DoD RMF, Compliance and Risk Management Leader
CrederaAbout the role
Credera is a global consulting firm that combines transformational consulting capabilities, deep industry knowledge, AI and technology expertise to deliver valuable customer experiences and accelerated growth across various industries. We continuously evolve our services to meet the needs of future organizations and reflect modern best practices. Our unique global approach provides tailored solutions, transforming the most influential brands and organizations worldwide.
Our employees, the lifeblood of our company, are passionate about making an extraordinary impact on our clients, colleagues, and communities. This passion drives how we spend our time, resources, and talents. Our commitment to our people and work has been recognized globally. Please visit our employer awards page: https://www.credera.com/awards-and-recognition.
The DoD GRC Leader ensures Department of Defense (DoD) Information Systems achieve and maintain security and compliance by applying security engineering principles throughout the system development lifecycle. This role provides strategic oversight for risk management, security architecture, compliance initiatives, and cross-functional collaboration, supporting Authorization to Operate (ATO) and adherence to DoD, NIST, and federal standards.
RESPONSIBILITIES
- Enterprise System Security Design & Integration
- Provide strategic leadership in designing and integrating security architectures for government information systems, ensuring alignment with DoD and NIST frameworks
- Direct the documentation and integration of security requirements into system architectures and engineering processes
- Oversee the implementation, validation, and continuous improvement of security controls for effective risk mitigation and compliance
- Lead modernization and migration of systems to meet evolving security baselines and regulatory requirements
- Risk Assessment & Mitigation
- Lead comprehensive risk assessments, including vulnerability testing and technical evaluations, to identify and address threats and mission impacts
- Develop and implement risk mitigation strategies, and ensure ongoing risk management in line with DoD organizational objectives and regulatory directives
- Direct the development and execution of security assessment plans, including in-depth technical evaluations, vulnerability testing, and compliance assessments in accordance with DoD and NIST standards
- Analyze vulnerability scan results and threat intelligence, prioritizing remediation and ensuring timely resolution of security issues
- Compliance & Authorization
- Oversee the Risk Management Framework (RMF) process, guiding systems through assessment and authorization phases to achieve and sustain ATO
- Ensure accurate development and maintenance of System Security Plans (SSPs) and related compliance documentation
- Maintain continuous monitoring and governance to ensure ongoing compliance with all applicable cybersecurity standards and directives
- Oversee and support cybersecurity audits and inspections, driving prompt and effective technical remediation of findings
- Continuous Monitoring & Incident Response
- Direct the development and execution of enterprise-wide continuous monitoring strategies to maintain situational awareness and security posture
- Oversee impact analyses for system and operational changes, ensuring informed risk decisions and regulatory compliance
- Lead the creation and maintenance of incident response plans, and provide expert guidance during cybersecurity incidents to ensure effective mitigation and recovery
- Serve as a senior technical advisor during cybersecurity incidents, providing expert guidance, coordination, and support to ensure effective containment, mitigation, and recovery efforts
- Collaboration & Reporting
- Foster collaboration with IT leadership, program managers, and key cybersecurity stakeholders throughout the system lifecycle
- Provide executive-level briefings and reports to senior management, supporting informed decision-making and effective risk communication
- Ensure comprehensive and audit-ready documentation for security controls, assessments, and system architecture
QUALIFICATIONS
- Minimum 8 years progressive, hands-on Federal consulting experience, including significant DoD exposure
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s