Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
eSimplicity

Information Security Officer

eSimplicity

. Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership .

Posted 9/25/2026full-timeRemote • United StatesSeniorLead💰 $112,800 - $160,000 per yearWebsite

Tech Stack

Tools & technologies
AWSCloudCyber SecurityServiceNow

About the role

Key responsibilities & impact
  • Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership
  • Interpret FISMA, NIST RMF, NIST SP 800-53, CMS ARS, and agency security requirements and translate them into technical and operational actions
  • Develop, review, and maintain detailed security control implementation statements and supporting evidence
  • Maintain ATO artifacts, including System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, and configuration management plans
  • Lead Security Impact Analyses for system, application, infrastructure, cloud, data, and configuration changes
  • Support security assessments and audits by coordinating evidence collection, reviewing artifacts, responding to assessor inquiries, documenting gaps, and tracking corrective actions
  • Review vulnerability and compliance scan results, validate findings, assess risk, and coordinate remediation
  • Develop and review vulnerability documentation, remediation plans, POA&Ms, false-positive determinations, and risk exception requests
  • Track vulnerability and compliance findings through assignment, remediation, mitigation, risk acceptance, retesting, and closure
  • Support continuous monitoring, access reviews, security data calls, compliance reporting, and security posture assessments
  • Identify control, evidence, and documentation gaps and recommend corrective actions or process improvements
  • Develop security metrics, dashboards, status reports, and risk summaries for government stakeholders and program leadership
  • Communicate security risks, decisions, dependencies, overdue actions, and remediation status
  • Mentor security team members and perform quality reviews of security deliverables

Requirements

What you’ll need
  • Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles
  • Bachelor's degree in computer science, Information Systems, Engineering, Business, or another related scientific or technical discipline
  • Experience supporting federal systems subject to FISMA and the NIST Risk Management Framework
  • Experience applying NIST SP 800-53 security and privacy controls and CMS ARS or comparable federal security requirements
  • Experience developing, reviewing, and maintaining system-specific security control implementation statements and supporting evidence
  • Experience supporting ATO activities and maintaining System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related security artifacts
  • Experience supporting security assessments and audits, including evidence collection, assessor responses, gap identification, corrective action planning, remediation tracking, and closure validation
  • Experience managing vulnerability and compliance findings through validation, assignment, remediation, mitigation, risk acceptance, retesting, and closure
  • Experience with vulnerability and compliance tools such as Tenable, Snyk, AWS Security Hub, AWS Inspector, or comparable platforms
  • Ability to prepare technically supported risk exception requests and vulnerability documentation
  • Ability to develop accurate, audit-ready documentation and communicate security requirements, risks, findings, and remediation activities to technical and non-technical stakeholders
  • Ability to manage concurrent assignments, meet deadlines, maintain accurate status reporting, and escalate risks or blockers
  • Ability to obtain and maintain a Public Trust clearance
  • Must have resided in the United States for at least 3 of the last 5 years
  • Direct CMS systems, CMS security programs, or CMS ATO experience desired
  • Advanced CMS ARS 5.0 or later experience desired
  • AWS cloud security experience desired
  • Familiarity with DevSecOps, CI/CD pipelines, source-code scanning, software composition analysis, container scanning, and security release reviews desired
  • Experience using Jira, Confluence, and ServiceNow desired
  • Current certification such as CISSP, CISM, CISA, CRISC, CAP/CGRC, CCSP, or equivalent security or audit certification desired

Benefits

Comp & perks
  • Medical coverage
  • Dental coverage
  • Vision coverage
  • 401(k) retirement benefits
  • Paid time off
  • Paid holidays
  • Life insurance
  • Disability insurance
  • Wellness and employee support programs
  • Remote work environment
  • Occasional travel for training and project meetings, estimated at less than 5% per year