IntelanceEnterprise Architecture. Cybersecurity. AI Operating Models. We build strategic systems for the future of business.
• Review how access is currently granted across core business systems, including users, roles, groups, privileged accounts and service accounts. • Identify where access is broader than required and document the associated risks. • Carry out role mining and design role based access models, access matrices and least privilege structures. • Support access certification and recertification exercises so managers can make informed decisions. • Complete segregation of duties analysis and document conflicts and mitigating controls. • Define joiner, mover and leaver controls, and access request, approval and review processes. • Support the review of how AI tools and connectors access internal information, alongside the Cyber, Identity and Access Lead. • Prepare clear findings, role descriptions and evidence suitable for internal stakeholders and external audit. • Maintain the implementation backlog and support testing and evidence review as client system owners make changes.



