Cyber Remediation & POA&M Coordinator (R-00188)

1 day, 12 hours ago
Full-time
Mid Level
Cybersecurity
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Coordinate enterprise remediation activities for vulnerabilities identified through continuous monitoring, scanning, penetration testing, audits, and security assessments.
  • Develop, maintain, and manage Plans of Action and Milestones (POA&Ms) in line with Federal, HHS, and NIH requirements.
  • Partner with ISSOs, system owners, security engineers, and technical teams to define remediation plans, milestones, and timelines.
  • Monitor remediation progress, validate supporting evidence, and ensure corrective actions are accurately documented.
  • Coordinate risk acceptance requests, compensating controls, waivers, and remediation exceptions through governance processes.
  • Track remediation performance against service level objectives and escalate overdue or high-priority items to leadership.
  • Support RMF authorization activities by ensuring vulnerabilities and POA&M items are reflected in authorization documentation.
  • Collaborate with vulnerability management and threat intelligence personnel to reprioritize work based on exploitability, Known Exploited Vulnerabilities (KEVs), operational impact, and emerging threats.
  • Develop recurring status reports, executive summaries, and operational metrics for Government leadership.
  • Support cybersecurity assessments by coordinating remediation responses and tracking corrective actions through closure.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, or a related discipline.
  • 3+ years of experience supporting vulnerability management, RMF, cybersecurity governance, or compliance programs.
  • Experience developing and managing Plans of Action and Milestones (POA&Ms).
  • Working knowledge of NIST Risk Management Framework (RMF), FISMA, and NIST SP 800-53.
  • Experience coordinating remediation activities across multiple technical teams and business stakeholders.
  • Strong organizational skills with the ability to manage multiple concurrent remediation efforts.
  • Excellent written and verbal communication skills for technical and executive audiences.
  • Preferred: Experience supporting NIH, HHS, or other Federal civilian agencies.
  • Preferred: Experience with GRC platforms such as JCAM, eMASS, ServiceNow, Archer, or similar tools.
  • Preferred: Experience supporting vulnerability management programs and Continuous Diagnostics and Mitigation (CDM) initiatives.
  • Preferred: Familiarity with CISA KEV guidance, Binding Operational Directives, and Federal remediation requirements.
  • Preferred: Experience supporting audit remediation, authorization package development, and continuous monitoring programs.
  • Preferred certifications include CGRC, CISSP, Security+, CAP, CISM, or PMP.

Benefits

  • Competitive salary, paid twice per month.
  • Best-in-class medical coverage with 100% of medical premiums covered by the company.
  • 3 weeks of PTO starting plus 11 paid holidays annually.
  • 401(k) program with 100% company match on the first 4%.
  • Monthly reimbursement for cell phone and home internet costs.
  • Paternity/maternity leave.
  • Investment in training and certifications.
  • Company-wide new business incentive programs and contribution incentives.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Manager, Governance, Risk & Compliance

Ultimate Medical Academy is hiring a remote Manager, Governance, Risk & Compliance to lead its institution-wide GRC and information security programs in support of a national higher-education environment.

Cybersecurity HIPAA Network Security Penetration Testing
12 hours, 46 minutes ago

Sr. Insider & Data Risk Analyst

Alpaca 51-250 Capital Markets

Alpaca is hiring a Senior Insider & Data Risk Analyst to lead insider risk investigations and strengthen data loss prevention and risk management across its global brokerage infrastructure.

AWS Azure Cybersecurity Elasticsearch GCP Python SIEM Splunk SQL
1 day, 12 hours ago

French Speaking Digital Trust and Safety Analyst - Work In Sofia, Bulgaria

Mercier Consultancy Professional Services

Mercier Consultancy Group is hiring a French Speaking Digital Trust and Safety Analyst in Bulgaria to help moderate content and protect the safety and quality of a major global social media platform.

1 day, 13 hours ago

Transaction Monitoring and Fraud Analyst

Mews 251-1K Consumer Services

Mews is hiring a FinCrime professional to monitor transactions and payment activity, investigate suspicious behavior, and help reduce fraud and financial crime at scale across its growing payments platform.

Python SQL
3 days, 11 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers