Job Description
Job Description
Description :
CMS is seeking an Information System Security Officer who will ensure the security and compliance of high visibility federal systems. You will work closely with technical teams to apply cybersecurity best practices, support system authorizations, and maintain a strong security posture that enables mission success. The position is hybrid, currently one day onsite in Ashburn, VA.
Key Responsibilities
- Prepare, maintain, and implement system security plans for high visibility production systems
- Ensure implementation of security measures by working with the system’s development and operational teams, conducting interviews, and table-top exercises
- Perform various Information Assurance support functions in support of client applications
- Advise on processes that align to the Risk Management Framework
- Develop and implement security controls based on FISMA and NIST 800 53 guidelines
- Develop and implement Authority to Operate packages and provide ongoing support
- Coordinate with IT leads from partner agencies and components to identify opportunities to collaborate in developing or leveraging security capabilities
- Conduct IT audits and ensure secure information systems and network connections
- Provide security guidance and interpretation of security policy for project development teams
- Support continuous monitoring including vulnerability assessments, compliance reporting, and tracking vulnerability management and mitigation.
- Partner with system owners to ensure configuration management and change control are executed in alignment with security requirements
- Review security artifacts and documentation and maintain audit ready evidence throughout the system lifecycle
Requirements :
You must live within the DC, MD, VA area.
U.S. Citizenship is required. Candidate must be able to obtain CBP Public Trust clearance.
Minimum of 7 years experience securing government IT systemsStrong working knowledge of the RMFExperience providing security guidance to systems deployed in AWS environmentsDemonstrated understanding of technical components in an information system environmentUnderstanding of cloud infrastructure, networking, containerization, and AWS related technologiesUnderstanding of Zero Trust architectureAbility to work in a collaborative environment and independently manage individual tasksOutstanding verbal and written communication skillsExperience with system categorization and control selection in accordance with FIPS 199 and NIST 800 60Hands on experience with vulnerability scanning tools such as Nessus or similarExperience supporting Continuous ATO or ongoing authorization modelsFamiliarity with FedRAMP and cloud security inheritance modelsPreferred Skills and Experience :
Experience working on Interconnection Security Agreements, PKI, security plans and auditsOne or more security certifications such as Security+, CISSP, GIAC, or CISMExperience in an Agile development environment using Jira or similar toolsKnowledge of DevSecOps pipelines and security integrations in CI and CDExperience with Zero Trust maturity model compliance activitiesAbility to understand AI concepts and apply them to enhance security oversight and role effectiveness