Washington, DC30+ days ago
p>· <\/span><\/span><\/span><\/span>Define and communicate security architecture strategies compatible with multi-tenant and hybrid cloud environments.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Evaluate vendor security postures and integration security impacts for connected applications.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Support internal and external audits, coordinating responses and remediation activities across functional teams.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Advise project managers and technical leads on secure configuration baselines and policy compliance.<\/span><\/span> <\/p> <\/div><\/span> Requirements<\/h3>Minimum Qualifications/Experience:<\/span> <\/h3> <\/span><\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Minimum 5 years of experience in federal cybersecurity, including at least 3 years in FedRAMP, FISMA, or related authorization frameworks.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Deep familiarity with NIST SP 800-53, 800-171, and 800-37 RMF.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Solid understanding of security architecture for cloud SaaS solutions (preferably SAP Concur, Mulesoft, or similar platforms).<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Experience with vulnerability management, incident response, and security operations.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Strong written and verbal communication skills for interfacing with Federal stakeholders.<\/span><\/span> <\/p> <\/span><\/span> <\/p>Preferred Qualifications:<\/span><\/b><\/span> <\/p>· <\/span><\/span><\/span><\/span>CISSP, CISM, or FedRAMP 3PAO experience.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Experience supporting GSA, DHS, or other civilian agencies in large-scale digital modernization projects.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Prior involvement in cloud migration or ERP cloud security initiatives.<\/span><\/span> <\/p> <\/span><\/span> <\/p>What You'll Deliver:<\/span><\/b><\/span> <\/p>· <\/span><\/span><\/span><\/span>Secure, compliant SAP Concur implementation aligned with GSA's Go.gov transformation milestones.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Comprehensive ATO documentation and control validation evidence.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>A sustainable framework for ongoing monitoring and risk management across participating agencies.<\/span><\/span> <\/p> <\/span><\/span> <\/p>Minimum Education:<\/span> <\/h3> <\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Bachelor's Degree in Information Security, Computer Science, or related field. <\/p>· <\/span><\/span><\/span><\/span>Develop, review, and maintain system security documentation including SSPs, POA&Ms, and related artifacts per NIST SP 800-53 and 800-37 guidelines.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Interface with GSA IT Security, agency ISSOs, and SAP Cloud Compliance teams to align controls, evidence, and risk assessments.<\/span><\/span> <\/p>· <\/span><\/span><\/span><\/span>Conduct continuous monitoring and controls assessment to sustain authorization.<\/span><\/span>