Cybersecurity Specialist
Role details
Job location
Tech stack
Job description
-
Support Risk Management Framework (RMF) implementation and lifecycle activities in accordance with NIST SP 800-37/30/53.
-
Support compliance with Federal Information Security Modernization Act (FISMA) Confidential Information Protection and Statistical Efficiency Act (CIPSEA), Office of Management and Budget (OMB), and HHS information security requirements.
-
Develop, update, and maintain Security Assessment and Authorization (SA&A) documentation including System Security Plans, Risk Assessment Reports, Plan of Action and Milestones (POA&Ms), Contingency Plans, and related security artifacts.
-
Assist system stewards and Information System Security Officers (ISSOs) with preparing complete authorization packages.
-
Provide expertise in FedRAMP, cloud-hosted SA&A activities, and contractor & CDC-hosted environments.
-
Support cloud migration and cloud security governance for systems in Amazon Web Services, Azure, or other authorized federal environments.
-
Supporting federal continuous monitoring programs and vulnerability reporting.
-
Develop Standard Operating Procedures, templates, system documentation, training materials, and reusable tools.
-
Coordinate regularly with federal staff, contractors, business stewards, technical stewards, and privacy officials.
-
Provide expert consultation on security requirements, cloud architectures, and risk mitigation strategies.
-
Perform technical writing, documentation development, dashboard/report preparation, and training support activities.
Requirements
Do you have experience in RMF?, Do you have a Bachelor's degree?, * 5 years of demonstrated experience supporting Federal information security and privacy compliance activities within a federal civilian agency environment.
- Experience supporting RMF implementation, SA&A/ATO activities, and continuous monitoring.
- Hands-on experience with cloud security operations, FedRAMP-aligned environments, and modernized/cloud-based systems.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field., * Relevant cybersecurity certifications such as:
- Certified Information Systems Security Professional (CISSP),
- Certified Authorization Professional (CAP),
- Certified Information Security Manager (CISM),
- Certified Cloud Security Professional (CCSP),
- or equivalent certifications
- Experience supporting CDC, HHS, or other Federal civilian agency environments
- Experience supporting cloud migration, FedRAMP authorization activities, or Federal continuous monitoring programs
- Experience supporting Federal information security governance, compliance, and operational security support activities within large or complex enterprise environments
- Demonstrated familiarity with the Confidential Information Protection and Statistical Efficiency Act (CIPSEA) and its application within a federal statistical agency environment.
Security Requirements
- Public Trust Level 5 or Higher required.