Job responsibilities:
- Provide leadership and oversight for maintaining and updating System Security Plans (SSPs), ensuring documentation accuracy, completeness, and alignment with NIST protocol and SOM compliance standards.
- Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and ensuring successful approval and continuous compliance for all supported applications.
- Ensure all applications maintain a valid ATO on a three-year cycle and lead efforts to validate and maintain accurate security controls throughout each renewal period.
- Reviews and informs management on security risk assessment results and recommends corrective actions as necessary.
- Reviews, assesses risks and scope for high level security incidents. Develops new reports for management based on those collected metrics across multiple agencies: conducts trend analysis.
- Work with stakeholders to address and track Plans of Action & Milestones (POA&Ms) and other compliance requirements, ensuring timely reporting and closure.
- Provide senior-level support across multiple business areas, MDCR, MCSC & MiLEAP, with a focus on standardized security plan updates, documentation improvements, and long-term process consistency.
- Analyze existing compliance documentation, identify gaps or risks, and guide corrective actions to meet regulatory and organizational requirements.
- Coordinate cross-functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for
SSP and ATO processes are properly completed and maintained.
- Oversee review, updates, and remediation of security controls, ensuring issues are tracked, ommunicated, and resolved in collaboration with stakeholders.
- Lead efforts to identify procedural gaps, risks, or required updates during renewal cycles,
ensuring consistent application of best practices across all supported systems.
- Contribute to enterprise security governance by providing guidance, maintaining accurate
records, mentoring team members, and driving timely completion of compliance activities.
- Leads mid to high-level Incident Responses when working to resolve incidents.
- Serves as the Incident response specialist for cyber event detection, correlation, response,
and recovery.
Job Qualifications:
- Bachelor's degree in cyber security, Information Assurance, Business Analytics, or IT Related
Field
o OR: 5 years of experience
- Preferred Advanced Degrees, Master's in Cybersecurity, Information Assurance, Information
Systems / IT Leadership, or an MBA with an IT or Security Concentration
- Educational or professional knowledge of NIST Framework and Controls a must
- Strong aptitude for written and oral communication
- Strong documentation skills
- Can collaborate cross-functionally
Skil