Track This Job
Add this job to your tracking list to:
- Monitor application status and updates
- Change status (Applied, Interview, Offer, etc.)
- Add personal notes and comments
- Set reminders for follow-ups
- Track your entire application journey
Save This Job
Add this job to your saved collection to:
- Access easily from your saved jobs dashboard
- Review job details later without searching again
- Compare with other saved opportunities
- Keep a collection of interesting positions
- Receive notifications about saved jobs before they expire
AI-Powered Job Summary
Get a concise overview of key job requirements, responsibilities, and qualifications in seconds.
Pro Tip: Use this feature to quickly decide if a job matches your skills before reading the full description.
Key Responsibilities
Security Program & Compliance
- Provide leadership within FISMA/RMF-compliant programs, with strong preference for experience in:
- CMS MARS-E
- ARC-AMPE
- Develop, maintain, and assess RMF/A&A artifacts including:
- System Security Plans (SSPs)
- Privacy Impact Assessments (PIAs)
- Interconnection Security Agreements (ISAs)
- Computer Matching Agreements (CMAs)
- Conduct interviews, audits, and assessments to validate compliance artifacts.
- Integrate RMF/A&A activities into the System Development Life Cycle (SDLC).
- Support cloud security governance and vendor security management efforts.
Perform detailed architectural reviews and risk analyses, including:
- Network design and information flow
- System and data access models
- Firewall rule reviews (ports, protocols, services)
- Configuration deviation requests
- Vulnerability management reviews
- Champion security and compliance initiatives across SCDHHS.
- Audit and assess internal systems and third-party/vendor environments.
- Serve as primary point of contact for third-party audits and assessments.
- Review and assess:
- Contracts
- Business Associate Agreements (BAAs)
- Data usage and data-sharing agreements
- Provide security risk mitigation recommendations to leadership and stakeholders.
- Document findings using tools such as:
- Microsoft Office (Word, Excel, PowerPoint, Visio)
- System Center Service Manager (ticketing)
- Archer eGRC
- Bizagi
- Atlassian products
- Produce clear, compliant audit and assessment documentation following branding and style guidelines.
Hands-on experience with one or more of the following:
- Archer (eGRC)
- Enterprise NoSQL databases
- IBM System 390 / zSeries
- Linux and Windows servers
- Network firewalls, IPS, switching and routing
- SIEM solutions
- Identity and Access Management (IAM) solutions
- 5+ years of IT experience working with and/or auditing:
- IBM System 390/zSeries
- Windows and Linux systems
- Relational and non-relational databases
- Networking infrastructure
- Web-based applications
- Prior experience working within a FISMA-compliant program
- Experience using eGRC systems
- ITIL experience in Information Security Management
- Prior Health Information Technology experience
- One or more Information Security certifications:
- ISC2
- ISACA
- SANS GIAC
- Or equivalent
- Bachelor's degree in Computer Science or a related field OR
- 10+ years of relevant professional experience
- Strong knowledge of FISMA, NIST, CMS MARS-E, and HIPAA
- Ability to work independently and collaboratively
- Strong multitasking and prioritization skills
- Effective communication with technical and non-technical audiences
- High attention to detail with strong big-picture awareness
- Adaptability to change and constructive feedback
Key Skills
Ranked by relevanceReady to apply?
Join TALENT Software Services and take your career to the next level!
Application takes less than 5 minutes

