Risk Manager
2 weeks ago
OverviewCVP is seeking a Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency’s CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks.ResponsibilitiesIdentify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency.Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency’s Information Security Program related to governance, optimizations, automation, and supporting tools.Develop an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37 (Risk Management Framework for Information Systems and Organizations) and SP 800-39 (Managing Information Security Risk).Conduct an enterprise risk assessment and develop an agency Information Security Risk Assessment Report addressing all findings.Develop an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the Risk Assessment Report.Develop an agency Information Security Risk Management Plan covering risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities.Provide risk management guidance to agency offices for A&A activities, ensuring continuous risk monitoring of information security control implementation and required compliance.Support the Information Security and Assurance Office (ISAO) in implementing and overseeing information security risk management and security assessment and authorization (A&A) activities.Advise on tailoring the revised A&A process for non-traditional technologies (e.g., cloud, mobile, Internet of Things).Provide recommendations on continuous monitoring and assessment of security posture and alert decision makers to increased risk or imminent threats.Develop guidance, templates, tools, and advice to program offices to support their risk management and ATO activities.Provide risk management and continuous monitoring program implementation recommendations to program offices.Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify risk areas due to unimplemented POA&Ms or cross-cutting issues.Track A&A status for divisions and programs to ensure protection of agency data and operations.Develop artifacts to complete security accreditation packages for OCIO information systems and provide oversight and advisory support for A&A package completion.Follow NIST FIPS and SPs (e.g., FIPS 199/200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, SP 800-18) and comply with agency IT security and Privacy policies, including PIA requirements and templates.QualificationsMinimum of six years’ experience in cybersecurity; 10+ years’ experience preferred.Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies; seven+ years’ experience preferred.Shall have at least one of the following industry-recognized certifications:Certified Information System Security Professional (CISSP)Certified Information Systems Auditor (CISA)Certified Information Security Manager (CISM)Certified in Risk and Information Systems Control (CRISC)Familiarity with ITIL Foundation, GRC tools, continuous monitoring, and vulnerability management tools (NIH currently uses CSAM).Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks.Proven experience bringing innovative approaches to reduce FISMA workload and time to authorization/reauthorization (e.g., boundary consolidation, common control reuse, automation, assessment readiness, digital transformation).Desired SkillsPMP CertificationCISSP CertificationExperience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)NIH/HHS experienceLocationRockville, MD (Hybrid)Salary$130-140k (Depending on experience)About CVPCVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associates. We are committed to maintaining a workplace where everyone can grow both personally and professionally. #J-18808-Ljbffr
-
Risk Manager
4 weeks ago
Rockville, United States Customer Value Partners Full timeOverview CVP is seeking an Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance...
-
Manager, Probabilistic Risk Assessment
3 weeks ago
Rockville, United States X-energy Full timeJoin to apply for the Manager, Probabilistic Risk Assessment role at X-energy 3 weeks ago Be among the first 25 applicants Join to apply for the Manager, Probabilistic Risk Assessment role at X-energy X-energy LLC conducts a thorough recruiting process and will never issue offers without interview to discuss qualifications and responsibilities. All...
-
Manager, Probabilistic Risk Assessment
3 weeks ago
Rockville, United States X Energy, LLC Full timeX-energy LLC conducts a thorough recruiting process and will never issue offers without interview to discuss qualifications and responsibilities. All applications will be submitted via our company career page, www.x-energy.com/careers/. We will never ask you to provide payment information as part of the recruiting process. If anyone claiming to represent...
-
Enterprise Risk Management Tutor
3 weeks ago
Rockville, United States Varsity Tutors, a Nerdy Company Full timeJoin to apply for the Enterprise Risk Management Tutor role at Varsity Tutors, a Nerdy Company The Varsity Tutors Live Learning Platform has thousands of students looking for online Enterprise Risk Management tutors nationally. As a tutor on the Varsity Tutors Platform, you’ll have the flexibility to set your own schedule, earn competitive rates, and make...
-
Manager, Probabilistic Risk Assessment
2 days ago
Rockville, MD, United States X Energy, LLC Full timeX-energy LLC conducts a thorough recruiting process and will never issue offers without interview to discuss qualifications and responsibilities. All applications will be submitted via our company career page, www.x-energy.com/careers/. We will never ask you to provide payment information as part of the recruiting process. If anyone claiming to represent...
-
Senior Safety
2 weeks ago
Rockville, United States City of Rockville Full timeA local government agency is seeking a Safety Manager to oversee occupational safety and health management programs. Responsibilities include risk assessments, claims investigations, and safety training for employees. The ideal candidate will have a relevant Bachelor's degree and at least five years of experience in safety or risk management. This full-time...
-
Rockville, United States Customer Value Partners, Inc. Full timeA leading technology consulting firm is seeking a Cybersecurity Risk Manager for a government agency. The role focuses on managing cybersecurity risks, developing strategies, and ensuring compliance with security policies. Ideal candidates will have over six years of cybersecurity experience and relevant certifications. The position offers an attractive...
-
Information Security Risk Assessor
4 weeks ago
Rockville, United States Cyquent Full timeInformation Security Risk Assessor Onsite in Rockville, MD Scope of Work The Cyber Security Risk Analyst will support Governance, Risk, and Compliance (GRC) efforts by performing detailed risk evaluations and compliance assessments. The analyst will work primarily within the ServiceNow GRC platform to review IT security policy exception requests, assess...
-
Program Manager III, Medicare Risk Adjustment
3 weeks ago
Rockville, United States Kaiser Permanente Full timeProgram Manager III, Medicare Risk Adjustment & Chart ReviewThe Program Manager III for Risk Adjustment and Chart Review is responsible for overseeing the accuracy and efficiency of risk adjustment processes and retrospective chart reviews. They will support the management and oversight of internal and vendor chart retrieval operations, including performance...
-
Cybersecurity Risk and Compliance Analyst
1 week ago
Rockville, MD, United States E-talentnetwork Full timeJob Profile Summary The Cybersecurity Risk Analyst is responsible for supporting and advancing the organization's Governance, Risk, and Compliance (GRC) functions. This role helps ensure regulatory compliance, strengthens the overall security posture, and drives risk management initiatives across systems, networks, and third-party vendors. The Analyst works...