Назад
Company hidden
4 дня назад

Information Security Officer (Cybersecurity)

112 800 - 160 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Officer (Cybersecurity): Supporting FISMA and NIST-based security compliance, risk management, vulnerability management, audits, and continuous monitoring for a CMS program with an accent on ATO documentation, security control implementation, and federal security requirements. Focus on leading Security Impact Analyses, coordinating remediation and POA&M activities, preparing audit-ready evidence, and communicating security risks to government stakeholders.

Location: Fully remote within the United States, operating in the Eastern Time zone; expected hours are 9:00 AM to 5:00 PM Eastern. Occasional travel for training and project meetings is expected at less than 5% per year.

Salary: $112,800–$160,000 per year

Company

hirify.global is a digital services company delivering technology, design, and strategy solutions for US government agencies.

What you will do

  • Advise CMS ISSOs, product owners, engineers, infrastructure teams, assessors, auditors, and program leadership on federal security requirements.
  • Interpret FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS ARS requirements and translate them into technical and operational actions.
  • Develop and maintain security control implementation statements, supporting evidence, System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, and related ATO artifacts.
  • Lead Security Impact Analyses for application, infrastructure, cloud, data, and configuration changes.
  • Support assessments and audits by coordinating evidence, responding to assessor inquiries, identifying gaps, and tracking corrective actions.
  • Manage vulnerability and compliance findings through validation, remediation, risk acceptance, retesting, and closure while producing metrics and risk reports.

Requirements

  • 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles.
  • Bachelor's degree in computer science, information systems, engineering, business, or a related technical discipline.
  • Experience supporting federal systems subject to FISMA and the NIST Risk Management Framework.
  • Experience applying NIST SP 800-53 controls and CMS ARS or comparable federal security requirements.
  • Experience with ATO activities, audit-ready security documentation, vulnerability management, risk exceptions, and compliance findings.
  • Ability to obtain and maintain a Public Trust clearance and have resided in the United States for at least 3 of the last 5 years.

Nice to have

  • Experience supporting CMS systems, CMS security programs, or CMS ATO activities.
  • Experience with CMS ARS 5.0+, AWS cloud security, DevSecOps, CI/CD security reviews, and security scanning.
  • Experience using Tenable, Snyk, AWS Security Hub, AWS Inspector, Jira, Confluence, or ServiceNow.
  • Certifications such as CISSP, CISM, CISA, CRISC, CAP/CGRC, or CCSP.
  • Experience mentoring security analysts and reviewing security deliverables.

Culture & Benefits

  • Remote work environment aligned with Eastern Time to support government clients.
  • Medical, dental, and vision coverage.
  • 401(k) retirement benefits, paid time off, and paid holidays.
  • Life and disability insurance plus wellness and employee support programs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →