Manage security compliance and assessment for application and infrastructure modernization projects.
This role is remote.
Responsibilities
Provide security compliance oversight for applications and systems within the ATO boundary using MARS-E, NIST, and HIPAA guidelines.
Support the ISSO in maintaining Authorization to Operate (ATO) and system security plans.
Collaborate with Enterprise Architecture, DBA, and development teams to implement automated Disaster Recovery, security event logging, and monitoring processes.
Perform internal assessments of security controls and monitor infrastructure assets using NIST 800-53.
Track remediation efforts from audits through Plans of Action and Milestones (POA&Ms) and Correction Action Plans (CAPs).
Required Skills
5+ years of related IT security work experience.
5 years of experience providing security compliance for applications in cloud environments (AWS, Azure, or Google).
5 years of experience updating or maintaining SSP/SSPP documentation.
5 years of experience participating in the Assessment & Authorization (A&A/ATO) process.
5 years of experience monitoring and testing application/system components utilizing NIST 800-53.
Proficiency with NIST and HIPAA guidelines.
Working knowledge of CMS, USDA, and ACF requirements.
Experience with security control implementation and risk mitigation strategies.
Preferred Skills
Experience reviewing RFPs, MOUs, and MOAs for privacy, security, Business Continuity Planning, and Disaster Recovery requirements.