FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in compliance and security assessments for AI vendors, with a strong focus on Federal systems and CMS requirements. Proficient in authoring security artifacts and managing compliance documentation while ensuring adherence to regulatory standards.
Highest-signal resume keywords
Compliance Work LeadershipCFACTS KnowledgeFISMA / NIST SP 800-53 Control TailoringAWS FedRAMP ExperienceTechnical Writing
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Compliance AssessmentSecurity Artifact AuthoringData-Handling ComplianceControl InheritanceBoundary DefinitionVulnerability ManagementPHI HandlingPII RequirementsSecurity Posture AssessmentThird-Party Vendor Assessment
Soft Skills
Clear Technical WritingCoordination with StakeholdersAdvisory Skills
Tools & Technologies
AWS IAMAWS KMSAWS GuardDutyAWS CloudTrailOkta SSO/RBACCloudWatchSplunkDatabricksSnowflake
Certifications & Qualifications
CISSPCISMCAPCISA
Industry Keywords
CMS Security PostureATO LifecycleSOC 2FedRAMPHIPAAHITRUSTPublic Trust ClearanceSAFe Agile ComplianceVendor-Isolated Enclaves
Tech Stack
Tools & technologiesAWSSplunk
About the role
Key responsibilities & impact- Assess each candidate agentic AI vendor against CMS security posture, data-handling, and ATO requirements
- Author security-and-compliance inputs to the POC Solution proposal, including control inheritance, boundary definition, data-flow diagrams, and compliance narrative
- Coordinate with the FPS ISSO/ISSM and CMS security stakeholders to keep AI tool assessment and POC activity inside the FPS ATO boundary
- Own compliance artifacts and cadence, including SSP inputs, POA&M entries, and PIA/SORN as applicable
- Serve as the single point of contact for security-and-compliance questions from third-party vendors, CMS, or the Peraton PM
- Advise the Lead AI Solutions Architect on LLM/agentic-AI-specific compliance concerns, including data retention, prompt/response logging, PHI-in-prompt controls, and tool authorization
Requirements
What you’ll need- Minimum of 8 years with BS/BA; minimum of 6 years with MS/MA; minimum of 3 years with PhD
- Experience leading compliance work on Federal systems, ideally CMS systems
- Deep working knowledge of CFACTS, CSRAP, and the ATO lifecycle (SSP, SAR, POA&M, contingency plan, PIA/SORN)
- Practical experience with FISMA / NIST SP 800-53 control tailoring, AWS FedRAMP baseline control inheritance, and boundary definition
- Experience assessing third-party/vendor security posture, including SOC 2, FedRAMP, HIPAA/HITRUST, penetration-test evidence, and vulnerability management
- Familiarity with AWS IAM, KMS, GuardDuty, CloudTrail, Config, Okta SSO/RBAC, and audit-log routing to CloudWatch/Splunk
- Working knowledge of HIPAA PHI handling and Federal PII requirements, especially for Medicare/Medicaid claims data
- Ability to author security artifacts and briefings for CMS-level review; clear technical writing required
- US citizenship
- Ability to obtain and maintain a Public Trust clearance
- Preferred: CISSP, CISM, CAP, CISA, or equivalent certification
- Preferred familiarity with LLM and agentic AI security considerations
- Preferred experience defining vendor-isolated enclaves within a Federal customer's authorization boundary
- Preferred familiarity with SAFe Agile compliance patterns
- Preferred familiarity with Databricks and Snowflake governance controls
Benefits
Comp & perks- Potential eligibility for overtime
- Potential eligibility for shift differential
- Potential eligibility for a discretionary bonus
- Equal opportunity employment
