Information Security Compliance Specialist

2 hours ago


Rockville, Maryland, United States Axle Full time
Job Title: Information Security Compliance Engineer

Axle is a leading bioscience and information technology company that offers cutting-edge advancements in translational research, biomedical informatics, and data science applications to research centers and healthcare organizations nationally and abroad.

We are seeking a highly skilled Information Security Compliance Engineer to join our vibrant team at the National Institutes of Health (NIH) supporting the National Center for Advancing Translational Sciences (NCATS) located in Rockville, MD.

Job Summary

The successful candidate will support the NCATS Cybersecurity Services (CSS) team in implementing the NIST 800-53 security controls and assist the infrastructure, platform, and application teams with technical security support.

Key Responsibilities
  • Manage daily Cybersecurity Operational activities.
  • Proactively manage Cybersecurity Operations projects and tasks and ensure on-time delivery.
  • Take initiatives to identify, analyze, and remediate weaknesses and present reports to the management.
  • Lead and mentor the NCATS CSS Cybersecurity Operations team.
  • Represent the NCATS CSS team and provide technical security guidance in troubleshooting calls.
  • Have hands-on experience with firewalls, load balancers, switches, routers, Windows, and Linux/Unix servers.
  • Have an expert understanding of TCP/IP and networking principles.
  • Take the lead on securing NCATS systems and applications through system hardening.
  • Secure DevOps pipelines by providing technical security guidance and support to the application and infrastructure teams.
  • Lead the security operations in proactively managing threats, vulnerabilities, and remediation efforts.
  • Familiar with Risk Management Framework (RMF), NIST 800-53, and other Government mandates.
  • Lead NCATS Cybersecurity ATO preparations efforts to follow the Risk Management Framework (RMF).
  • Have a solid understanding of the ATO preparation and security controls implementation process.
  • Lead ATO technical guidance efforts and help write documents such as System Security Plans (SSPs).
  • Schedule and coordinate operational activities, sessions, and meetings with stakeholders.
  • Provide security controls implementation guidance.
  • Provide effective guidance to stakeholders on secure baseline configurations.
  • Manage work through tools such as NIH incident response (IRT) portal, Splunk, ServiceNow, Jira, Confluence, etc.
  • Establish communications with vendors for the release of newly identified vulnerabilities and to ensure they understand the specialized requirements of the client's information systems.
  • Develop daily, weekly, and annual NCATS security landscape metrics.
  • Help the Vulnerability Management team to identify, analyze, and develop mitigation or remediation actions for system and network vulnerabilities.
Requirements
  • Hands-on Linux/Unix experience and knowledge of how to secure systems.
  • Understanding of how to implement security controls based on NIST 800-53.
  • Ability to conduct and lead technical reviews and analysis with infrastructure and application teams.
  • Ability to troubleshoot security incidents and lead other technical teams to resolve incidents and remediate threats and concerns.
  • Ability to provide guidance on security control implementation and perform technical tasks when needed for Windows, Linux/Unix environments.
  • Familiarity with networking and other infrastructure components such as traffic flow, access management, and Active Directory, etc.
  • Ability to manage cyber risks by providing guidance to secure system designs, baseline configuration assistance, and administer ATO preparation activities.
  • Ability to manage and administer security tools and have hands-on working experience with Tenable Nessus, Netsparker, Trellix suite, Palo Alto, BigFix, Splunk, etc., and cloud-based equivalents.
  • Experience with DevOps security controls implementation.
  • Familiarity with GitHub, Docker, and in general, with the CI/CD pipeline security.
  • Assist in security incident response efforts.
  • Work with other teams to integrate the NCATS Threat and Vulnerability Management processes with the patching cycles, baseline configurations, and CIS benchmarks.
  • Familiarity with database server architecture and ability to provide security support to the database team.
  • Familiarity with Cloud environments and tools.
  • Familiarity with Risk Management Framework (RMF) and Government mandates such as continuous diagnostic mitigation (CDM) and Binding operations directives (BODs).
  • Identify, analyze, and develop mitigation or remediation actions for POA&Ms.
  • Assist with a reliable patch and compliance management mechanism for all on-premises and cloud systems.
  • Recommend, configure, and install advanced firewalls and centrally manage other security tools in multiple cloud environments.
Preferred Qualifications
  • BS degree in computer science, computer engineering, information systems, privacy engineering, or related field of study.
  • Bachelor's degree in a relevant technical discipline and 4+ years of overall related IT security compliance experience. 5+ years of additional related years of experience is accepted in lieu of a degree.
  • Experience working with NIST 800-53 series guidance.
  • Familiarity with Windows/Unix/Linux platforms.
  • Familiarity with DevOps pipelines, code scanning, penetration testing, etc.
  • Experience in security compliance documentations such as SARS, Waivers, Contingency and Incident Response plans, etc.

Axle is an equal opportunity employer and welcomes applications from diverse candidates. If you need an accommodation as part of the employment process, please contact careers@axleinfo.com.

Salary Range: $150,000—$160,000 USD



  • Rockville, Maryland, United States Axle Full time

    Job DescriptionJob Summary:Axle is seeking a highly skilled Information Security Compliance Engineer to join our team. The successful candidate will be responsible for ensuring the security and compliance of our systems and infrastructure.Key Responsibilities:Implement and maintain security controls based on NIST 800-53 guidelines.Conduct regular security...


  • Rockville, Maryland, United States Hendall Inc Full time

    Job OverviewPOSITION SUMMARYHendall Inc. is looking for a dedicated full-time Information Security Officer to enhance our robust security framework.This role will provide critical support to the Health & Human Services (HHS) and the Centers for Medicare & Medicaid Services (CMS), which are committed to promoting health equity, increasing coverage, and...


  • Rockville, Maryland, United States Hendall Inc Full time

    Job OverviewPOSITION SUMMARYHendall Inc. is in search of a dedicated Systems Security Officer to enhance our security framework.This role is crucial in supporting the Health & Human Services (HHS) and the Centers for Medicare & Medicaid Services (CMS), which are committed to promoting health equity, increasing coverage, and enhancing health outcomes for the...


  • Rockville, Maryland, United States General Dynamics Information Technology Full time

    Job Summary:We are seeking a highly skilled Senior Cloud Security Engineer to join our team at General Dynamics Information Technology. As a Senior Cloud Security Engineer, you will be responsible for designing, deploying, operating, and maintaining secure Cloud products and services within a Cloud-based environment.Key Responsibilities:Collaborate with...


  • Rockville, Maryland, United States Cherokee Federal Full time

    {"title": "Privacy and Security Program Lead", "description": "Job SummaryCherokee Federal is seeking a highly skilled Privacy and Security Program Lead to join our team. As a trusted partner for more than 60 federal clients, we are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and...


  • Rockville, Maryland, United States General Dynamics Information Technology Full time

    Job Summary:We are seeking a highly skilled Senior Cloud Security Engineer to join our team at General Dynamics Information Technology. As a Senior Cloud Security Engineer, you will be responsible for designing, deploying, operating, and maintaining secure Cloud products and services within a Cloud-based environment.Key Responsibilities:Collaborate with...


  • Rockville, Maryland, United States General Dynamics Information Technology Full time

    Job Summary:We are seeking a highly skilled Senior Software Engineer to join our team at General Dynamics Information Technology. As a Senior Software Engineer, you will be responsible for designing, deploying, operating, and maintaining secure Cloud products and services within a Cloud-based environment.Key Responsibilities:Collaborate with a team of...


  • Rockville, Maryland, United States TM ASSOCIATES MANAGEMENT INC Full time

    Job OverviewTM Associates Management Inc. is seeking a highly skilled Compliance Community Support Specialist to join our team. As a Compliance Community Support Specialist, you will play a critical role in ensuring the accuracy and completeness of certification files for all Move Ins, Annual Certifications, and Interim Certifications for the properties...


  • Rockville, Maryland, United States Axle Full time

    Job Title: Information SpecialistWe are seeking a highly skilled and detail-oriented Information Specialist to join our team at Axle, a bioscience and information technology company. The successful candidate will be responsible for managing and disseminating information, conducting research, and providing support to internal teams and external...


