Cybersecurity Risk Management Lead

4 days ago


Washington, United States BTI Full time
About the Role

We are seeking a highly skilled Cybersecurity Risk Management Lead to join our team at BTI. As a key member of our organization, you will be responsible for leading our risk management efforts and ensuring the security of our customer's inventory of on-premise, vendor, and cloud-based systems.

Key Responsibilities
  • Manage Information System Security Officers (ISSOs) to support information technology (IT) security goals and objectives and reduce overall organizational risk.
  • Assist in the execution and management of the House Risk Management Framework (RMF) and advise ISSOs on proper application of House cybersecurity policies and requirements.
  • Assist senior management in the development and interpretation of information assurance guidelines, policies, regulations, etc.
  • Advise senior management (e.g., Chief Information Security Officer [CISO]) on risk levels and security posture.
  • Advise appropriate senior leadership or Authorizing Official of changes affecting the organization's cybersecurity posture.
  • Conduct independent or coordinated studies to identify, evaluate, or recommend solutions to significant systems management problems that are likely to be complex and sensitive in nature.
  • Ensure that security improvement actions are evaluated, validated, and implemented as required.
  • Identify alternative information security strategies to address organizational security objectives.
  • Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
  • Participate in information security risk assessments during the Security Assessment and Authorization process.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
  • Provide quality assurance reviews of cybersecurity deliverables to ensure consistency, accuracy, and relevancy.
  • Provide technical and procedural information system advice to risk management team.
  • Perform quality reviews of security artifacts collected by ISSOs under their purview to ensure quality assessment and authorization (A&A) deliverables are provided.
  • Assume ISSO responsibilities in the absence of ISSO.
  • Ensure approved House procedures are followed in the implementation of security controls.
  • Ensure a record is maintained of all vulnerabilities for existing authorization boundaries.
  • Advise ISSOs on all matters, technical and otherwise, involving the security of assigned IT systems.
  • Maintain a working knowledge of system technology, security policies, and security safeguards.
  • Ensure continuous monitoring of authorization boundaries and implemented security controls is followed.
  • Provide guidance to ISSOs on mitigation actions for security control deficiencies and scan vulnerabilities for assigned IT systems.
  • Provide role-based training for assigned ISSOs specific to their roles and responsibilities.
  • Brief senior management on the status of ISSOs and their assigned projects.
  • Work with senior leadership to mature risk management processes within the House environment.
  • Develop and formalize risk management training, specific to the House environment, for varied stakeholder groups.
  • Conduct assigned technical reviews and risk analyses and develop cybersecurity risk mitigation recommendations and strategies based on threats.
  • Research and recommend innovative, secure, and (where possible) automated solutions to improve risk management processes and activities.
  • Participate in the technical security evaluation and assessment of new technologies in support of House of Representatives operations and provide supporting reviews.
  • Provide audit support to cybersecurity for audit activities and recommendations.
  • Perform other duties as assigned.
Requirements
  • Minimum of eight (8) years of demonstrated work experience in cybersecurity risk management.
  • Demonstrated experience managing systems security assessments, reviewing system security documentation for successful security authorization of such systems.
  • Strong knowledge and expertise with NIST publications.
  • Demonstrated experience providing quality A&A deliverables.
  • Proven technical acumen and understanding of common operating systems and network technologies, risk management frameworks, and common security tools and scanners.
  • Demonstrated understanding of cloud service models, hybrid applications, and mobile security technologies and tools.
  • Understanding of management, operational, and technical cybersecurity principles.
  • Experience with privacy principles and frameworks is preferred.


  • Washington, United States BTI Full time

    Business Technology Integrators (BTI) is in search of an Information Systems Security Manager (ISSM) to spearhead a dedicated team focused on implementing risk management strategies for our diverse portfolio of on-premise, vendor, and cloud-based systems.The ideal candidate will be responsible for:Leading Information System Security Officers (ISSO):...


  • Washington, United States BTI Full time

    Business Technology Integrators (BTI) is in search of an Information Systems Security Manager (ISSM) to spearhead a dedicated team focused on implementing risk management strategies across our client's diverse systems, including on-premise, vendor, and cloud-based environments.The ideal candidate will be responsible for:Leading Information System Security...


  • Washington, United States BTI Full time

    Business Technology Integrators (BTI) is in search of an Information Systems Security Manager (ISSM) to oversee a dedicated team focused on implementing risk management strategies for our client's array of on-premise, vendor, and cloud-based systems.The ideal candidate will be responsible for:Leading Information System Security Officers (ISSO): Guide the...


  • Washington, Washington, D.C., United States Gunnison Consulting Group Inc Full time

    About the RoleGunnison Consulting Group Inc is seeking a highly skilled Cybersecurity Risk Management Lead to support a Department of Defense customer. The successful candidate will be responsible for identifying, assessing, and prioritizing computing risks while developing strategies to secure the Agency's systems, networks, and data.Key...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    Opportunity for Navy Cybersecurity Risk Management Lead:Become an integral part of our team as a Navy Cybersecurity Risk Management Lead, where you will significantly contribute to the Navy's efforts in combating cyber threats. We seek a seasoned information security risk expert to aid the Navy in recognizing and alleviating risks linked to their IT...


