Governance, Risk & Compliance / Cloud Security Subject Matter Expert

Lexical Intelligence LLC
  • Bethesda, MD
    4 days ago

    Job Description

    Lexical Intelligence provides software and services related to processing large-scale biomedical information sources. Our NLP and analytics software is used by policy and decision makers to evaluate and prioritize current and emerging areas of research.

    Lexical Intelligence is seeking a senior Governance, Risk & Compliance / Cloud Security Subject Matter Expert (GRC / Cloud SME) to serve as the security subject matter expert for a complex, cloud-native system supporting the National Institutes of Health (NIH). The system is fully deployed in Amazon Web Services (AWS) across multiple accounts and hosts multiple applications that process and analyze large-scale biomedical data. This is a hands-on Governance, Risk, and Compliance (GRC) leadership role. The GRC / Cloud SME will own the development and maintenance of the systems Authority to Operate (ATO) package within JCAM (NIHs enterprise GRC platform), advise the program on the security implications of change and configuration management, and serve as the systems Contingency Planning and Incident Response Coordinator. The GRC / Cloud SME will act as the trusted security advisor to a cross-functional team of software developers, DevOps engineers, data scientists, and program leadership. Key Responsibilities

    ATO Package Development & Maintenance

    Develop, maintain, and continuously improve the systems ATO package in JCAM, including the System Security Plan (SSP), control implementation statements, security policies and procedures, and all supporting artifacts. Ensure the ATO package accurately reflects the as-built, multi-account AWS environment and remains current as the system evolves. Support security assessments, audits, and annual control assessments; coordinate evidence collection and respond to assessor findings. Manage Plans of Action & Milestones (POA&Ms): track weaknesses, coordinate remediation with engineering teams, and report status to the Authorizing Officials staff.

    Change & Configuration Management Advisory

    Serve as the security voice in the change and configuration management process: review proposed system changes, perform Security Impact Analyses (SIA), and advise the team on whether changes affect the authorization boundary or control posture. Ensure security-relevant changes are documented, assessed, and reflected in the ATO package and continuous monitoring reporting. Advise on secure configuration baselines and monitor for configuration drift across AWS accounts.

    Contingency Planning & Incident Response Coordination

    Serve as the systems Contingency Planning Coordinator: develop and maintain the Information System Contingency Plan (ISCP), plan and facilitate annual contingency plan tests and tabletop exercises, and document test results and lessons learned. Serve as the systems Incident Response Coordinator: maintain the Incident Response Plan, coordinate incident detection, reporting, and response activities in accordance with NIH and HHS requirements, and lead incident response exercises. Ensure backup, recovery, and resilience capabilities are documented, tested, and aligned with system recovery objectives.

    Cloud Security Engineering & Team Advisory

    Advise developers, DevOps engineers, and data scientists on secure architecture and AWS security best practices across a multi-account environment, including IAM, AWS Organizations and service control policies, encryption and key management (KMS), logging and monitoring (CloudTrail, CloudWatch, GuardDuty, Security Hub, AWS Config), and network security. Support vulnerability management: review scan results, prioritize findings, and partner with engineering teams on remediation. Advise on secure development and DevSecOps practices, including CI/CD pipeline security and infrastructure as code. Serve as the day-to-day security advisor to the program, translating federal security requirements into practical guidance the team can act on.

    Minimum Qualifications

    7+ years of information security experience, including direct support of federal systems and the full ATO lifecycle under the NIST Risk Management Framework (SP 800-37). Deep, demonstrated expertise in NIST SP 800-53 control selection, implementation, and assessment, including authoring SSPs and control implementation statements. Hands-on experience securing AWS environments, preferably multi-account architectures (AWS Organizations), including IAM, logging/monitoring services, and encryption/key management. Experience developing and maintaining complete ATO packages within an enterprise GRC platform (e.g., JCAM, CSAM, eMASS, Xacta, or similar). Experience performing Security Impact Analyses and advising change control processes on security-relevant changes. Experience developing, maintaining, and testing contingency plans (NIST SP 800-34) and incident response plans (NIST SP 800-61). Experience with vulnerability management and POA&M lifecycle management, including tools such as Tenable, Inspector, or similar scanners. Strong technical writing and documentation skills with meticulous attention to detail. Proven ability to communicate security requirements effectively to engineers, data scientists, and program leadership. One or more of the following certifications: CISSP, CISM, AWS Certified Security - Speciality. Cloud process knowledge Linux familiarity

    Preferred Qualifications

    Direct experience with JCAM and supporting systems within NIH or other HHS agencies. Experience with containerized environments and orchestration platforms (e.g., Kubernetes, Amazon EKS). Exposure to infrastructure as code (e.g., Terraform) and automation of compliance or continuous monitoring activities. Familiarity with large-scale data platforms, biomedical data, or research-focused systems, including data privacy considerations for sensitive or regulated data. Experience supporting public-facing federal systems or APIs. Additional relevant certifications such as CISSP, CGRC/CAP, CISM, CCSP, or AWS Certified Security - Specialty. Cloud architecture / DevOps experience or knowledge

    All candidates will be required to undergo a background check, must be authorized to work in the United States, and must be able to obtain and maintain an NIH badge with Public Trust Level Two suitability. Location Preference will be given to candidates within reasonable commuting distance of Bethesda, MD. Candidates outside the greater Washington, D.C. / Maryland / Virginia area may be responsible for their own transportation costs for badging, equipment retrieval, and in-person attendance when required.

    Salary and benefits We offer a competitive salary and a generous benefits package, including at no cost: full health and dental for you and your dependents, HSA account, 401k, short- and long-term disability insurance, life and accident insurance, paid time off, and 11 federal holidays.

    Equal Employment Opportunity Policy Lexical Intelligence, LLC, provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

    This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

    Numbers & Facts

    LocationBethesda, MD

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Analysis Softwareunmatched
    • Application Hostingunmatched
    • Application Programming Interface (API)unmatched
    • Automationunmatched
    • Background Investigationunmatched
    • Best Practicesunmatched
    • Biomedicineunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Change Controlunmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Securityunmatched
    • Configuration Managementunmatched
    • Contingency Plansunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Improvementunmatched
    • Continuous Integrationunmatched
    • Cross-Functionalunmatched
    • Cryptographyunmatched
    • Data Recoveryunmatched
    • Data Scienceunmatched
    • Department of Health and Human Servicesunmatched
    • Detail Orientedunmatched
    • DevOpsunmatched
    • Establish Prioritiesunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Leadershipunmatched
    • Linux Operating Systemunmatched
    • National Institutes of Health (NIH)unmatched
    • Natural Language Processing (NLP)unmatched
    • Network Securityunmatched
    • Network Supportunmatched
    • Organizational Skillsunmatched
    • Riskunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Auditingunmatched
    • Security Infrastructureunmatched
    • Software Developmentunmatched
    • Status Reportsunmatched
    • Systems Administration/Managementunmatched
    • Systems Maintenanceunmatched
    • Technical Writingunmatched
    • Test Plan/Scheduleunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder