Jobs and Careers
NO

Sr. Cybersecurity Engineer – GRC

Noblis
United Statesfull_timeVerifiedPosted 30 Nov 2023
💰 $210,200/yr($120,100/yr$210,200/yr)

About the role

Responsibilities

As a Senior Cybersecurity Engineer for the CMS Cyber Risk Management (CRM) Program at Noblis you will be part of our Health Solutions team.  You will be responsible for managing and maintaining the CMS governance, risk, and compliance (GRC) tool platform, assessing current and future GRC tools needs, and leading the identification of potential internal and/or external options that reduce risks, provide better security and compliance, and address significant GRC challenges.  

 

CMS seeks to strengthen and modernize the Nation's health care system and provide access to high quality patient-centered care and improved health at lower costs. In delivering this mission, CMS is responsible for collecting, generating, storing, and therefore protecting large volumes of personal, financial, healthcare, and other sensitive information.  The CMS Cybersecurity Risk Management (CRM) Program aligns the processes, data, technologies, capabilities, and services to effectively manage risk across the enterprise. This program enables a shift to data-driven risk management, enabling prioritized investments in cybersecurity by focusing efforts where they will reduce the most risk.

 

Working in concert with cybersecurity leaders and experts, you will address challenges related to ensuring CMS has the right risk management tools and processes in place to maintain organizational trust across an ever-increasing risk landscape.

 

Role functions may include:

  • Managing and maintaining the configuration and upgrades to the existing GRC tool platform.
  • Leading the design, engineering, documentation, and implementation of the GRC platform architecture.
  • Creating GRC requirements documentation, detailing compliance requirements, operational constraints, and business requirements for CMS GRC tools and capabilities.
  • Leading the evaluation, testing, and implementation of enhanced GRC tooling and capabilities that innovate, automate, and streamline GRC activities while retaining compliance with agency policies and guidelines.
  • Producing audio, video and text-based content to document and describe GRC tooling and capabilities and train GRC platform end-users.
  • Ensuring that GRC platform capabilities are integrated with and support various cybersecurity functions, including asset management, vulnerability management, and risk reporting.

 LOCATION: REMOTE OR Baltimore MD

Required Qualifications

  • Minimum of a Bachelor's degree or equivalent experience (Science, Technology, Engineering or Mathematics)
  • At least 8 years experience in the cyber security industry, including specific experience with Federal governance, compliance, and risk management tools and processes.
  • Experience with the RSA Archer GRC platform.
  • Experience with leading security solution development/engineering or hands-on implementation of security solutions
  • Experience with  Federal security and compliance standards, including NIST SP 800-53 and NIST SP-800-37
  • Knowledge of modern programmatic interfaces, such as REST or SOAP APIs, and real-word experience integrating open-source software (OSS) and consumer-off-the-shelf (COTS) solutions.
  • Experience with cloud security solutions and monitoring within the AWS and Azure environments, including knowledge of AWS compliance tools.
  • Ability to thrive in an ever changing, technology-based consulting environment.
  • Willingness to readily take ownership of tasks and problems, which often extend beyond initial scope of responsibility.

Desired Qualifications

  • Security-related certification such as CISM, CISSP, or similar

Overview

Noblis and our wholly owned subsidiaries, Noblis ESI, and Noblis MSD tackle the nation's toughest problems and apply advanced solutions to our clients' most critical missions. We bring the best of scientific thought, management, and engineering expertise together in an environment of independence and objectivity to deliver enduring impact on federal missions. Noblis works with a wide range of government clients in the defense, intelligence and federal civil sectors. Learn more at Noblis -About Us

 

Why work at a Noblis company?

Our employees find greater meaning in their work and balance the other things in life that matter to them. Our people are our greatest asset. They are exceptionally skilled, knowledgeable, team-oriented, and mission-driven individuals who want to do work that matters and benefits the public. Noblis has won numerous workplace awards. Noblis maintains a drug-free workplace.

Minimum Salary

USD $120,100.00/Yr.

Maximum Salary

USD $210,200.00/Yr.

Salary Range Explanation

At Noblis we recognize and reward your contributions,

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Noblis

View company profile →