Security Lead

Posted Aug 12

This is a fully remote position, open to applicants in Arizona, +24 more states.

📋 Description

• Establish and manage the cybersecurity, privacy, and compliance framework for a CMS case management initiative.

• Act as the primary security consultant to program leadership.

• Collaborate closely with the Program Manager, Solutions Architect, Cloud Architect, DevSecOps team, and governmental security stakeholders.

• Direct the cybersecurity strategy for the program and ensure adherence to CMS ARS, FISMA, HIPAA/HITECH, NIST 800-53, and FedRAMP guidelines.

• Create and sustain security plans, policies, and procedures that align with federal standards.

• Assist with Authority to Operate (ATO) processes and liaise with government security officials and compliance auditors.

• Oversee POA&M activities and maintain the program's risk register.

• Evaluate and approve AWS cloud architecture designs and secure cloud-native implementations.

• Enforce IAM policies, multi-factor authentication (MFA), encryption, network segmentation, and Zero Trust principles.

• Integrate security controls into CI/CD pipelines and verify cloud configurations against security baselines.

• Implement automated scanning for source code, containers, Kubernetes workloads, Infrastructure as Code (IaC), and open-source dependencies.

• Conduct security risk assessments and threat modeling; identify vulnerabilities and formulate mitigation strategies.

• Assess third-party and integration partner security risks.

• Define data classification, handling, retention, and destruction protocols for Personally Identifiable Information (PII) and Protected Health Information (PHI).

• Review interoperability and data-sharing solutions to ensure HIPAA privacy compliance.

• Develop and maintain incident response protocols and support SIEM-based monitoring and alerting strategies.

• Coordinate response efforts for security incidents and vulnerabilities.

• Participate in Architecture Review Boards and evaluate application, integration, data, and infrastructure designs for security deficiencies.

• Ensure secure API and interoperability implementations across integrated systems.


⛳️ Requirements

• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related discipline.

• Over 10 years of experience in cybersecurity, with at least 2 years supporting federal health programs.

• More than 5 years of experience securing cloud-based solutions, especially AWS.

• Experience in supporting healthcare or CMS-related systems.

• Familiarity with ATO processes and federal compliance frameworks.

• Proven experience leading security teams in Agile and DevSecOps settings.

• CISSP certification is preferred.


🏝️ Benefits

• Remote work arrangement.

• Reasonable accommodations for individuals with disabilities.

• Equal employment opportunities without discrimination.

People also viewed

Campbell's20 hours ago

Workday Platform Owner – Integration, Reporting, Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$127.9k – $175.9k/year
ApplyView job
VALCE Talent Solutions20 hours ago

SAP Basis, Security Experience

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
The Hello Team21 hours ago

Senior Cybersecurity & Compliance Consultant, HIPAA, NIST, SOC 2

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Anduril Industries22 hours ago

Senior Security Engineer

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$1/year
ApplyView job
Anduril Industries22 hours ago

Senior Security Engineer – OT

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$1/year
ApplyView job
Optiv23 hours ago

Senior Cybersecurity Advisor – AI

US flagKansas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers