CVP logo
CVPPosted 25 months ago

Risk Manager

$155–$165,000 year

HybridRockville, Maryland, United States

Full TimeAssociates DegreeMedium

Job Summary

Develop agency information security risk management strategies and conduct enterprise risk assessments aligned with NIST Special Publications. Create the Information Security Risk Assessment Report, Privacy and Security Roadmap, and Risk Management Plan to guide risk tolerance, response, and monitoring. Provide recommendations for A&A activities, tailor processes for non-traditional technologies like cloud and IoT, and track POA&Ms across divisions. Develop guidance, templates, and tools to support program offices in completing security accreditation packages and continuous monitoring. Advise decision-makers on system security posture and imminent threats.

Required Qualifications

  • Minimum of six years' experience in cybersecurity
  • Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs
  • Shall have at least one of the following industry-recognized certifications: Certified Information System Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC)
  • Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services
  • Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks
  • Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation
  • Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18
  • Compliance with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates
  • Location: Rockville, MD (Hybrid)

Desired Qualifications

  • 10+ years' experience in cybersecurity
  • Seven plus years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs
  • PMP Certification
  • CISSP Certification
  • Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)
  • NIH/HHS experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce