Cyber Remediation & POA&M Coordinator (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cyber Remediation & POA&M Coordinator (Cybersecurity): Coordinating enterprise vulnerability remediation and Risk Management Framework activities supporting NIH programs with an accent on POA&M governance, corrective-action validation, and risk visibility. Focus on prioritizing high-impact findings, coordinating remediation across technical and business stakeholders, and producing executive-level reporting on residual risk and compliance.
Location: 100% remote within the United States; supports federal cybersecurity programs for the National Institutes of Health.
Company
is a cybersecurity services company supporting government and enterprise security, risk, and compliance programs.
What you will do
- Coordinate remediation of vulnerabilities identified through monitoring, scanning, penetration testing, audits, and security assessments.
- Develop, maintain, and manage POA&Ms in line with Federal, HHS, and NIH requirements.
- Partner with ISSOs, system owners, security engineers, and technical teams to define remediation plans, milestones, and timelines.
- Monitor progress, validate evidence, document corrective actions, and escalate overdue or high-priority items.
- Coordinate risk acceptance requests, compensating controls, waivers, and remediation exceptions.
- Prepare remediation metrics, executive summaries, authorization documentation, and assessment responses.
Requirements
- Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, or a related field.
- At least three years of experience in vulnerability management, RMF, cybersecurity governance, or compliance programs.
- Experience developing and managing Plans of Action and Milestones (POA&Ms).
- Working knowledge of NIST RMF, FISMA, and NIST SP 800-53.
- Experience coordinating remediation across multiple technical teams and business stakeholders.
- Strong organizational, written, and verbal communication skills for technical and executive audiences.
Nice to have
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience with JCAM, eMASS, ServiceNow, Archer, or similar GRC platforms.
- Familiarity with CISA Known Exploited Vulnerabilities guidance, Binding Operational Directives, and Federal remediation requirements.
- Experience with CDM initiatives, audit remediation, authorization packages, or continuous monitoring.
- CGRC, CISSP, Security+, CAP, CISM, or PMP certification.
Culture & Benefits
- 100% remote work arrangement.
- People-first environment focused on cybersecurity excellence and sustained growth.
- Opportunity to support high-impact Federal cybersecurity and risk-reduction initiatives.
- Collaboration with security, engineering, system ownership, and executive leadership stakeholders.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →