Sr Principal Business Information Security Officer
Magellan HealthAbout the role
This is a 100% remote position that will lead cybersecurity compliance efforts ensuring adherence to federal regulations and contracts. The ideal candidate brings deep experience in federal cybersecurity frameworks, stakeholder engagement, and information security leadership.
Responsibilities:
Lead GRC initiatives supporting federal contracts.
Ensure compliance with federal cybersecurity frameworks including NIST 800-53, NIST 800-171, FAR/DFARS.
Lead CMMC certification and/or FedRAMP authorization.
Maintain organization information in the Supplier Risk Performance System (SPRS)
Develop and maintain System Security Plans (SSPs), POA&Ms, and Authority to Operate (ATO) packages as needed.
Conduct gap analyses security control assessments to ensure continuous compliance and readiness for external assessments.
Support federal contractor information systems and ensure alignment with contract-specific security requirements.
Collaborate with program managers, technical teams, and external clients to implement security controls to mitigate risks.
Serve as a liaison with federal clients and third-party assessors.
Required Skills:
Experience leading an organization's achievement of FAR/DFARS and FedRAMP compliance.
Strong knowledge of NIST 800-53, NIST 800-171, FAR/DFARS, CMMC, and FedRAMP.
Strong communication and documentation skills, including briefing senior leadership and government stakeholders.
Ability to translate regulatory requirements into actionable security controls and program strategies.
Experience with NIST 800-37 Risk Management Framework (RMF).
Possess at least one of the following certifications: CISM, CISA, CISSP, CGRC, CCP, CCA.
Previous ISSO or BISO experience.
Experience with HIPAA, HITRUST, and SOC 2 compliance.
Leads efforts to ensure adequate security processes and solutions to mitigate or remediate identified risks sufficiently to meet business objectives, contractual and/or regulatory requirements.
Leads incident response activities, ensuring security incidents are properly contained, eradicated, and recovered.
Drives development of security policies, standards and plans to ensure the protection of corporate data against unauthorized use, access, modification and destruction.
Ensures proper security logs are generated and sent to the organization’s Security Information and Event Management (SIEM) system.
Researches and implements emerging technologies to enhance the security portfolio.
Persistently evaluates adherence with defined policies and standards.
Leads efforts with identifying, remediating, and/or mitigating vulnerabilities in the environment, ensuring appropriate response to high risk and aged findings.
Leads the development, design, implementation, and maintenance of a secure environment for Magellan Health.
Ensures Magellan security processes and solutions are protected against a failure or attack that reduces the organization’s ability to respond to security incidents.
Ensures Magellan processes and solutions are maintained securely and highly available to protect the confidentiality, integrity and availability of assets
Monitors and ensures systems revisions and patches are up to date.
Manages and performs changes to the solutions and remove unnecessary services.
Understands risks and impact to systems in the corporate environment and their interconnectivity
Builds cross function team unity by supporting other Magellan team members to understand security risks and impact to all co
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Behavioral Health Clinical Trainer Sr – Foster Care (Charlotte, NC and nearby counties)
Elevance Health
Sr. Quality Engineer - Corrective & Preventive Actions
iRhythm
$125,000/yr
Sr. Universal Banker
Mechanics Bank