
Information Systems Security Manager
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United States.
• Oversee and manage all aspects of FedRAMP authorization processes, including planning, execution, resource allocation, and coordination with stakeholders.
• Take charge of the development, upkeep, and quality assurance of FedRAMP security documentation such as the SSP, SAP, SAR, POA&M, and Continuous Monitoring artifacts.
• Supervise monthly management of POA&M, prioritize vulnerabilities, track remediation efforts, and coordinate risk acceptance.
• Lead independent assessments of security controls, manage vulnerabilities, conduct penetration testing, and test contingency plans as required.
• Direct the Continuous Monitoring activities for FedRAMP and ensure timely submission of monthly, quarterly, and annual deliverables.
• Act as the main contact for sponsoring agencies, 3PAOs, and internal stakeholders concerning FedRAMP issues.
• Investigate and respond to government security bulletins, vulnerability advisories, and federal data requests.
• Keep precise inventories of systems, software, and hardware for government-authorized environments.
• Provide strategic direction on secure cloud architecture and compliance-driven designs within AWS, Azure, and/or GCP environments.
• Assess the impact of system changes on FedRAMP compliance and ensure adherence to change management, configuration management, and incident response protocols.
• Interpret and adapt to changing FedRAMP, NIST, and agency-specific requirements, translating them into actionable directives.
• Train and inform internal teams on FedRAMP responsibilities, audit expectations, and security best practices.
• Implement process enhancements to improve compliance efficiency, mitigate risks, and bolster audit preparedness.
• Create and present status reports and metrics to leadership regarding authorization posture, risk exposure, and compliance health.
• Complete assigned performance objectives, special projects, and additional responsibilities.
• A minimum of 8 years of experience in information security, risk management, or compliance.
• Experience in engaging with senior leadership, auditors, and regulatory bodies.
• Proven experience in leading or managing FISMA Moderate or High authorizations and maintaining ongoing ATOs.
• Comprehensive understanding of FedRAMP, NIST SP 800-53, and the NIST Risk Management Framework.
• Experience in managing SSPs, POA&Ms, vulnerability remediation, audits, and Continuous Monitoring programs.
• Practical experience with AWS, Azure, and/or GCP and SaaS environments.
• Demonstrated ability to lead cross-functional initiatives involving both technical and non-technical teams.
• Exceptional written and verbal communication skills.
• Strong organizational skills and the ability to prioritize tasks in a highly regulated setting.
• Security or compliance certifications such as CISSP, CISM, Security+, AWS Security, or Azure Security certifications.
• Capability to provide high-speed internet access/connectivity as well as office setup and maintenance.
• Ability to maintain a dedicated, secure workspace.
• Capacity to perform responsibilities with or without reasonable accommodations.
• Eligibility for discretionary bonuses.
• Coverage under medical insurance.
• Coverage under dental insurance.
• Coverage under vision insurance.
• Coverage under disability insurance.
• Coverage under life insurance.
• Participation in a 401(k) savings plan.
• Provision for paid family leave.
• Nine paid holidays each year.
• 17-27 days of Paid Time Off (PTO) annually, based on specific level and length of service.
• Options for remote work arrangements.
• Requirement to provide high-speed internet access/connectivity and office setup and maintenance.
• Requirement to maintain a dedicated, secure work area.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.