Quick Overview
Job Description
Goals and Worker Activities
- Integrate security into program operations
- Partner with organizational leaders to incorporate information security best-practices into technical and operational development.
- Provide recommendations on how to improve the information security posture of programs and reduce risk.
- Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact.
- Draft security requirements to be included into charters, scope documents, procurements.
- Document and communicate analysis. Answer clarifying questions.
- Escalate to ISS leadership if an acceptable level of risk cannot be achieved
- Act as a liaison between the program area and the Information Security Section
- Be a solutions-focused advocate.
- Intake projects and other program initiatives and champion them through the appropriate ISS workstream
- Gather information as needed so that security team can perform thorough analysis
- Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer needs, follow-up on any clarifications.
- Coordinate across ISS meeting their security-focused needs
- Coordinate with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome
- Support audit, assessment, incident response, and other regulatory activities
- Responsibility and authority will vary based on the use case and customer need.
- Request and/or gather artifacts demonstrating compliance.
- Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders.
- In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone.
- Provide oversight to the resolution, test for compliance, and request authority to close.
- Respond to regulatory inquiry and draft documents as needed
- Participate and support Program Integration related activities
- Back-up other security liaison roles
- Draft and deliver status reports
- Establish and maintain positive working relationships with stakeholders
- Establish and documents standard operations for job-related activities.
- Support Vulnerability Management related to DMS and its vendors
- Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors
- Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management
- Draft and monitor plans of action and milestones for non-compliance
- Support DHS s transition from the Center for Medicare and Medicaid Services (CMS) compliance requirements known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to the new requirements known as Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE)
- In partnership with Deloitte, DET, and ISS conduct GAP analysis to support transition, implementation, and maturation of DHS s transition from MARS-E to ARC-AMPE
- Draft the ARC-AMPE System Security and Privacy Plan (SSPP) and keep it current
- Draft and monitor plans of action and milestones for non-compliance
- Support DHS in completing software reviews, cloud brokerage reviews, and AI Use Case reviews
- Other duties as assigned
- Back-up other security staff
- Write concept papers, proposals and briefs, and other documentation
Knowledge, Skills, and Abilities
- Well qualified candidate will have broad knowledge of information security and experience application development, technical architecture, contracting, audit, or vendor management.
- Be familiar with NIST or another recognized framework
- Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner.
- Demonstrated attention to detail and organizational skills.
- Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.
- Demonstrated commitment to fostering a diverse working environment.
- Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment.
Project Details:
DHS is seeking a Level III security professional with vulnerability management knowledge, strong documentation and compliance experience, and excellent stakeholder communication skills. Success in this position depends on the ability to work cross-functionally, manage competing priorities, contribute to federal security compliance efforts, and serve as a trusted partner to both security teams and business stakeholders.
This role requires understanding security concepts, technical requirements, and operational processes, and communicating them effectively to non-security audiences. The position contributes to key security and privacy deliverables, including system security and privacy plans, and plays a significant role in developing and maintaining these documents. It also supports vulnerability management efforts across the CARES environment, with a strong focus on tracking, monitoring, and ensuring remediation activities are completed.
Interview Process:
- Two Round Virtual Interview Process. Video conference interview or an onsite interview may be required.
- AI Assistance is PROHIBITED during the interviews.
- A real time photo is required to be uploaded for interviews.
Similar jobs
- DP
Appian Security Business Analyst- Secret Clearance with Security Clearance
Dunhill Professional Search
Arlington, VA🇺🇸$115k - $132k/yrRemote1 week agoOperations & Project Management - SP
Product Security Engineer (Starlink)
SpaceX
Hawthorne, CA🇺🇸$130k - $155k/yrHybrid4 weeks agoTCP/IPC++Go+1Technology - AI
Information Systems Security Officer with Security Clearance
Anduril Industries
Irvine, CA🇺🇸$113k - $149k/yrHybrid6 weeks agoEncryptionSplunkBash+4Technology - AI
Manager, Security Software Engineering with Security Clearance
Anduril Industries
Costa Mesa, CA🇺🇸$191k - $253k/yrHybrid6 weeks agoRustComputer VisionC+++3Technology - CG
Information System Security Officer (ISSO) with Security Clearance
CCS Global Tech
Scott AFB, IL🇺🇸Remote6 weeks agoTechnology - SP
Embedded Security Engineer (Starlink)
SpaceX
Hawthorne, CA🇺🇸$130k - $155k/yrHybrid7 weeks agoTCP/IPC++Go+1Technology