|
Apply
Description
Nemean Solutions, headquartered in Sierra Vista, AZ, is a certified SBA 8(a) Native Hawaiian Organization (NHO) and veteran-operated company providing advanced Military Intelligence, Enterprise and Cloud IT services, Cybersecurity, Special Operations Forces (SOF) Exercise and Training, and niche Program Support and Professional Services to Federal and State Agencies supporting the US Government Defense, Intelligence and Aerospace sectors. Job Overview: Nemean Solutions is seeking a Senior Cybersecurity Compliance Lead (FISMA Readiness & Security Architecture) to lead Task 003 Enterprise Vulnerability Management: FISMA Readiness and provide focused support to Task 004.3 Security Architecture and Engineering for the Privacy and Civil Liberties Oversight Board (PCLOB). The position serves as the primary FISMA compliance and risk-management resource while partnering with the Senior Network Administrator, vSOC, Splunk/Cribl Engineer, and PCLOB OCIO stakeholders to translate federal cybersecurity requirements into actionable plans, auditable evidence, technical recommendations, and sustainable operating processes. Support Hours: Applicant shall be available during core work hours as established the Government customer. Essential Duties & Responsibilities: Enterprise Vulnerability Management: FISMA Readiness
- Lead and maintain PCLOB FISMA readiness activities, including system security plans (SSPs), security-control implementation documentation, continuous-monitoring records, risk-management decisions, and supporting evidence.
- Manage Plans of Action and Milestones (POA&Ms), including validation of findings, assignment of corrective actions, milestone tracking, risk acceptance support, and closure documentation.
- Apply the NIST Risk Management Framework and NIST SP 800-53 controls to assess control implementation, identify gaps, document risk, and recommend practical remediation actions.
- Develop and maintain IT security policies, procedures, configurations, risk-management decisions, incident-response documentation, contingency-planning artifacts, and other records required to demonstrate compliance with FISMA, OMB A-130, NIST SP 800-53, NIST SP 800-34 Rev. 1, and agency-specific requirements.
- Coordinate FISMA audit and assessment readiness activities; organize evidence, support annual IG metric responses and CyberScope-ready reporting, respond to assessor requests, track findings, and prepare leadership briefings and corrective-action status reports.
- Analyze vulnerability, configuration, and compliance data from approved security tools and translate results into prioritized remediation plans and trend reporting.
- Research and recommend commercial and government off-the-shelf governance, risk, and compliance tools, including improvements to evidence management, workflow efficiency, and continuous monitoring.
Security Architecture and Engineering Support
- Assess the PCLOB security stack, identify capability gaps and tool overlap, and develop a prioritized roadmap and implementation plan to enhance existing investments and reduce redundancy.
- Review IT security policies with OCIO stakeholders and recommend practical technical solutions for policy enforcement.
- Collaborate with the Senior Network Administrator and other stakeholders on security-engineering deployments and integrated projects, including security architecture, segmentation, identity and access, remote access, configuration management, vulnerability remediation, and monitoring considerations.
- Prepare Security Engineering SME reviews, technical analyses, recommendation memoranda, implementation plans, project milestones, resource considerations, testing approaches, and completion dates.
- Maintain project status, risks, dependencies, milestones, and completion dates for assigned security-engineering activities and provide weekly progress updates, including concerns affecting schedule or completion.
- Provide responsive guidance to PCLOB security and system-administration personnel and participate in integrated engineering, change-management, and risk discussions.
Cross-Task Coordination and Technical Control Support
- Review network and security documentation, architecture diagrams, inventories, configuration records, and proposed changes for compliance, completeness, control impact, and risk.
- Support the Sr. Network Administrator in implementing and documenting FISMA-related technical controls associated with network infrastructure, identity and access, remote access, vulnerability management, monitoring, patch management, and configuration management.
- Coordinate with the vSOC and Splunk/Cribl Engineer to review security-monitoring coverage, data-source visibility, dashboards, alerting, and evidence supporting continuous monitoring and incident response.
- Identify monitoring, evidence, or visibility gaps and recommend priorities to the responsible vSOC or Splunk/Cribl engineering resource.
- Analyze vulnerability, compliance, configuration, and security-monitoring trends to support risk-based recommendations, executive reporting, and continuous improvement.
- Provide security analysis, compliance leadership, and engineering governance. This position complements, but does not replace, hands-on Citrix, Nutanix, routing, switching, Cisco Call Manager, firewall, server, or Splunk/Cribl administration performed by the applicable PWS technical labor categories.
Program Support and Customer Engagement
- Coordinate directly with PCLOB OCIO leadership, system administrators, and other stakeholders to clarify requirements, communicate risk, and drive assigned actions to closure.
- Produce concise, decision-ready briefings, reports, roadmaps, status updates, and technical recommendation packages for Government and Nemean leadership.
- Maintain compliance evidence, action-item logs, risk registers, decision logs, engineering backlogs, and deliverable trackers.
- Participate in recurring status meetings, technical exchanges, audit activities, and incident-response or tabletop exercises as required.
- Perform quality review of cybersecurity compliance and engineering deliverables before submission.
Competencies:
- Excellent verbal and written communication skills.
- Excellent interpersonal and customer service skills.
- Excellent organizational skills and attention to detail.
- Excellent time management skills with a proven ability to meet deadlines.
- Ability to prioritize tasks and to delegate them when appropriate.
- Ability to function well in a high-paced and at times stressful environment.
Requirements
Minimum Requirements/Education:
- Five or more years of progressively responsible federal cybersecurity, FISMA, RMF, information-assurance, ISSO, or security-engineering experience; the PWS minimum for the FISMA Compliance Analyst labor category is three to five years of FISMA security-control validation experience.
- Demonstrated experience with FISMA, NIST SP 800-37, NIST SP 800-53, SSP development and maintenance, POA&M management, continuous monitoring, control assessments, and audit readiness.
- Experience analyzing vulnerability and configuration findings and coordinating remediation with infrastructure, network, system-administration, and security operations teams.
- Strong technical writing, briefing, organization, and customer-engagement skills.
- Current Security+ CE or comparable baseline cybersecurity certification; certification in IT audit, internal controls, risk, or cybersecurity management is strongly preferred.
Security Requirement:
- An active TS / SCI security clearance.
Preferred Requirements:
- CISM, CISSP, CAP/CGRC, or comparable advanced cybersecurity certification.
- Hands-on experience with Xacta, as identified in the PWS, or another federal GRC platform.
- Experience working with Splunk or comparable SIEM platforms, vulnerability scanners, IDS/IPS, firewalls, Active Directory, VPN, Citrix, Windows, Linux, and secure federal enterprise environments.
- Experience supporting federal inspections, independent assessments, authorization activities, incident response, configuration management, and Zero Trust initiatives.
- Bachelor's degree in cybersecurity, information technology, engineering, or a related discipline; relevant experience and certifications may be considered in lieu of a specific degree.
The pay range listed represents a good-faith estimate, in accordance with pay transparency requirements, and may vary depending on the candidate's experience, education, and other job-related factors. What Nemean Solutions, LLC offers: Medical, Dental, and Vision insurance plans, Paid Time Off, sick leave, 401k Retirement Savings plan with company match, and more. Nemean Solutions is proud to be a Veteran friendly employer and provides Equal Employment Opportunity (EEO) to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability status, genetic information, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable federal, state, and local laws. Equal Opportunity for VEVRAA Protected Veterans. Nemean Solutions, LLC will not discriminate against employees and job applicants who inquire about, discuss or disclose compensation information. We are a Virginia Values Veterans (V3) Certified Employer and strongly encourage applications from veterans, transitioning service members, and military spouses.
Salary Description
$150,000 and above
|