Security Compliance Manager

Found in: Talent US C2 - 3 weeks ago


Baltimore, United States GDIT Full time
Job Description:

General Dynamics Information Technology (GDIT) is seeking a Security Manager who is innovative, dedicated, and highly motivated to lead our security team in solving challenging problems for our client, the Division of Federal Systems (DFS) for the Office of Child Support Services (OCSS).

Our team provides program support to DFS OCSS to manage and monitor the development, implementation, operation, maintenance, technical support, and enhancement of the division’s systems and services. Federal Parent Locator Service (FPLS) information is, by statute, made available to child support agencies and a limited number of federal and state agencies. These secure systems and services help child support agencies, employers, insurers, and financial institutions exchange information about child support cases; locate parents; establish paternity, custody and visitation; collect support; and identify fraud.

Currently, this role is remote. Once COVID restrictions are lifted, the work location for this position is the Department of Health and Human Services Mary Switzer Building near Federal Center Southwest in Washington, D.C.

The ideal candidate enjoys managing a team and will find satisfying the challenges and opportunities provided by a fast-paced, customer-oriented environment.  If you want to work with a dynamic group of dedicated, technical professionals on a collaborative team that supports a critical mission, we encourage you to apply. 

Responsibilities:
  • Manage and lead security team to ensuring all security tasks and deliverables are completed on time.
  • Lead security team meetings and represent security in Governance, Technical Operations, Change Advisory Board, and Technical Review Boards.
  • Develop and enforce security policies and procedures in compliance with Federal mandates, OMB, NIST guidelines, HHS/ACF, and FPLS security requirements.
  • Act as a Subject Matter Expert (SME) on application, network security, and emerging security technologies.

Security Task includes:

  • Federal System Compliance: Serve as the subject matter expert on federal security compliance regulations, including but not limited to ZTA, Supply Chain NIST, FedRAMP, FISMA, and OMB guidelines. 
    • Evaluate security controls implement by O&M security team to ensure compliance with federal guidelines and safeguard sensitive data and systems.
    • Provide guidance to the design and development teams to ensure compliance with Federal mandates, OMB and NIST guidelines, Health and Human Services (HHS), Administration for Children and Families (ACF) and Federal Parent Locator Service (FPLS) security requirements.
    • Provide guidance to the design and development teams on security issues and assist as needed in the development of security documentation for Security Authorization.
    • Participate in the continuous monitoring of FPLS systems and applications in support of the security authorization process through system development life cycle, risk assessments, vulnerability testing, inventory and configuration audits, technical and physical assessments, and development of security documentation. 
    • Support the Office of Child Support Enforcement (OCSE) management, the ACF CISO, ACF Cyber Security Office, and HHS Chief Information Security Officer (CISO) to ensure FPLS compliance with ACF and HHS security requirements.
    • Assist the FPLS ISSO, FPLS ITSSO and Technical Manager to ensure that FPLS upholds all security requirements to maintain the ACF Authority to Operate.
       
  • System Risk Assessment: Conduct comprehensive risk assessments of system portfolio to identify potential vulnerabilities and weaknesses in the organization's security posture.
    • Participate in routine and on-demand system and application vulnerability scanning, document findings and recommendations, and present analysis of results to stakeholders. 
    • Document and track internal POAMs for DFS systems and applications.
    • Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs.

  • Audits & Compliance: Plan and execute regular audits to assess compliance with federal security standards and regulatory requirements.
    • Support the Security Team in responding to external audits conducted by the HHS Inspector General (IG), Internal Revenue Service (IRS) and other Federal agencies as required. 
    • Assess security events to determine impact and implements corrective actions. Conduct research pertaining to the latest security vulnerabilities. and the latest technological advances in combating unauthorized access to information.
    • Support systems security evaluations, audits, and reviews. Develop systems security contingency plans and disaster recovery procedures.
    • Participate in conducting security site assessments on data matching partner sites and FPLS contractor sites.
    • Security Site Assessments: Actively participate in security site assessments conducted on data-matching partner sites and FPLS contractor sites. This includes planning, reviewing relevant documents, writing comprehensive reports, and reviewing/responding to Plans of Action and Milestones (POAMs).
    • POAM Creation and Tracking: Create and maintain a system to track POAMs after each audit, ensuring that all identified security gaps and issues are properly documented and addressed within specified timelines.
    • Questionnaire Review: Review questionnaires submitted by our matching partners to assess their adherence to security controls and requirements. Conduct kickoff meetings and virtual audits to validate the implementation of appropriate security measures.
    • Security Control Monitoring: Continuously monitor the implementation of security controls by collaborating with stakeholders and conducting regular audits. Identify any deviations or vulnerabilities and recommend corrective actions as needed.

  • Security Awareness Training: Develop and deliver training programs to educate employees on federal security compliance requirements and best practices.
    • Assist in the development and delivery of Security Awareness Training as required.
    • Promote awareness of security issues among management and ensures sound security principles are reflected in organizations’ visions and goals.
       
  • Stakeholder Communication: Communicate effectively with various stakeholders, including senior management, IT teams, legal teams, and external auditors, to convey compliance issues, risks, and remediation plans. Support the client in publishing security alerts, advisories, and bulletins.
     
  • Industry Knowledge: Stay abreast of emerging trends, technologies, and regulatory changes in the federal security compliance landscape and provide recommendations for adapting policies and procedures accordingly.
  • Documentation: Maintain accurate and up-to-date documentation of compliance activities, audit findings, and remediation efforts. Proficiency or familiarity with project management tools, particularly Jira, is preferred. The ability to effectively utilize Jira for task tracking, issue management, and collaboration is highly desirable.

Required Skills:

  • Bachelor's degree in Computer Science, Information Systems, or in a related field. Relevant certifications (e.g., CISSP, CISM, CRISC) are highly desirable. AWS Certified Security Specialty is a plus.
  • Minimum of 5 years of experience working as a Federal Security Compliance Analyst with at least 3 years in a managerial role.
  • 2 years security compliance experience NIST, FedRAMP, FISMA, OMB, ZTA, Supply Chain knowledge.
  • 5 Years of experience handling sensitive data sources and distribution of data containing personally identifiable information related to a Federal system.

Desired Skills:

  • Exceptional leadership and Managerial skills
  • Excellent verbal and written communication skills, with the ability to effectively communicate complex security concepts to both technical and non-technical stakeholders.
  • Strong analytical and problem-solving skills to identify compliance risks, evaluate controls, and recommend effective solutions.
  • Meticulous attention to detail and the ability to maintain accurate and thorough documentation.
  • Proven ability to work collaboratively in a team environment and establish positive relationships with cross-functional teams. Ability to adapt quickly to changing priorities, regulations, and compliance requirements.
  • Relevant security certifications (e.g., CISSP, CISM, CISA) are highly desirable.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Remote

Work Location:

USA MD Baltimore


  • Security Guard

    6 days ago


    Baltimore, United States DMAC Security Full time

    Specific Duties and Functions - Perform Security patrols of assigned areas on foot or vehicles - Watch for irregular or unusual conditions that may create security concerns or safety hazards - Sound alarms or calls police or fire department in case of fire or presence of unauthorized persons - Warn violators of rule infractions, such as loitering, smoking or...


  • Baltimore, Maryland, United States State of Maryland - COMP Compliance Division Full time

    Introduction\r\rOPEN TO ALL QUALIFIED APPLICANTS\r�\rThis is a position specific recruitment. The resulting certified eligible list may be used to staff several current and future vacancies for this position/function only.\r\r\r*REPOST* - Previous Applicants DO NOT Need to Re-Apply\r\r�\r\r GRADE14\r\r LOCATION OF POSITIONBaltimore, Maryland\r POSITION...

  • Mid Security Engineer

    Found in: Talent US C2 - 2 weeks ago


    Baltimore, United States Iron Vine Security Full time

    Position Title: Mid-Level Security Engineer Location: Woodlawn MD Hours: 9 am – 5pm Position Summary: Iron Vine Security is a rapidly growing information security and information technology company in Washington, DC. We are looking for a dynamic Infrastructure Security Engineer who is proficient in Linux administration (using the CLI) and is...

  • Information Security Manager

    Found in: Talent US A C2 - 15 hours ago


    Baltimore, United States InsideHigherEd Full time

    Responsibilities and DutiesManage the planning, delivery, and support of all privacy, governance, risk, compliance processes, procedures, and technologies such as data usage requests, MPIA requests, privacy data subject access requests, and the GRC application.  Develop and maintain strategies for continuous improvement of privacy operations, risk...

  • Compliance Specialist

    Found in: Appcast Linkedin GBL C2 - 2 days ago


    Baltimore, United States Phyton Talent Advisors Full time

    Our client, a Global Investment Bank, is seeking a Compliance specialist in their Baltimore, MD location: Responsibilities:Develop, maintain or enhance securities licensing processes and proceduresRespond to regulatory and registration requestsSupport process workflows and the systems utilized to associate registered individual'sHandle resolution of...


  • Baltimore, United States Wolf Professional Security LLC Full time

    Job DescriptionJob DescriptionWolf Professional Security is currently interviewing unarmed security officers with storefront experience in the Prince Georges County area. Duties will include working with management and loss prevention employees to deter theft as well as providing good customer service at the entrance of the store. Applicants must have their...

  • Armed Security Guard

    2 weeks ago


    Baltimore, United States Wolf Professional Security LLC Full time

    Job DescriptionJob DescriptionWolf Professional Security is currently interviewing Armed security officers with storefront experience in the Prince Georges County area. Duties will include working with management and loss prevention employees to deter theft as well as providing good customer service at the entrance of the store. Applicants must have their...

  • Unarmed Security Officers

    Found in: Talent US C2 - 2 weeks ago


    Baltimore, United States BTI Security Full time

    Unarmed Security Officers - Various locations within Baltimore, MDUnarmed Security Officers perform a variety of security-related duties depending on the post.Patrolling and monitoring exterior and community areas on-premises.Access control of entrances and exits and departure of employees and visitors.Monitoring surveillance cameras for any disruptions or...

