Talent.com
Senior Cybersecurity Engineer - Compliance & Risk Management
Senior Cybersecurity Engineer - Compliance & Risk ManagementHuman Resources Research Organization • Alexandria, VA, US
Senior Cybersecurity Engineer - Compliance & Risk Management

Senior Cybersecurity Engineer - Compliance & Risk Management

Human Resources Research Organization • Alexandria, VA, US
Hace más de 30 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

Job Description

Job Description

Senior Cybersecurity Engineer - Compliance & Risk Management

The Human Resources Research Organization (HumRRO) is a non-profit leader in developing high-impact services and products in the arenas of employment, military, student testing, and professional credentialing and licensure. We work with federal and state government agencies, private sector organizations, and professional associations.

About the Organization

As a non-profit, HumRRO is dedicated to work that contributes to science and society. Our employees enjoy a highly collaborative and supportive environment that fosters innovation, ethical practice, and outstanding customer service. Our core operational staff includes Industrial-Organizational Psychologists, Educational Researchers, and Behavioral Science Consultants. We are committed to supporting a diverse workforce and to practicing equity and inclusion for all staff.

About the Job

We are seeking a Senior Cybersecurity Engineer to lead our enterprise compliance and security programs across federal, state, and private sector engagements. This role manages multiple compliance frameworks including CMMC, FedRAMP, SCRM, NIST 800-171 / 53, and ISO 27001 : 2022 regulatory requirements. You will work on compliance standards across hybrid cloud environments while leading a team of junior engineers conducting vulnerability assessments and security scanning operations. A significant portion of this role involves creating security documentation, developing compliance policies, responding to time-critical security requirements from clients, and managing third-party compliance audits.

As a Senior Cybersecurity Engineer, you will :

  • Lead enterprise cybersecurity compliance programs (CMMC, FedRAMP, SCRM, NIST frameworks, ISO 27001 : 2022)
  • Manage monthly compliance reporting and KPI dashboards for executive leadership
  • Coordinate third-party compliance audits (NIST 800-171, CMMC, ISO 27001, FedRAMP) and remediation activities
  • Maintain compliance evidence catalogs and SaaS compliance implementation controls
  • Evaluate and implement security controls across software applications and cloud platforms AWS, Azure, and Office 365
  • Oversee Risk Management Framework (RMF) processes for government contract organizations as well as applications in the DoD space (ATO / IATT / IATO documentation)
  • Conduct weekly Plan of Action and Milestone (POA&M) reviews and monthly security assessments
  • Develop and maintain security policies, procedures, and technical standards
  • Lead vulnerability management programs & conduct security assessments and penetration testing coordination
  • Manage business continuity of operations (COOP) program including disaster recovery and crisis management plans
  • Lead incident response and security event investigation
  • Mentor and manage junior cybersecurity engineers and analysts
  • Interface with federal agencies, auditors, and compliance assessors
  • Work with system architects for security requirements on existing cloud workloads, cloud migrations and / or hybrid environments
  • Facilitate and oversee completion of all customers' cyber security questionnaires and qualifications with time-critical deadlines
  • Coordinate with HumRRO Contracts Division on written responses to RFPs regarding IT security, controls, data privacy and regulatory compliance
  • Assist with implementation and administration of cybersecurity supply chain risk management (C-SCRM) program
  • Develop compliance documentation and security narratives for proposals
  • Support business development with technical security expertise
  • Serve as subject matter expert on internal security controls and regulations

Minimum Requirements :

  • US Citizen with ability to obtain / maintain security clearance
  • Work on-site at Alexandria VA (Up to 2 remote days possible after 90-day introductory period)
  • Bachelor's degree in Cybersecurity, Computer Science, or equivalent field. Work experience may be considered in lieu of degree
  • 7+ years of cybersecurity engineering and compliance experience
  • 5+ years of enterprise experience managing Risk and Compliance efforts including multiple regulatory and standard security frameworks
  • Existing Security+ certification or the ability to obtain within 6 months (CISSP, CCSP, or CISM preferred)
  • Deep expertise in NIST 800-171, 800-53, RMF, and DoD compliance frameworks
  • Hands-on experience with CMMC and FedRAMP authorization processes
  • Proficiency in Office 365 security configuration and management
  • Experience with vulnerability scanning tools (e.g. ACAS, Nessus, Rapid7, Qualys or equivalent)
  • Strong analytical and information gathering skills with ability to work multiple tasks simultaneously under short deadlines
  • Excellent communication skills for stakeholder engagement
  • Preferred :

  • Active DoD clearance
  • Experience in the nonprofit sector managing IT or related activities
  • CMMC Certified Professional (CCP) or CMMC Certified Assessor (CCA)
  • Experience with FedRAMP 3PAO assessments
  • Knowledge of Supply Chain Risk Management (SCRM) frameworks
  • AWS certifications (Solutions Architect, Security Specialty preferred)
  • Experience with DevSecOps pipeline integration and IAC
  • CISSP, CCSP, CISM, or CISSP-ISSAP certifications
  • Knowledge of DoD STIG implementation and automated compliance tools
  • Federal contracting and audit experience
  • Experience with Atlassian suite (Jira, Confluence)
  • Experience with eMASS package development and continuous monitoring activities
  • Experience with STIG implementation and SCAP compliance validation
  • Experience with bi-annual COOP testing and crisis management plan development
  • Leadership experience managing technical teams
  • People Management Experience is a plus
  • The anticipated salary for this role is $100,000 to $155,000. Specific salary offers are based on candidate qualifications and experience.

