
Security, RMF Lead
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Ensure that System Security Plans (SSPs) are maintained as dynamic documents for all NCHS systems, with timely updates following any security-impacting changes.
• Oversee the management of Plan of Action & Milestones (POA&Ms) with quarterly reviews of progress, evidence of closure, and tracking of remediation efforts.
• Address vulnerabilities within required timelines, monitor findings until closure, and provide evidence of retesting.
• Prepare Authorization to Operate (ATO) packages, which include SSPs, POA&M status, assessment outcomes, and risk analysis for review by the Authorizing Official.
• Execute annual security assessments of over one-third of key controls utilizing CSAM or similar tools.
• Deliver monthly validated vulnerability and application scan results by the fifth business day.
• Facilitate coordination among developers, system owners, and security personnel, while liaising with CDC CSPO, NCHS SSPO, and CDC Enterprise Architects.
• Adhere to the CDC CSPO Change Management SOP, ensuring security impact analysis for changes made post-ATO.
• Assist in the implementation of the Risk Management Framework (RMF), ensuring compliance with FISMA and OMB directives.
• Generate security-related EPLC artifacts for governance and stage-gate reviews.
• Lead the development of SSPs during the 30-day transition-in activation period and support the submission of SSPs within 30 days of contract award.
• Assist with PTA/PIA activities in collaboration with CDC privacy officials.
• A bachelor's degree in cybersecurity, information assurance, computer science, or a related discipline.
• Over 6 years of federal information security experience utilizing NIST RMF (NIST SP 800-37).
• Proven experience in developing and maintaining SSPs, POA&Ms, and ATO packages for systems rated FIPS 199 Moderate or higher.
• Proficient in using vulnerability scanning results to ensure remediation is completed and documented (including retesting evidence) within a federal context.
• Practical experience with federal security management tools such as CSAM and eMASS.
• Familiarity with NIST SP 800-53 Rev. 5 and NIST SP 800-53A.
• Understanding of FISMA 2014 reporting and OMB security directives.
• Knowledge of the Privacy Act and E-Government Act's privacy provisions, including PTA/PIA processes.
• Experience in coordinating with federal ISSOs/CISOs and security authorization officials.
• Possession of an active Tier 4 / High Risk / Public Trust Level 6+ clearance at the time of proposal submission.
• Eligibility for HSPD-12/PIV.
• Ability to work during Eastern Time (ET) business hours.
• Comprehensive medical, dental, and vision insurance.
• 401(k) plan with company matching contributions.
• Paid time off along with federal holidays.
• Opportunities for rapid advancement within a culture of high accountability.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.