×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Officer

Job in Rockville, Montgomery County, Maryland, 20847, USA
Listing for: eSimplicity Inc.
Full Time position
Listed on 2026-10-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

Description

About Us:

eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow.

Purpose of Scope:

The Senior Information Security Analyst will provide security compliance, risk management, vulnerability management, audit, and

continuous monitoring support for a Centers for Medicare & Medicaid Services (CMS) program. This role requires extensive

knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS Acceptable Risk Safeguards (ARS).

The analyst will independently develop and maintain detailed security control implementation statements, evaluate supporting

evidence, conduct Security Impact Analyses, support Authorization to Operate activities, and prepare systems for security

assessments and audits. The analyst will also manage vulnerability and compliance findings throughout their lifecycle, including

validation, remediation coordination, POA&M management, risk exception development, retesting, and closure.

This position will work closely with CMS ISSOs, product owners, engineers, infrastructure teams, security assessors, auditors, and

program leadership. The successful candidate must be able to produce accurate, audit-ready security documentation, identify

compliance gaps, communicate security risks clearly, and drive assigned activities to completion with minimal supervision.

Responsibilities:
  • Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership.
  • Interpret FISMA, NIST RMF, NIST SP 800-53, CMS ARS, and agency security requirements and translate them into clear technical and operational actions.
  • Develop, review, and maintain detailed security control implementation statements that accurately reflect the system environment, responsible parties, processes, technologies, and supporting evidence.
  • Maintain and support ATO artifacts, including System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related documentation.
  • Lead Security Impact Analyses for proposed system, application, infrastructure, cloud, data, and configuration changes.
  • Support security assessments and audits by coordinating evidence collection, reviewing artifacts, responding to assessor inquiries, documenting gaps, and tracking corrective actions through closure.
  • Review vulnerability and compliance scan results; validate findings; assess risk; and coordinate remediation with product, engineering, infrastructure, and Dev Sec Ops  teams.
  • Develop and review vulnerability documentation, remediation plans, POA&Ms, false-positive determinations, and risk exception requests to ensure they are complete, accurate, and appropriately supported.
  • Track vulnerability and compliance findings through assignment, remediation, mitigation, risk acceptance, retesting, and closure.
  • Support continuous monitoring activities, access reviews, security data calls, compliance reporting, and security posture assessments.
  • Identify control, evidence, and documentation gaps and recommend corrective actions or process improvements to reduce security risk.
  • Develop security metrics, dashboards, status reports, and risk summaries for government stakeholders and program leadership.
  • Maintain timely and accurate communication regarding security risks, decisions, dependencies, overdue actions, and remediation status.
  • Mentor security team members and perform quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables.
Requirements
  • Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles, with demonstrated technical depth and increasing responsibility.
  • A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline.
  • Demonstrated experience supporting federal systems subject to FISMA and the NIST Risk Management Framework.
  • Experience applying NIST SP 800-53 security and privacy controls and CMS ARS or comparable federal security requirements.
  • Demonstrated…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary