Назад
Company hidden
2 дня назад

Cyber Security Risk Lead (Cybersecurity)

192 546 - 200 875$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Security Risk Lead (Cybersecurity): Leading A&A, ATO, cybersecurity risk, vulnerability management, and compliance activities for VA Supply Chain Management DevSecOps products with an accent on NIST RMF artifacts, federal security controls, and cloud and containerized systems. Focus on managing authorization packages, coordinating assessments and remediation, and integrating security evidence into Agile delivery and release planning.

Location: Hybrid in Rockville, Maryland, or remote within the continental United States (CONUS); up to 10% CONUS travel.

Salary: $192,546–$200,875 per year.

Company

Provides cybersecurity, information technology, and DevSecOps services supporting federal programs, including the Department of Veterans Affairs Supply Chain Management program.

What you will do

  • Lead Assessment and Authorization (A&A), Authority to Operate (ATO), cybersecurity risk, vulnerability management, and compliance activities across the product portfolio.
  • Manage authorization status, security risks, Plan of Action and Milestones (POA&M), assessments, findings, evidence requests, and remediation activities.
  • Develop and maintain A&A artifacts aligned with the NIST Risk Management Framework and VA security requirements.
  • Support privacy and security requirements for cloud-hosted, containerized, and integrated systems.
  • Integrate authorization requirements and security evidence into Agile delivery, release planning, and incident response documentation.
  • Maintain reusable A&A templates, risk reporting standards, and security compliance practices.

Requirements

  • 8+ years of information security experience, including 4+ years as an ISSO, ISSM, Security Control Assessor, or A&A lead on federal IT programs.
  • Experience authoring complete A&A packages under the NIST Risk Management Framework, including System Security Plans, Risk Assessments, PIAs, Security Configuration Checklists, ISAs, and MOUs.
  • Hands-on experience with POA&Ms, security control evidence, federal GRC, vulnerability management, remediation tracking, and security risk assessments.
  • Experience supporting cloud-hosted or containerized systems, inherited security controls, and DevSecOps security practices and tools.
  • ISC2 CISSP, ISACA CISM, and GIAC Security Leadership Certification (GSLC) are required; CISM and GSLC may be obtained within 12 months of hire.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field; Tier 2 / Moderate Risk Background Investigation and ability to obtain a VA PIV credential required.

Nice to have

  • Experience with VA OIT, VHA, or other federal health cybersecurity environments.
  • Familiarity with VA Handbook 6500, VA Critical Security Controls, and VA security processes.
  • Master’s degree in a related field.

Culture & Benefits

  • Mission-driven work supporting programs that improve lives.
  • Remote working options, paid time off, paid holidays, and military leave.
  • Healthcare benefits, Healthcare Savings Account, Flexible Savings Account, paid life insurance, and short- and long-term disability coverage.
  • 401(k) matching, tuition reimbursement, training and certification opportunities, and an Employee Assistance Program.
  • Learning, internal mobility, transparent leadership, and support for Veterans.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →