Security / RMF Lead

3 months ago
Full-time
Senior
Cybersecurity
Essnova

Essnova

Essnova is a mature small business providing a broad range of technology and programmatic support services to governmental and commercial customers. Specializing in SETA Services, Geospatial, Environmental, and Medical Services, Essnova offers highly e...

Internet Software & Services
11-50
Founded 2005

Description

  • Maintain System Security Plans (SSPs) as living documents and update them after security-impacting changes.
  • Manage Plan of Action & Milestones (POA&Ms), including quarterly reviews, closure evidence, and remediation tracking.
  • Remediate vulnerabilities within required timelines and provide retesting evidence through closure.
  • Prepare Authorization to Operate (ATO) packages, including SSPs, POA&M status, assessment results, and risk analysis.
  • Conduct annual security assessments of one-third-plus-key-controls using CSAM or equivalent tools.
  • Submit monthly authenticated vulnerability and application scan results by the fifth business day.
  • Coordinate with developers, system owners, security staff, and CDC/NCHS stakeholders on security and compliance activities.
  • Follow CDC change management procedures and perform security impact analysis for post-ATO changes.
  • Support RMF, FISMA compliance, OMB directives, and related governance/stage-gate security artifacts.
  • Lead SSP development during transition-in and support SSP submission within 30 days of contract award.
  • Support PTA/PIA activities with CDC privacy officials.

Requirements

  • Bachelor's degree in cybersecurity, information assurance, computer science, or a related field.
  • 6+ years of federal information security experience applying NIST RMF (NIST SP 800-37).
  • Experience developing and maintaining SSPs, POA&Ms, and ATO packages for FIPS 199 Moderate or higher systems.
  • Experience using vulnerability scan results to track remediation to closure, including retesting evidence, in a federal environment.
  • Hands-on experience with federal security management tools such as CSAM and eMASS.
  • Working knowledge of NIST SP 800-53 Rev. 5 and NIST SP 800-53A.
  • Knowledge of FISMA 2014 reporting and OMB security directives.
  • Knowledge of Privacy Act and E-Government Act privacy provisions, including PTA/PIA processes.
  • Experience coordinating with federal ISSOs/CISOs and security authorization officials.
  • Active Tier 4 / High Risk / Public Trust Level clearance at proposal submission.
  • Eligibility for HSPD-12/PIV.
  • Availability to work during Eastern Time (ET) business hours.
  • CISSP, CISM, or CAP certification, or an equivalent credential, preferred.
  • Experience supporting CDC, HHS, or other federal health agencies, preferred.
  • Experience with CIPSEA-protected data environments or federal statistical agencies, preferred.
  • Experience with FedRAMP continuous monitoring and cloud security assessment, preferred.

Benefits

  • Medical, dental, and vision insurance.
  • 401(k) with company match.
  • Paid time off plus federal holidays.
  • Fast-track growth in a high-accountability culture.
  • High-ownership environment where individual contributions are visible.
  • Direct access to leadership with minimal bureaucracy.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Technical Consultant - Network Security

AHEAD 1K-5K IT Services

AHEAD is seeking a Principal Technical Consultant to lead complex, client-facing network security engagements spanning firewalls, network access control, application delivery, SASE, and Zero Trust, from architecture through implementation and knowledge transfer.

Ansible AWS Azure CI/CD CloudFormation DNS GCP HIPAA JSON Kubernetes Microservices Network Security OpenAPI SIEM Splunk Terraform XML
18 hours, 33 minutes ago

Senior Consultant - Cyber Resilience

AHEAD 1K-5K IT Services

AHEAD is hiring a Senior Consultant to help enterprise clients improve cyber incident recovery, disaster recovery, resilience programs, and recovery validation from strategy through implementation.

Cybersecurity Network Security
1 day, 18 hours ago

Associate, Compliance Security Penetration Tester

Coalfire 251-1K Internet Software & Services

Coalfire is seeking a penetration testing professional to conduct cybersecurity assessments and simulate sophisticated attacks for clients across network, application, cloud, wireless, and social engineering environments.

C Cybersecurity HIPAA Network Security Penetration Testing PowerShell Python Ruby Shell Scripting
1 day, 18 hours ago

Security Officer

European Dynamics 251-1K IT Services

European Dynamics is seeking a remote Security Officer to support a major client’s IT team by leading information security, risk management, governance, and resilience activities.

Agile Cybersecurity DevSecOps
3 days, 18 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers