Search jobs > Washington, DC > Subject matter expert

Senior RMF Subject Matter Expert

Iron Vine Security
Washington, DC
Full-time

Job Requirements :

  • 8+ years of Executive-Level cyber RMF consulting experience advising Cybersecurity programs in large federal organizations.
  • Strong interpersonal and human relations skills, including ability to communicate technical concepts to non-technical personnel.
  • Strong written, verbal, and presentation skills, including demonstrated ability to interact effectively with Senior Agency management and leadership.
  • Strong stakeholder management and engagement skills with staff at all levels, including ability to collaborate with people of varied technical backgrounds and management levels.
  • Advanced understanding of and experience with GRC tools, policy, procedures, and processes, including (but not limited to) FISMA audits and compliance, NIST, RMF, and recent Executive Orders.
  • Experience with NIST Risk Management Framework and Governance, Risk & Compliance (GRC) and Information Assurance capabilities / tools.
  • Strong familiarity with NIST Risk Management Framework at the subject matter expert level, particularly including SP 800-30, -37, -39, -137, -53, and -53A / B.
  • Ability to guide the development of enterprise-specific implementation guidance for agency management.
  • Ability to analyze and interpret Federal legislation, directives, Office of Management and Budget (OMB) mandates, and guidance provided by the National Institute of Standards and Technology (NIST) against existing information security and privacy policy to identify required updates.
  • Ability to conduct research on new and emerging information technologies and develop comprehensive information security and privacy policy, standards / guidelines, and procedures to facilitate the implementation of information security and privacy controls.

Must have working knowledge of the Privacy Act of 1974 (as amended), the Federal Information Security Modernization Act (FISMA).

Manage the program team and oversee the development of Enterprise Information Security Trainings and Enterprise Outreach Campaign Plans.

Certifications / Licenses :

  • A Bachelor's degree from an accredited college in systems engineering, computer science, computer engineering, information technology, management information systems or equivalent.
  • Combined 13+ years in cyber, IT or related fields.
  • At least one Cybersecurity or related certification. Preferred include :
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • GIAC Security Essentials Certification (GSEC)
  • Certified Authorization Professional (CAP)
  • Project Management Professional (PMP).
  • Active Secret clearance or higher.

Additional Experience Preferred :

Planning, developing, and implementing enterprise-scale cyber security programs for Federal Agencies.

o Planning and overseeing cyber and information security policies, processes, and procedures management activities.

o Experience managing Security Controls Assessment teams.

o Experience overseeing the development and execution of security and privacy assessment plans in accordance with NIST SP 800-53A, as amended, requirements, for each security assessment project.

o Experience overseeing enterprise-scale standards, guidance, administration, templates, reports, processes and procedures, and leverage communication vehicles used by the key stakeholders.

  • Knowledge of penetration testing principles, tools, and techniques.
  • Knowledge of an organization’s threat environment.
  • Experience with tools such as ServiceNow, Cylance, Tenable, Netsparker, Symantec DLP and Federal GRC tools (Xacta, CSAM, RSA Archer, Trusted Agent FISMA, Archangel, eMASS, etc.).

Position Responsibilities :

Be a driver of holistic and enterprise-scale changes in cyber-security programs within large Federal clients. Act as a disruptor to the status-quo to drive needed changes to cybersecurity and related agency-wide workflows (Privacy, SDLC, procurement, etc.

to ensure that security and privacy best-practices and statutory and regulatory requirements are met in a holistic and cost-effective manner.

Provide consultation expertise at various levels with a large Federal agency to develop and maintain enterprise-scale cyber security program that reacts quickly to changing regulatory and operational drivers, including emerging technical, operational and management risk-drivers :

o Participate in Daily, Weekly, and Monthly status meetings with key Government personnel, at times on short notice, to ensure stakeholders are informed of program status and progress on various cyber initiatives.

Provide an opportunity to set priorities, identify opportunities or concerns, and coordinate resolution of identified problems.

o Develop program level security documentation, audit liaison activities, and compliance oversight activities to strengthen the security program and promote compliance with the Risk Management Framework (RMF).

o Support the performance of independent security and privacy control assessments in support of Security Assessment & Authorization (SA&A).

o Support the management and implementation of continuous monitoring solutions to increase the visibility and transparency of network activity.

30+ days ago
Related jobs
Promoted
Axiologic Solutions
Washington, District of Columbia

The candidate must be able to work in a team as well as solely on special projects; have excellent interpersonal skills; be able to prepare top-quality written and oral communications products; and have experience working with senior Government executives. Communicate formally and informally through...

Promoted
VirtualVocations
Washington, District of Columbia

A company is looking for an IBM ODM Subject Matter Expert (SME). ...

Iron Vine Security
Washington, District of Columbia

Strong familiarity with NIST Risk Management Framework at the subject matter expert level, particularly including SP 800-30, -37, -39, -137, -53, and -53A/B. Executive-Level cyber RMF consulting experience advising Cybersecurity programs in large federal organizations. Strong written, verbal, and pr...

Promoted
VirtualVocations
Washington, District of Columbia

A company is looking for a Laboratory Subject Matter Expert to support the modernization of Electronic Health Records capabilities for the Department of Defense. ...

BryceTech
Washington, District of Columbia

Principal Subject Matter Expert (SME) II. ...

Promoted
VirtualVocations
Washington, District of Columbia

A company is looking for a Data Literacy Subject Matter Expert (SME) to develop and implement data literacy training programs for federal government agencies. ...

Booz Allen Hamilton
Washington, District of Columbia

Physical Access Control Systems Subject Matter Expert. As an Identity and Access Management (IAM) Physical Access Control Systems (PACS) Subject Matter Expert (SME)at Booz Allen, you’ll play a critical role in the world of identity and access management and zero trust. Applicants selected will be su...

Barrow Wise Consulting
Washington, District of Columbia

The IT Subject Matter Expert will support Barrow Wise's Federal Agency project and perform the following duties:. Provide new federal security guidance policies, processes, and subject matter expertise to develop new cybersecurity standards for contractors. Minimum of eight years of cybersecurity an...

BryceTech
Washington, District of Columbia

Principal Subject Matter Expert (SME) I. ...

Chenega Corporation
Washington, District of Columbia

Collaborate and support a team of performers across a range of expertise, including molecular diagnostic testing and biosensor instrument developers, data analysts, risk assessment software developers, property management firms, and others. ...