    Benefits :

  • Health, dental and vision insurance
  • Life insurance equal to 2x annual salary
  • Retirement plan with company matching
  • Paid professional development and certification maintenance
  • Tuition reimbursement
  • 12 weeks of paid parental leave
  • Generous paid time off and 10 paid holidays
  • All qualified applications will receive consideration without regard to race, color, religion, sex, national origin, age, marital status, sexual orientation, veteran status, medical condition, or disability. EEO / Vet / Disabled.

    Named one of "50 Great Places to Work" by Washingtonian magazine and one of "Top Workplaces" by The Washington Post.

    Crear una alerta de empleo para esta búsqueda

    Senior Cybersecurity Engineer • Alexandria, VA, US

    Ofertas relacionadas
    Application Security Engineer

    Application Security Engineer

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for an Application Security Engineer to enhance the security of their platform.Key Responsibilities Design and deploy scalable, integrated security solutions that fit seamles...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Product Security Analyst

    Product Security Analyst

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Product Security Analyst, EMEA.Key Responsibilities Evaluate vulnerability reports to determine validity, risk, and severity Collaborate with hackers to address report...Mostrar más
    Última actualización: hace 4 días • Oferta promocionada
    Cloud Security Architect

    Cloud Security Architect

    VirtualVocations • Rockville, Maryland, United States
    A tiempo completo
    A company is looking for a Cloud Senior Lead Security Architect.Key Responsibilities Develop and maintain comprehensive security architectures for solutions in public clouds Evaluate and recomme...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    State Licensed Senior Security Architect

    State Licensed Senior Security Architect

    VirtualVocations • Alexandria, Virginia, United States
    Indefinido
    Security Architect to lead the design and implementation of secure enterprise and AI-driven architectures.Key Responsibilities Architect and design secure solutions for AI, data analytics, and cl...Mostrar más
    Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
    Cyber Security Architect

    Cyber Security Architect

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Staff Cyber Systems Architect.Key Responsibilities Create systems and practices for secure and reliable DNS services across various environments Architect systems usin...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Software Engineer, Trust and Risk

    Software Engineer, Trust and Risk

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Software Engineer, Trust and Risk.Key Responsibilities Design and develop systems to protect the platform and mitigate risks Proactively monitor and balance risk with ...Mostrar más
    Última actualización: hace 6 días • Oferta promocionada
    Software Security Engineer IV

    Software Security Engineer IV

    Airlines Reporting Corporation • Arlington, VA, US
    A tiempo completo
    It's a great time to join us at Airlines Reporting Corporation (ARC)! ARC accelerates the growth of global air travel by delivering forward-looking travel data, flexible distribution services a...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Product Security Engineer

    Product Security Engineer

    VirtualVocations • Rockville, Maryland, United States
    A tiempo completo
    A company is looking for a Product Security Engineer to integrate security best practices into the product development lifecycle. Key Responsibilities Collaborate with development teams to enhance...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Senior Principal / Principal Industrial Security Analyst

    Senior Principal / Principal Industrial Security Analyst

    Northrop Grumman • Annapolis Junction, MD, US
    A tiempo completo
    RELOCATION ASSISTANCE : No relocation assistance available.At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the wo...Mostrar más
    Última actualización: hace 2 días • Oferta promocionada
    ServiceNow Incident Manager

    ServiceNow Incident Manager

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for an Incident Manager responsible for overseeing the lifecycle of IT incidents within the ServiceNow platform. Key Responsibilities Monitor, triage, and manage incidents fro...Mostrar más
    Última actualización: hace 21 horas • Oferta promocionada • Nueva oferta
    Lead Incident Manager

    Lead Incident Manager

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Lead Incident Manager to manage critical outages and incidents impacting business operations.Key Responsibilities Plan and coordinate incident management activities for...Mostrar más
    Última actualización: hace 3 días • Oferta promocionada
    Application Security Principal Engineer

    Application Security Principal Engineer

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Principal Engineer to lead the development of innovative Application Security products.Key Responsibilities : Develop and integrate code scanning and application securit...Mostrar más
    Última actualización: hace 13 horas • Oferta promocionada • Nueva oferta
    Security Engineer with MBI Clearance

    Security Engineer with MBI Clearance

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Security Engineer.Key Responsibilities Design, implement, and manage security measures for network and information systems Configure, manage, and troubleshoot Palo Alt...Mostrar más
    Última actualización: hace 6 días • Oferta promocionada
    Software Engineer, Fraud

    Software Engineer, Fraud

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Software Engineer, Fraud.Key Responsibilities Design and develop systems to protect the platform against risks Balance risk and user experience by monitoring protectiv...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Software Engineer, Security

    Software Engineer, Security

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Software Engineer, Proactive Security.Key Responsibilities Build and maintain core security products such as Remote Access Management and Access Control Collaborate wi...Mostrar más
    Última actualización: hace 4 días • Oferta promocionada
    Network Security Architect

    Network Security Architect

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for a Network Senior Lead Security Architect.Key Responsibilities Lead assessments of potential risks targeting network infrastructures and provide security requirements and ...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Application Security Architect

    Application Security Architect

    VirtualVocations • Rockville, Maryland, United States
    A tiempo completo
    A company is looking for an Application Security Architect.Key Responsibilities Collaborate with development teams to implement secure coding practices and conduct application vulnerability asses...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Optimization Scientist with Security Clearance

    Optimization Scientist with Security Clearance

    VirtualVocations • Alexandria, Virginia, United States
    A tiempo completo
    A company is looking for an Optimization Scientist (Security Clearance).Key Responsibilities Integrate with an interdisciplinary team to design, build, and optimize models for real-world insights...Mostrar más
    Última actualización: hace 6 días • Oferta promocionada