Security / RMF Lead

1 month, 3 weeks ago
Full-time
Senior
Cybersecurity
Essnova

Essnova

Essnova is a mature small business providing a broad range of technology and programmatic support services to governmental and commercial customers. Specializing in SETA Services, Geospatial, Environmental, and Medical Services, Essnova offers highly e...

Internet Software & Services
11-50
Founded 2005

Description

  • Maintain System Security Plans (SSPs) as living documents and update them after security-impacting changes.
  • Manage Plan of Action & Milestones (POA&Ms), including quarterly reviews, closure evidence, and remediation tracking.
  • Remediate vulnerabilities within required timelines and provide retesting evidence through closure.
  • Prepare Authorization to Operate (ATO) packages, including SSPs, POA&M status, assessment results, and risk analysis.
  • Conduct annual security assessments of one-third-plus-key-controls using CSAM or equivalent tools.
  • Submit monthly authenticated vulnerability and application scan results by the fifth business day.
  • Coordinate with developers, system owners, security staff, and CDC/NCHS stakeholders on security and compliance activities.
  • Follow CDC change management procedures and perform security impact analysis for post-ATO changes.
  • Support RMF, FISMA compliance, OMB directives, and related governance/stage-gate security artifacts.
  • Lead SSP development during transition-in and support SSP submission within 30 days of contract award.
  • Support PTA/PIA activities with CDC privacy officials.

Requirements

  • Bachelor's degree in cybersecurity, information assurance, computer science, or a related field.
  • 6+ years of federal information security experience applying NIST RMF (NIST SP 800-37).
  • Experience developing and maintaining SSPs, POA&Ms, and ATO packages for FIPS 199 Moderate or higher systems.
  • Experience using vulnerability scan results to track remediation to closure, including retesting evidence, in a federal environment.
  • Hands-on experience with federal security management tools such as CSAM and eMASS.
  • Working knowledge of NIST SP 800-53 Rev. 5 and NIST SP 800-53A.
  • Knowledge of FISMA 2014 reporting and OMB security directives.
  • Knowledge of Privacy Act and E-Government Act privacy provisions, including PTA/PIA processes.
  • Experience coordinating with federal ISSOs/CISOs and security authorization officials.
  • Active Tier 4 / High Risk / Public Trust Level clearance at proposal submission.
  • Eligibility for HSPD-12/PIV.
  • Availability to work during Eastern Time (ET) business hours.
  • CISSP, CISM, or CAP certification, or an equivalent credential, preferred.
  • Experience supporting CDC, HHS, or other federal health agencies, preferred.
  • Experience with CIPSEA-protected data environments or federal statistical agencies, preferred.
  • Experience with FedRAMP continuous monitoring and cloud security assessment, preferred.

Benefits

  • Medical, dental, and vision insurance.
  • 401(k) with company match.
  • Paid time off plus federal holidays.
  • Fast-track growth in a high-accountability culture.
  • High-ownership environment where individual contributions are visible.
  • Direct access to leadership with minimal bureaucracy.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Data Loss Prevention (DLP) Implementation Consultant - Part Time

Muller Internet Software & Services

Data Loss Prevention (DLP) Implementation Consultant at a company deploying enterprise security controls for customer environments, responsible for implementing and operationalizing a DLP solution aligned to security requirements.

Active Directory HIPAA macOS SIEM
17 hours, 1 minute ago

Senior Consultant - ICS/OT Cybersecurity

Dragos 251-1K Professional Services

Dragos is hiring a Senior Consultant for its Professional Services team to lead cybersecurity engagements that help industrial organizations protect critical infrastructure.

Active Directory Cybersecurity SIEM SSH
1 day, 16 hours ago

RMF, Security & ATO Manager

Lever 251-1K Professional Services

Latitude IT Solutions is hiring an RMF, Security & ATO Manager to own compliance and authorization for a complex, multi-tenant VA health IT platform.

DevSecOps HIPAA
3 days, 17 hours ago

Business Information Security Officer - Remote/Defense Industrial Base (DIB) Exp

EVOTEK 51-250 IT Services

EVOTEK is hiring a Business Information Security Officer to help lead and evolve the company’s security strategy across business, technology, and compliance initiatives for client-facing operations.

Cybersecurity
3 days, 17 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers