Enterprise Cybersecurity Federal Compliance ISSO
Booz Allen HamiltonAbout the role
The Opportunity:
Enterprise Cybersecurity (ECS) Governance, Risk and Compliance (GRC) play a pivotal role in safeguarding the organization's sensitive information and ensuring compliance with stringent cybersecurity regulation and guidance. The GRC team is responsible for assessing and managing compliance and regulatory requirements in partnership with key stakeholders. ECS is seeking a definitive Subject Matter Expert in Cybersecurity Maturity Model Certification (CMMC) Levels 2 and 3 and National Institute of Standards and Technology (NIST) frameworks to lead compliance architecture and assessment within our Extended Enterprise Environment (EEE). Reporting through GRC leadership to the Cybers Information Security Officer (CISO), this executive-level contributor will audit controls and actively engineer compliance.
This role is responsible for reviewing and assessing technical and environmental details and providing a hands-on approach to ensure security compliance and regulatory requirements are achieved. This role collaborates with cross-functional teams across the Booz Allen enterprise and client teams. Due to the nature of work performed within this facility, U.S. citizenship is required.
Join us. The world can’t wait.
You Have:
10+ years of experience in cybersecurity or GRC
Experience in cybersecurity roles such as Security Control Assessor (SCA), Validator, Information System Security Officer (ISSO), Information System Security Engineer (ISSE), or Information Systems Security Manager (ISSM)
Experience with security controls alignment, and assessment against CMMC, National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, NIST SP 800-171 rev. 2 and rev. 3, Risk Management Framework (RMF), Federal Information Processing Standards (FIPS) 199, FIPS 200 and associated SPs, and Federal Risk and Authorization Management Program (FedRAMP)
Experience translating CMMC Level 3, NIST SP 800-171, and NIST SP 800-172 requirements into actionable engineering directives, leading the validation of evidence requirements for Level 2 and Level 3 assessments and meticulously analyze environment records, and identifying compliance gaps in complex systems, and driving remediation
Experience managing the full risk lifecycle, from identification to implementation of risk reducing strategies and final closure, using both qualitative and quantitative frameworks
Experience performing in-depth continuous monitoring and assessment of cybersecurity controls, evidence, and scan results to evaluate effectiveness and ensure continuous compliance
Experience partnering with IT, operations, and delivery teams to provide expert guidance, drive GRC initiatives, and foster a culture of awareness and knowledge for security compliance
Experience leveraging GRC automation platforms, such as eMASS, ServiceNow, RSA Archer, CSAM, or Telos Xacta
Ability to develop, maintain, and communicate metrics a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s