Cybersecurity Specialist 100% Remote

KMJJ Enterprise LLC
Lake Worth Beach, FL, United States
4 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing Security CompTIA Security+ Cyber Security Identity and Access Management Information Systems Security Architecture Professional Zero Trust Network Access Software Vulnerability Management Data Logging Software Security Information Technology Devsecops
+1 more
Plan of Action and Milestones

Job description

Seeking a Cybersecurity Specialist to ensure all applications meet FedRAMP High security and compliance requirements during assessment and onboarding for a FedRAMP High-authorized, healthcare-focused platform hosted in an AWS Government enclave. This role supports Independent Software Vendors (ISVs) and government applications by identifying security gaps, supporting authorization documentation, and validating alignment with applicable federal cybersecurity frameworks. The Cybersecurity Specialist will:

  • Assess application security posture, including logging, auditing, and control implementation, against FedRAMP High baseline requirements.
  • Support Authority to Operate (ATO) documentation efforts and compliance readiness activities for applications undergoing onboarding assessment.
  • Identifies cybersecurity gaps across assessed applications and recommends prioritized remediation actions with supporting rationale.
  • Evaluates application and environment alignment with Zero Trust architecture principles and continuous monitoring requirements.
  • Supports development of System Security Plans (SSPs), Plan of Action and Milestones (POA&M) inputs, and related security authorization artifacts.
  • Applies Risk Management Framework (RMF) processes to security assessment activities and documents findings in accordance with NIST guidelines.
  • Reviews identity, access control, and encryption implementations to verify compliance with applicable standards and FedRAMP controls.
  • Conducts vulnerability management reviews and evaluates continuous monitoring capabilities for onboarding candidates.
  • Collaborates with cloud architects, program managers, and ISV technical teams to communicate security findings and guide remediation planning.

Other Duties:

  • Performs other duties as assigned by management in support of SBG Technology Solutions contract objectives.
  • Travel requirements: occasional travel as required by project needs (estimated up to 10% per year).

Conditions of Employment:

  • Must be a US Citizen.
  • Must be able to pass a Federal background check.
  • Must be determined suitable for federal employment.

Security and Privacy Duties and Responsibilities Individuals working will be subject to security and privacy requirements as explained in HIPAA, FedRAMP, and NIST 800-53. Additionally, they are required to undergo specific FedRAMP training to ensure compliance with all associated controls and responsibilities in the day-to-day performance of their duties. Individuals working in departments that are considered to be in the high-risk category will be required to undergo advanced training based on their role and level of access. Individuals with access to modify data and the configuration baseline will require further training. The preceding functions are examples of the work performed by employees assigned to this job classification. Management reserves the right to add, modify, change, or rescind work assignments and make a reasonable accommodation as needed.

Requirements

  • In-depth knowledge of FedRAMP High security controls and the NIST Risk Management Framework (RMF) process.
  • Proficiency in security architecture review and cloud security engineering within AWS or comparable government cloud environments.
  • Experience conducting vulnerability management assessments and evaluating continuous monitoring programs.
  • Working knowledge of identity and access management (IAM), encryption standards, and access control frameworks.
  • Ability to develop and review authorization documentation including SSPs, POA&Ms, and security assessment reports.
  • Strong analytical and written communication skills; able to document and present security findings clearly to both technical and non-technical audiences.
  • Capable of managing concurrent assessment workstreams and delivering findings within defined project timelines.

Preferred Skills:

  • Familiarity with HIPAA Security Rule requirements and healthcare application security considerations.
  • Experience with AWS security tooling (e.g., AWS Security Hub, GuardDuty, CloudTrail, Config).
  • Knowledge of DevSecOps practices and secure software development lifecycle (SSDLC) methodologies.

Education: Required:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related technical discipline.
  • A combination of education and experience will be considered (2 years of relevant experience equivalent to 1 year in a degree program).

Desired: Master’s degree in Cybersecurity, Information Assurance, or a related field. Certification(s), Licenses: Desired:

  • Certified Information Systems Security Professional (CISSP).
  • Certified Information Security Manager (CISM).
  • CompTIA Security+ or equivalent federal baseline certification.
  • AWS Certified Security - Specialty.

Years of experience in a similar role: Required:

  • 8+ years of cybersecurity experience in federal or regulated environments, with demonstrated engagement in FedRAMP or RMF processes.

Desired:

  • 10+ years of cybersecurity experience, including direct responsibility for ATO support or FedRAMP authorization activities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · World Congress 2025

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all