This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Our client, a leader in the HCM space is in need of a GRC/Vulnerability Lead for a 1 year contract with a strong likelihood of extension. This individual will be working a hybrid schedule out of Reston VA, support security, compliance, and risk management initiatives. The Lead will be responsible for supporting FedRAMP and RMF assessment and authorization activities, maintaining compliance across public sector cloud environments, and partnering with internal engineering and security teams to support secure product development and ongoing audit readiness.
Job Responsibility
support security, compliance, and risk management initiatives
support FedRAMP and RMF assessment and authorization activities
maintain compliance across public sector cloud environments
partner with internal engineering and security teams to support secure product development and ongoing audit readiness
Requirements
5+ years of experience in governance, risk and compliance and/or cybersecurity engineering
3+ years of direct experience with the FedRAMP and RMF assessment and authorization processes
Strong understanding of FedRAMP frameworks and DoD Impact Levels IL4 and IL5
Experience supporting federal SaaS cloud environments including logging and monitoring systems, access controls, FIPS encryption methods, source control management, and vulnerability management
Experience documenting security controls, policies, procedures, and compliance requirements
Experience supporting audit management, compliance assessments, and remediation activities
Strong written and verbal communication skills with the ability to support multiple initiatives simultaneously
Active TS SCI w/ CI Poly Clearance
DoD 8570 compliant at IAM or IAT Level II or higher
Nice to have
Experience supporting Intelligence Community or highly regulated federal environments
Experience assisting with vulnerability remediation and coordinating with engineering teams to resolve findings
Experience designing or assessing secure cloud computing systems
Strong understanding of product development lifecycle security requirements
Certifications including CISSP, CISA, PMP, AWS, CIPP, or related certifications