Remotery

Security, RMF Lead

Posted Jul 17

This is a fully remote position, open to applicants in United States.

📋 Description

• Ensure that System Security Plans (SSPs) are maintained as dynamic documents for all NCHS systems, with timely updates following any security-impacting changes.

• Oversee the management of Plan of Action & Milestones (POA&Ms) with quarterly reviews of progress, evidence of closure, and tracking of remediation efforts.

• Address vulnerabilities within required timelines, monitor findings until closure, and provide evidence of retesting.

• Prepare Authorization to Operate (ATO) packages, which include SSPs, POA&M status, assessment outcomes, and risk analysis for review by the Authorizing Official.

• Execute annual security assessments of over one-third of key controls utilizing CSAM or similar tools.

• Deliver monthly validated vulnerability and application scan results by the fifth business day.

• Facilitate coordination among developers, system owners, and security personnel, while liaising with CDC CSPO, NCHS SSPO, and CDC Enterprise Architects.

• Adhere to the CDC CSPO Change Management SOP, ensuring security impact analysis for changes made post-ATO.

• Assist in the implementation of the Risk Management Framework (RMF), ensuring compliance with FISMA and OMB directives.

• Generate security-related EPLC artifacts for governance and stage-gate reviews.

• Lead the development of SSPs during the 30-day transition-in activation period and support the submission of SSPs within 30 days of contract award.

• Assist with PTA/PIA activities in collaboration with CDC privacy officials.


⛳️ Requirements

• A bachelor's degree in cybersecurity, information assurance, computer science, or a related discipline.

• Over 6 years of federal information security experience utilizing NIST RMF (NIST SP 800-37).

• Proven experience in developing and maintaining SSPs, POA&Ms, and ATO packages for systems rated FIPS 199 Moderate or higher.

• Proficient in using vulnerability scanning results to ensure remediation is completed and documented (including retesting evidence) within a federal context.

• Practical experience with federal security management tools such as CSAM and eMASS.

• Familiarity with NIST SP 800-53 Rev. 5 and NIST SP 800-53A.

• Understanding of FISMA 2014 reporting and OMB security directives.

• Knowledge of the Privacy Act and E-Government Act's privacy provisions, including PTA/PIA processes.

• Experience in coordinating with federal ISSOs/CISOs and security authorization officials.

• Possession of an active Tier 4 / High Risk / Public Trust Level 6+ clearance at the time of proposal submission.

• Eligibility for HSPD-12/PIV.

• Ability to work during Eastern Time (ET) business hours.


🏝️ Benefits

• Comprehensive medical, dental, and vision insurance.

• 401(k) plan with company matching contributions.

• Paid time off along with federal holidays.

• Opportunities for rapid advancement within a culture of high accountability.

People also viewed

LimeJul 26

Senior Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security Engineer$120k/year
ApplyView job
ThreatscapeJul 26

Associate Consultant – Microsoft Security, Purview, Data Security and Governance, AI

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
GFT TechnologiesJul 26

Senior IT Security Project Manager

CR flagCosta Rica OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
BeyondTrustJul 26

VP, Product Management, AI Security – Strategy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
QuisitiveJul 26

Digital Security Coach

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GEICOJul 25

Senior Field Security Investigator

US flagFlorida OnlyFull-timeCybersecurity / Security Engineer$3,200 – $5,000/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers