Risk Management Project Director

2 weeks ago


Washington, United States Gunnison Consulting Group Inc Full time
Job DescriptionJob Description

We are seeking a motivated and customer-oriented professional to support our HHS client.

Location: Remote

Duties and responsibilities include:

  • Provide strategic leadership to the enterprise cybersecurity risk management task area of the Cybersecurity Support Services (CSS) program at the Department of Health and Human Services (HHS).
  • Provide strategic leadership of activities required under Circular A-123, Management Responsibility for Internal Controls, as well as those under the Federal Managers Financial Integrity Act of 1982, improving accountability and effectiveness of federal programs and operations.
  • Manage communication between contract support, federal leads, and the HHS Risk Branch Chief regarding personnel, processes, contract deliverables, etc.
  • Conduct assessments to determine the likelihood and potential impact of identified risks in each program area.
  • Anticipate and identify risks associated with risk program areas, develop and recommend risk mitigation plans to minimize the impact of identified risks, and work with HHS to implement changes to mitigate risks and improve overall HHS risk posture.
  • Work with Risk Team Leads to mature HHS Risk area programs and processes.
  • Provide leadership and guidance to the Risk Team, fostering a culture of risk awareness and accountability.
  • Continuously evaluate and improve HHS' risk management processes, tools, and methodologies based on industry best practices and lessons learned.
  • Ensure that risk management practices comply with relevant regulatory requirements and industry standards.
  • Support additional activities under other task areas of the contract, as directed by the CSS Program Manager.

Required Qualifications:

  • Understanding of risk-related guidance from the National Institute of Standards and Technology (NIST); particularly Special Publication 500, 800, and 1800 series, as well as Interagency or Internal Reports (NISTIRs) and related artifacts.
  • Identifying factors and circumstances that may influence or lead to the formation of risks, issues, and opportunities.
  • Eliciting risks, issues, and opportunities from historical references, technical documentation, business processes, and U.S. Government-approved interview techniques, such as prompt lists and dipstick queries.
  • Experience defining and explaining risks, issues, and opportunities from a:
    • Threat-centric approach.
    • Control-centric approach.
    • Vulnerability-centric approach.
  • Experience performing all steps of the NIST Risk Management Framework (RMF).
  • Experience with both identifying and modeling threats.
  • Excellent verbal and written communication required.

Desired Qualifications:

  • Performing enterprise risk assessments.
  • Performing enterprise risk analyses (qualitative, quantitative, and semi-quantitative).
  • Performing issue and opportunity impact assessments and analyses.
  • Performing privacy threshold assessments (PTAs) and privacy impact analyses (PIAs).
  • Evaluating and comparing mitigations (including cost/benefit and time/resource evaluations).
  • Performing analyses of alternatives (AoAs).
  • Familiarity (prefer experience) with multi-layer and multi-dimensional relationships between specific and enterprise risks, issues, and opportunities, as described in ISO 31000, the 7 imperatives of Continuous Adaptive Risk and Trust Assessment (CARTA), the COSO Cube®, and (ISC)2.
  • Working familiarity with U.S. Government approved mitigation approaches.
  • Experience as an Information System Security Officer (ISSO) and/or a Security Control Assessor (SCA).
  • Performing physical facility risk, issue, and opportunity (RIO) walkthrough inspections.
  • Developing taxonomies to clarify the policy-level relationship between traditional GRC and privacy.
  • Procedure development and process improvement, such as ITIL, Lean, Six Sigma, and CMMI.
  • The following certifications and training are preferred:
    • Project Management Professional (PMP)
    • Certified Risk Manager (CRM) or Certified Risk Management Professional (CRMP)
    • Completion of U.S. Government authorized RMF training, either:
      • Introduction to the RMF, from the Center for Development of Security Excellence (CDSE), Defense Counterintelligence and Security Agency; or
      • RMF for Systems and Organizations Introductory Course - Version 2, from NIST.
    • Certified Authorization Professional (CAP), Certified Information Systems Security Professional (CISSP), and/or Certified Cloud Security Professional (CCSP)

Education Requirement: Bachelor's degree in business administration, Cybersecurity, or related field required

Clearance Requirement: Ability to obtain and maintain a Public Trust.


Why Join Gunnison?

  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Employee Benefits

Gunnison employee benefits meet or beat other companies in the Washington, D.C. metropolitan area, including:

  • Bonuses AND profit-sharing
  • 401k Matching
  • Certifications and training allowance $2,500/year
  • 3 weeks of personal leave your first year (160 hours can roll over every year)
  • 5 days of Flex-Time-Off per year

Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.

In 1994 Gunnison Consulting Group began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.




  • Project Manager

    1 week ago


    Washington, United States Voter Education Project Full time

    STRATEGIES FOR CHANGE GROUP WHO WE ARE: Since 2013, Strategies For Change Group has combined insightful advice with meaningful involvement to effect real change in communities. Our expertise spans business-to-business engagement, phone banking programs, peer-to-peer texting, and canvassing initiatives. As a minority-owned and operated firm, SFCG has engaged...

  • Project Manager

    2 weeks ago


    Washington, United States Voter Education Project Full time

    Job DescriptionJob DescriptionSTRATEGIES FOR CHANGE GROUP WHO WE ARE: Since 2013, Strategies For Change Group has combined insightful advice with meaningful involvement to effect real change in communities. Our expertise spans business-to-business engagement, phone banking programs, peer-to-peer texting, and canvassing initiatives. As a minority-owned and...

  • Project Manager

    2 weeks ago


    Washington, United States Civics Education Project Full time

    Job DescriptionJob DescriptionSTRATEGIES FOR CHANGE GROUP WHO WE ARE: Since 2013, Strategies For Change Group has combined insightful advice with meaningful involvement to effect real change in communities. Our expertise spans business-to-business engagement, phone banking programs, peer-to-peer texting, and canvassing initiatives. As a minority-owned and...


  • Washington, United States Gunnison Consulting Group Inc Full time

    Job DescriptionJob DescriptionGunnison Consulting is seeking a Cybersecurity Risk Assessment Lead to work in the Washington, DC area to support the Department of Health and Human Services' (HHS) cybersecurity mission of ensuring HHS can actively protect the vital health information with which it is entrusted, respond to existing and emerging...


  • Washington, United States Gunnison Consulting Group Inc Full time

    Job DescriptionJob DescriptionGunnison Consulting is seeking a Cybersecurity Risk Assessment Lead to work in the Washington, DC area to support the Department of Health and Human Services' (HHS) cybersecurity mission of ensuring HHS can actively protect the vital health information with which it is entrusted, respond to existing and emerging...

  • Cyber Risk Management Project Manager

    Found in: Talent US C2 - 2 weeks ago


    Washington, United States Gunnison Consulting Group Inc Full time

    Gunnison Consulting is seeking a Cybersecurity Risk Assessment Lead to work in the Washington, DC area to support the Department of Health and Human Services' (HHS) cybersecurity mission of ensuring HHS can actively protect the vital health information with which it is entrusted, respond to existing and emerging cybersecurity threats, and continue to enhance...

  • Remote Director of Project Management

    Found in: Jooble US O C2 - 2 weeks ago


    Washington DC, United States LVI Associates Full time

    We have a current opportunity for a Director of Project Delivery on a permanent basis, that is based in Houston, Texas. As a leading independent power producer, my client is looking to bring on an accomplished and self-motivated director to lead their pre-construction and construction teams in the utility scale solar sector. 10+ years experience within...

  • Risk Management Officer

    Found in: Talent US 2 C2 - 1 week ago


    Washington, United States National Park Service Full time

    Summary This position is located in Visitor and Resource Protection, in the Office of Risk Management Division. The National Park Service's Office of Risk Management (ORM) provides management direction, policy, oversight, and technical assistance for a variety of national programs relating to employee and visitor safety. The Chief, Office of Risk...

  • Project Manager

    1 week ago


    Washington, United States LexisNexis Risk Solutions Group Full time

    ** Project-Program Management Project Manager - Public Safety Service Delivery** * Brand: LexisNexis Risk Solutions * Location: Washington, District of Columbia, United States of America **Job Overview** The Public Safety Service Delivery Project Manager position is within the Government Service Delivery organization. This role provides project management...


  • Washington, United States Council for Affordable Quality Healthcare Full time

    **Position Summary**: The Director, Portfolio Management within the PMO is responsible for managing strategic project portfolios, leading high visibility, enterprise-wide strategic projects, and teams to deliver on key strategic initiatives. This role involves ensuring the successful planning, execution, and delivery of projects, and portfolio management of...

  • Director Cyber Risk Management

    Found in: Jooble US O C2 - 2 weeks ago


    Washington DC, United States Analytic Search Group Full time

    Job Description Growing Cyber Security Services firm and 2023 Top Work Places to Work recipient seeks an experienced Director to lead a segment of the firm's cybersecurity pipeline, from identification/capture through delivery management/oversight. The ideal candidate will have a deep understanding of cybersecurity in the federal sector to include one or...

  • REMOTE Director of Project Management

    Found in: Jooble US O C2 - 2 weeks ago


    Washington DC, United States LVI Associates Full time

    We have a current opportunity for a Director of Project Delivery on a permanent basis, that is based in Houston, Texas. As a leading independent power producer, my client is looking to bring on an accomplished and self-motivated director to lead their pre-construction and construction teams in the utility scale solar sector. Requirements/qualifications ...


  • Washington, United States The Hub Project Full time

    Job DescriptionJob DescriptionCommunications DirectorReports to: Senior Campaign Director Location: Washington, DC (Hybrid)Status: Full-time, ExemptSalary Range: $105k to $125k About The HubLaunched in 2016, The Hub is a nonprofit effort made up of a growing team of communications, research, and organizing experts with extensive experience in campaign...

  • Field Director

    1 week ago


    Washington, United States Voter Education Project Full time

    About Us: Voter Education Project is a dynamic and forward-thinking consulting firm dedicated to driving positive change in our community. We are seeking a motivated and experienced Field Director to oversee and coordinate our grassroots organizing efforts. As a Field Director, you will play a pivotal role in mobilizing supporters, building strategic...

  • IT Project Manager

    Found in: Talent US 2 C2 - 1 week ago


    Washington, United States Federal Emergency Management Agency Full time

    Summary This position is within the DHS, FEMA, Office of Response and Recovery, Logistics Management Directorate, Logistics Systems Division, Information Tech Support Branch located in Washington DC. The ideal candidate for this position will be a expert on providing technical advice, guidance, and recommendations to management and other technical...

  • Enterprise MF Risk

    7 days ago


    washington, United States Fannie Mae Full time

    Job Description As a valued colleague on our team, you will contribute to assessing and identifying potential risks that may threaten our reputation, safety, security, and/or financial success, as well as collaborate with team in communicating and collaborating with key stakeholders across the enterprise, and understanding business objectivesTHE IMPACT YOU...

  • Senior Risk Management Analyst

    Found in: beBee jobs US - 4 days ago


    Washington, Washington, D.C., United States ASRC Federal Holding Company Full time

    ASRC Federal AFSS is a premier provider of systems engineering, software engineering, system integration and project management services for real-time, mission-critical defense systems. We are seeking a Senior Risk Management Analyst to support a NASA contract in Greenbelt, MD.Responsibilities:Seeking an experienced senior-level Risk Management Analyst to...

  • Senior Risk Management Analyst

    Found in: beBee S US - 4 days ago


    Washington, United States ASRC Federal Holding Company Full time

    ASRC Federal AFSS is a premier provider of systems engineering, software engineering, system integration and project management services for real-time, mission-critical defense systems. We are seeking a Senior Risk Management Analyst to support a NASA contract in Greenbelt, MD. Responsibilities: Seeking an experienced senior-level Risk Management...


  • Washington, United States SAIC Full time

    Job ID: 2405870 **Location**:WASHINGTON, DC, US **Date Posted**:2024-04-24 **Category**:Program Management **Subcategory**:Project Analyst **Schedule**:Full-time **Shift**:Day Job **Travel**:No **Minimum Clearance Required**:None **Clearance Level Must Be Able to Obtain**:Public Trust **Potential for Remote Work**:No **Description** Our team is...

  • Field Director

    2 weeks ago


    Washington, United States Voter Education Project Full time

    Job DescriptionJob DescriptionAbout Us: Voter Education Project is a dynamic and forward-thinking consulting firm dedicated to driving positive change in our community. We are seeking a motivated and experienced Field Director to oversee and coordinate our grassroots organizing efforts. As a Field Director, you will play a pivotal role in mobilizing...