  • Rockville, Maryland, United States TBWA\Chiat\Day Full time

    About the RoleAxle is a leading bioscience and information technology company that offers cutting-edge advancements in translational research, biomedical informatics, and data science applications to research centers and healthcare organizations nationally and abroad.We are seeking a highly skilled Sr. Information Specialist to join our vibrant team at the...

  • Security Officer

    2 weeks ago


    Rockville, Maryland, United States BTI Security Full time

    Job Title: Unarmed Security OfficerJob Summary:BTI Security is seeking a highly skilled and experienced Unarmed Security Officer to join our team. As a Security Officer, you will be responsible for ensuring the safety and security of our clients and their properties.Key Responsibilities:Provide security services to clients, including patrolling premises and...

  • Security Professional

    4 weeks ago


    Rockville, Maryland, United States BTI Security Full time

    **Job Overview**BTI Security is committed to hiring top-notch security professionals who can help us achieve our goal of providing exceptional security services. Our industry-low turnover rate is a testament to our ability to attract and retain quality employees.**Key Responsibilities**As a Security Professional with BTI Security, you will be responsible for...


  • Rockville, Maryland, United States TM ASSOCIATES MANAGEMENT INC Full time

    Job OverviewThe Regulatory Compliance Support Specialist plays a crucial role in managing the documentation for all Move Ins, Annual Certifications, and Interim Certifications within the designated portfolio.Key Responsibilities:Conduct thorough file reviews to ensure compliance with regulatory standards.Input and verify data accurately in the certification...


  • Rockville, Maryland, United States Leidos Full time

    Cyber Security SpecialistWe are seeking a highly skilled Cyber Security Specialist to support multiple US Navy programs in Bethesda, MD. This role will involve maintaining physical and IT security in cleared areas, conducting security education and training, and preparing visit requests for program personnel.Key Responsibilities:Maintain physical and IT...


  • Rockville, Maryland, United States Dine Development Corporation Full time

    Job Summary:Diné Development Corporation (DDC) is seeking a highly skilled Information Systems Security Officer (ISSO) to support the U.S. Department of Commerce (DOC) National Oceanic and Atmospheric Administration (NOAA) Office of the Chief Information Officer (OCIO). As an ISSO, you will be responsible for providing full-spectrum Security Systems...


  • Rockville, Maryland, United States Artech Information System LLC Full time

    Job DescriptionArtech Information System LLC is seeking a skilled Documentation Specialist to join our team. As a key member of our organization, you will be responsible for creating and maintaining high-quality documentation to ensure compliance with regulatory requirements.Key Responsibilities:Develop and maintain technical documentation, including SOPs,...


  • Rockville, Maryland, United States Hendall Inc Full time

    Job OverviewPOSITION SUMMARYHendall Inc. is in search of a dedicated full-time Cybersecurity Compliance Officer to enhance our innovative workforce.This role will be pivotal in supporting the Health & Human Services (HHS) and the Centers for Medicare & Medicaid Services (CMS), committed to serving the community as a reliable partner and steward, focused on...


  • Rockville, Maryland, United States Artech Information System LLC Full time

    Job DescriptionArtech Information System LLC is seeking a skilled Documentation Specialist II to join our team.Key Responsibilities:Track and review change control documentation to ensure compliance with regulatory requirements.Assist with editing quality documents (SOPs, guidelines, validation master plans, etc.) to ensure accuracy and adherence to company...


  • Rockville, Maryland, United States TM ASSOCIATES MANAGEMENT INC Full time

    Job OverviewThis role is responsible for handling file reviews for Move Ins, Annual Certifications, and Interim Certifications for properties within an assigned portfolio. The specialist will verify and enter data into certifications, secure verifications, and prepare files for execution. Additionally, they will provide responses to State and Investor audits...

  • Security Officer

    3 weeks ago


    Rockville, Maryland, United States Hendall Inc. Full time

    OverviewHendall Inc. is seeking a full-time Systems Security Officer to support the Health & Human Services (HHS), Centers for Medicare & Medicaid Services (CMS) team.Key ResponsibilitiesOversee and verify security posture and policy for various projects, collaborating with Admins and DevOps to ensure environments are appropriately secured.Develop...