  • Washington, United States BTI Full time

    Business Technology Integrators (BTI) is in search of an Information Systems Security Manager (ISSM) to oversee a dedicated team focused on implementing risk management strategies for our diverse range of systems, including on-premise, vendor, and cloud-based solutions.The ideal candidate will be responsible for:Leadership: Directing Information System...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    About the Position:We are seeking a dedicated Navy Cybersecurity Risk Management Lead to join our team at Booz Allen Hamilton. In this pivotal role, you will contribute significantly to the Navy's efforts in combating cyber threats. Your expertise in information security risk management will be essential in identifying and addressing vulnerabilities within...


  • Washington, United States Gunnison Consulting Group Inc Full time

    Job DescriptionJob DescriptionGunnison Consulting is seeking a Cybersecurity Risk Assessment Lead to work in the Washington, DC area to support the Department of Health and Human Services' (HHS) cybersecurity mission of ensuring HHS can actively protect the vital health information with which it is entrusted, respond to existing and emerging...


  • Washington, United States BTI Full time

    Business Technology Integrators (BTI) is on the lookout for an Information Systems Security Manager (ISSM) to spearhead a dedicated team focused on implementing risk management strategies across our diverse range of systems, including on-premise, vendor, and cloud-based solutions.The ideal candidate will be responsible for:Leading a team of Information...


  • Washington, United States ASRC Federal Holding Company Full time

    Position Overview ASRC Federal Holding Company is on the lookout for a proficient Cybersecurity Risk Management Specialist to enhance our team. The selected candidate will play a pivotal role in delivering extensive information assurance support and cybersecurity knowledge, with a particular focus on Cybersecurity-Supply Chain Risk Management (SCRM). This...


  • Washington, United States BTI Full time

    Business Technology Integrators (BTI) is in search of an Information Systems Security Manager (ISSM) to spearhead a dedicated team focused on implementing risk management strategies across our client's array of on-premise, vendor, and cloud-based systems.The ideal candidate will provide expertise in the following areas:Team Leadership: Oversee Information...


  • Washington, United States SAIC Full time

    SAIC is seeking a seasoned Cybersecurity Risk Management Specialist to join our dedicated team supporting a significant government entity in the National Capital Region. This role presents an exciting opportunity to collaborate with a team focused on IT Security Governance, Risk Management, and Compliance, providing essential support to the agency's...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Specialist to join our team at Booz Allen Hamilton. As a Cybersecurity Risk Specialist, you will play a critical role in helping our clients understand and mitigate cyber risks.Key ResponsibilitiesConduct risk assessments and develop mitigation plans to help clients understand and manage cyber...


  • Washington, United States Watershed Security Full time

    COMPANY OVERVIEWWatershed Security is a Veteran Owned Small Business and a prominent provider of exceptional Cyber Security Services to the Federal Government. Watershed fosters a dynamic work environment that values challenge and respect.We are experiencing rapid growth and are committed to realizing our vision each day: "To inspire trust and respect with...


  • Washington, Washington, D.C., United States Armada Ltd Full time

    Job DescriptionJob Summary:Armada Ltd is seeking a highly skilled Senior Information Systems Security Officer to join our team. As a key member of our cybersecurity team, you will be responsible for ensuring the security and integrity of our information systems and networks.Key Responsibilities:Security Program Management: Develop, implement, and maintain a...


  • Washington, Washington, D.C., United States MORS Full time

    Head of Cybersecurity Risk Oversight - MORSMORS is in search of an exceptional candidate for the position of Head of Cybersecurity Risk Oversight. This role is integral to our commitment to safeguarding information and ensuring robust security practices.Position Summary:Oversee the formulation, implementation, and management of the organization's...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    About the RoleWe are seeking an experienced Cybersecurity Risk Management Specialist to join our team at Booz Allen Hamilton. As a key member of our team, you will work closely with the Department of Navy (DoN) to identify and mitigate cyber risks, develop mitigation plans, and ensure compliance with Navy Risk Management Framework (RMF) policies.Key...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Specialist to join our team at Booz Allen Hamilton. As a Cybersecurity Risk Specialist, you will play a critical role in helping our clients understand and mitigate cyber risks.Key ResponsibilitiesConduct risk assessments and develop mitigation plans to help our clients protect their...


  • Washington, United States Rividium Full time

    About the RoleRividium is seeking a highly skilled Cybersecurity Manager to join our team. As a key member of our organization, you will be responsible for ensuring the security and integrity of our information systems and networks.Key ResponsibilitiesDevelop and Implement Cybersecurity Strategies: Create and execute comprehensive cybersecurity plans to...


  • Washington, United States Georgetown University Full time

    Georgetown University, situated in a historic area of the nation's capital, is dedicated to providing a rigorous academic environment, a global outlook, and a commitment to social justice. Our community consists of a close-knit group of exceptional individuals who are passionate about intellectual exploration and making a positive impact in the world....