
location_onGranchina, Calle Guayama, 00917, United States
We are seeking a seasoned Security Governance and Risk professional to support and strengthen enterprise security governance for our Federal and Department of Defense (DoD) customers. This role is critical for translating complex Federal security requirements into practical, business-aligned solutions that drive organizational success.
In this position, you will perform complex risk analyses and establish Information Assurance (IA) requirements based on user, policy, regulatory, and resource demands. You will serve as a key advisor to information system owners, ensuring that client and project security policies align with rigorous Federal frameworks such as NIST, RMF, FedRAMP, and DoD mandates. Your work will involve collaborating closely with Enterprise ISSOs, project ISSOs, and business teams to maintain proper governance alignment across existing and prospective contracts.
A day in the life involves keeping abreast of emerging security technologies to recommend enhancements for system security postures, while also supporting the development and implementation of doctrine and policies. You will assist in the ongoing management of governance activities, including vendor assessments, annual enterprise risk assessments, and the maintenance of GRC Minimum Requirements. Success in this role requires the ability to communicate Federal technical language (such as NIST verbiage) in understandable business terms and to exercise significant judgment in selecting methods for evaluating complex security problems.
Work model: On-site
Granchina, Calle Guayama, 00917, United States
Skills: Nist, RMF, Fedramp, Fisma, Fips, CMMC, Nist 800-171, Nist 800-53, Nist 800-60, Nist 800-65.
Education: Bachelor's Degree in related field (equivalent experience considered); Bachelor's degree in cybersecurity, computer science, or related field (preferred).
Bachelor's degree in cybersecurity, computer science, information assurance, or related field. Certifications like CISSP, CISM, CISA, or GRC/audit or risk certifications.