  • Investment Associate

    Found in: beBee S US - 2 weeks ago


    Baltimore, United States Maryland State Retirement Agency Full time

    Introduction The Maryland State Retirement Agency (the "Agency") is the administrator of the Maryland State Retirement and Pension System (the "System"). The System is a multi-employer, public employees' defined benefit retirement system composed of twelve (12) separate retirement and pension systems with additional plan components, covering approximately...


  • Baltimore, United States UMMS Community Impact Grant Program Full time

    Hybrid model consists of 3 days a week in-office, and 2 days from home. Mondays are mandatory in-office at our Linthicum location. First weeks of training are fully on-site. Being among the top 25 employers in the state and recently recognized as America’sBest Large Employer 2021 by Forbes, UMMS brings together a diverse andcollaborative team of innovators...

  • Compliance/Registration Associate

    Found in: Appcast US C2 - 3 days ago


    Baltimore, United States eTeam Infoservices Ltd. Full time

    * DURATION 3 MONTHS *** Hybrid: 3 days on site per week "Since these individuals will be making regulatory filings, we need candidates that can demonstrate aptitude, strong communication and organizational skills, and will embrace the opportunity to learn, while working on a firm-wide initiative. We’ve had several contingents in the past that came...


  • Baltimore, United States Insight Global Full time

    Our client is looking for an electronic security program manager to sit in Windsor Mill, MD. This individual will be responsible for:* Operational Support: Collaborate with the Program Manager to oversee day-to-day service desk operations, ensuring adherence to service level agreements (SLAs) and standards. * Team Management: Assist in leading and mentoring...

  • data security officer

    Found in: beBee jobs US - 3 weeks ago


    Baltimore, Maryland, United States State of Maryland - COMP Compliance Division Full time

    Introduction\r\rOPEN TO ALL QUALIFIED APPLICANTS\r�\rThis is a position specific recruitment. The resulting certified eligible list may be used to staff several current and future vacancies for this position/function only.\r�\r\r\r GRADE13 \r LOCATION OF POSITIONBaltimore, MD\r POSITION DUTIESThe incumbent will be responsible for overseeing the...


  • Baltimore, United States ANGARAI Full time

    Job Description Job Description Job Title: Environmental Compliance Manager - Construction Job Location: Baltimore, MD, USA Last day to apply: 30-Oct-2023 ANGARAI - Project Management firm based out of College Park, MD. ANGARAI is a professional management firm that is driven by excellence. We provide ample opportunities for growth in a challenging, yet...


  • Baltimore, United States ANGARAI Full time

    Job DescriptionJob DescriptionJob Title: Environmental Compliance Manager - ConstructionJob Location: Baltimore, MD, USALast day to apply: 30-Oct-2023ANGARAI - Project Management firm based out of College Park, MD.ANGARAI is a professional management firm that is driven by excellence. We provide ample opportunities for growth in a challenging, yet...


  • Baltimore, United States ANGARAI Full time

    Job DescriptionJob DescriptionJob Title: Environmental Compliance Manager - ConstructionJob Location: Baltimore, MD, USALast day to apply: 30-Oct-2023ANGARAI - Project Management firm based out of College Park, MD.ANGARAI is a professional management firm that is driven by excellence. We provide ample opportunities for growth in a challenging, yet...

  • Security Manager

    2 weeks ago


    Baltimore, United States Chimera Enterprises International Full time

    Description. Chimera Enterprises International is seeking a Security Manager to support the Joint Program Executive Office for Chemical, Biological, Radiological and Nuclear Defense (JPEO- CBRND) JPEO-CBRND Medical Office. The JPEO-CBRND manages our nation’s investments in chemical, biological, radiological, and nuclear defense equipment, and medical...

  • Collection Targeting Compliance Manager 3 with Security Clearance

    Found in: Careerbuilder One Red US C2 - 7 days ago


    Baltimore, MD, United States RealmOne Full time

    Be RESILIENT ! RealmOne was built on the principle that people matter first and foremostWe believe in providing a strong work/life balance by investing in our employees and encouraging professional and personal growthWe do this by offering exceptional benefits, flexible schedules, and the tools necessary to achieve success through paid training, mentoring,...


  • Baltimore, United States Kellton Full time

    Title: Junior Compliance AnalystLocation: Baltimore, MDRemote/Hybrid/Onsite: Hybrid: 3 days on site per weekPosition Type: Contract, possible temp-to-perm.Duration: 12+ monthsRate: $24.00 - $26.00/hr. RESPONSIBILITIES:The position will be responsible for supporting all aspects of the registration and licensing processes to ensure that the regulatory...


  • Baltimore County, United States Latitude, Inc. Full time

    Job DescriptionJob DescriptionAre you a results-driven and detail-oriented professional with a passion for leading complex security system projects? If you excel at managing teams and implementing cutting-edge security solutions, we have an exciting opportunity for you to join our team as a Security System Project Manager!As a Security System Project...