IT - Cyber Security Specialist IV
Role details
Job location
Tech stack
Job description
An Information System Security Officer (ISSO) is sought to join a team supporting the ClaimsCore Program. This role involves overseeing activities related to system security authorization, compliance, and continuous monitoring for a federal environment. The ISSO will be instrumental in ensuring secure and compliant systems across both legacy integrations and modern cloud-based platforms, supporting major cybersecurity initiatives for the Centers for Medicare & Medicaid Services (CMS)., * Serve as the ISSO for the ClaimsCore Program, ensuring compliance with FISMA Moderate, FedRAMP Moderate, and CMS ARS 5.1 security controls.
- Oversee the Authorization to Operate (ATO) process, including the preparation and maintenance of all Security Authorization (SA) and Certification & Accreditation (C&A) documentation.
- Conduct risk and vulnerability assessments, track remediation activities, and ensure zero open Critical/High vulnerabilities at go-live.
- Manage security incidents, ensuring notification within 1 hour, and coordinate with stakeholders on mitigation and reporting.
- Develop, maintain, and update security policies, procedures, SSPs, SOPs, and other RMF documentation.
- Support annual and ad hoc federal security assessments, including CSRAP, CFO, and OMB A123 reviews.
- Manage POA&M entries, validate mitigation strategies, and support audit responses.
- Perform continuous monitoring activities, analyze security reports, and recommend corrective actions.
- Collaborate with engineering, operations, and program management teams to embed security into system design.
- Provide subject matter expertise on NIST 800-53 controls, FedRAMP requirements, and CMS-specific security processes.
- Ensure all system changes follow proper security impact analysis procedures prior to deployment.
- Support contractor, government, and third-party security assessments.
Requirements
- Minimum of 8 years of experience with a BS/BA degree; or
- Minimum of 6 years of experience with an MS/MA degree; or
- Minimum of 3 years of experience with a PhD.
Technical Skills & Experience:
- Demonstrated experience as an ISSO or similar security lead on federal programs following FISMA, NIST RMF, and FedRAMP requirements.
- Hands-on experience developing and reviewing RMF documentation (SSP, SAR, POA&M, CMP, Incident Response Plan, Contingency Plan, etc.).
- Experience conducting or supporting risk assessments, vulnerability analysis, and security audits.
- Familiarity with CMS ARS 5.1, CMS ATO processes, and federal cybersecurity reporting requirements.
- Experience supporting incident response processes, including rapid notification and coordination.
- Strong understanding of vulnerability management tools and processes (e.g., Nessus, Tenable.sc, Qualys).
- Ability to communicate effectively with both technical and non-technical stakeholders.
- U.S. Citizenship is required.
Preferred Qualifications
- Relevant certifications such as CISSP, CISM, Security+, CEH, or CAP.
- Previous experience supporting CMS, federal healthcare programs, or large federal IT modernization efforts.
- Experience in hybrid environments involving legacy systems and cloud platforms (AWS/Azure) subject to FedRAMP Moderate controls.
- Familiarity with continuous monitoring processes and automation tools.
- Experience supporting external audits such as CSRAP, CFO, and OMB A-123.
- Knowledge of secure software development practices and DevSecOps concepts.
- Experience with enterprise-scale government contractors or large federal IT programs.