Jobs
>
Raleigh

    Cyber Risk Management Lead - Raleigh, United States - Phia

    Phia
    Default job background
    Description
    phia, LLC


    At phia, trust us to solve the complex challenges of our connected world through top-tier cyber intelligence & threat hunting.

    Contact us.

    View company page


    At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients.

    phia is seeking a Cyber Risk Management Lead to provide IT/cybersecurity risk management and project management expertise for a Federal program.

    This security program provides cyber risk management, information system security continuous monitoring, Information Systems Security Officer (ISSO), and IT/cyber privacy support that balances business needs with security risks while ensuring compliance with Federal regulations.

    This will be a hybrid role reporting on-site with some capability to telework.

    The qualified individual will ideally be in Lakewood, CO (Denver metro area)/ Washington, DC, or the Reston, VA area (DC/MD/VA metro area).

    applicants may also be considered. While this opportunity is contingent upon contract award, that doesn't mean we can't start a conversation now What You'll Do

    Serve as the central point of contact to the customer and coordinate between personnel in all task areas within the program (i.e. Risk Management and Information Security Continuous Monitoring (ISCM), Information System Security Officers and System Security, and the PrivacyOffice).

    Provide technical and operational subject matter expertise in cyber risk management, the Risk Management Framework (RMF), OMB and FISMA guidance and mandates, NIST Special Publications, the Federal Risk and Authorization Management Program (FedRAMP), and program and project management involving Federal and Commercial shared services.

    Perform project management activities, including creating and updating project plans and actions, coordinating and tracking activities, and providing status reports.

    Shall be responsible for submitting all reports and deliverables.
    Shall be responsible for responding to all Government inquiries within timeframes based on criticality labels.
    Develop and conduct Risk Management Framework (RMF) briefings for existing information systems requiring Authorization to Operate (ATO) renewals.

    Prepare Security Impact Assessments (SIA's) to determine if proposed changes to information systems warrant new Assessment & Authorization (A&A) packages.

    Establish advanced analytics to enable dashboarding capabilities for monitoring and governance of systems.
    Provide Continuous Monitoring reporting based on the organization's Continuous Diagnostic and Mitigation (CDM) program.
    Perform control assessments and documentation updates for the supported systems.
    Maintain Interconnection Security Agreements (ISA) for information systems connecting to external entities.
    Maintain Plans of Action and Milestones (POA&Ms) in GRC tools and systems of record (e.g. Xacta), including creating, monitoring, closing, and reporting.
    Coordinate Incident Response


    with Information Systems Security Managers (ISSMs) and System Owners (SO) to include all associated actions necessary to mitigate the risk to unit systems.

    Support risk analysis and approval process for deviation/exemption requests to organization-wide Web Filtering, SSL Inspection, Data Loss Prevention (DLP), and IT Configuration Management policies for perimeter network devices and defense capabilities.

    Provide recommendations for updates and support review and approval processes for organization Standard Technical Implementation Guides (STIG) for commonly sure software across the agency (i.e., Windows Desktop/Server, Web Browsers, Databases).

    Provide technical writing support for formal documentation reports, training materials, slide decks, and architecture diagrams.
    Education + Requirements

    19 years of relevant experience, or
    AA/AS +17 years of relevant experience, or
    BA/BS +15 years of relevant experience, or
    MA/MS +13 years of relevant experience
    Significant expertise, deep knowledge, and practical experience with:

    Risk Management Framework (RMF)
    NIST Special Publications (800 series)
    FedRAMP / Cloud Service Providers (CSPs) - auditing, compliance, risk, assessment, etc.
    Federal Continuous Diagnostics and Mitigation (CDM) program structure, component tools/capabilities, and requirements
    Xacta Risk Management Platform (Xacta 360 / ),
    Vulnerability Scanning/Assessment tool data/outputs (e.g. Tenable/Nessus),
    Web Application Scanning/Assessment tool data/outputs (e.g. Accunetix),
    Cloud services/platform compliance and assessment tools (i.e. Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP)),
    Splunk and/or Elastic for reviewing federal Continuous Diagnostics and Mitigation (CDM) program datasets (e.g. BigFix/HCL, Microsoft Defender for Endpoint, etc.)
    Preferred Certifications


    PMP

    CISSP
    CCSP, CIPP, CAP, CASP / GSLC / CISM/CSM, or other industry-standard security certifications
    Security Clearance

    U.S. citizenship
    Ability to achieve Public Trust or higher government clearance.
    #LI-LC1
    Who You AreA proactive problem solver that appreciates the challenges of working in a fast-paced, dynamic environment.
    Intellectually curious with a genuine desire to learn and advance your career.
    An effective communicator, both verbally and in writing.
    Customer service-oriented and mission-focused.

    Critical thinker with excellent problem-solving skillsIf your experience and qualifications aren't a match for this position, you will remain in our database for consideration for future opportunities that may be a better fit.

    Who We Arephia, LLC is a Northern Virginia-based, small business established in 2011 with a focus on Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, and Information Assurance/Security.

    we proudly support various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial values work-life balance and offers the following benefits to full-time employees:Comprehensive medical insurance to include dental and visionShort Term & Long-Term Disability401k Retirement Savings Plan with Company MatchTuition and Professional Development AssistanceFlex Spending Accounts (FSA)

    phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity, or any other reason prohibited by law in the provision of employment opportunities and benefits.

    Explore more InfoSec / Cybersecurity career opportunities


    Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

    #J-18808-Ljbffr


  • IXL Learning Raleigh, United States

    IXL Learning, a leading EdTech company with products used by 15 million students worldwide, is seeking a Lead Account Manager to join our growing team in Raleigh, NC. · The Lead Account Manager will serve in a leadership role on the Account Management team, managing a team of · ...


  • AdvisorEngine Raleigh, United States Full time

    Who we are: · We believe that the future of financial advice is personal, scientific and beautiful - these three ideals drive everything that we do. · AdvisorEngine is a leading wealth management fintech platform that creates a unified experience across financial advisors, inve ...

  • IXL Learning

    Lead Account Manager

    2 weeks ago


    IXL Learning Raleigh, United States

    IXL Learning, a leading EdTech company with products used by 15 million students worldwide, is seeking a Lead Account Manager to join our growing team in Raleigh, NC. The Lead Account Manager will serve in a leadership role on the Account Management team, managing a team of Accou ...


  • insightsoftware Raleigh, United States

    Company Description · insightsoftware · is a leading provider of reporting, analytics, and performance management solutions. Over 30,000 organizations worldwide rely on us to support business needs in the areas of accounting, finance, operations, supply chain, tax, budgeting, p ...

  • insightsoftware

    Lead Project Manager

    2 weeks ago


    insightsoftware Raleigh, United States

    Company Description · insightsoftware is a leading provider of reporting, analytics, and performance management solutions. Over 30,000 organizations worldwide rely on us to support business needs in the areas of accounting, finance, operations, supply chain, tax, budgeting, plan ...

  • Lumen Inc

    lead project manager

    2 weeks ago


    Lumen Inc Raleigh, United States

    About Lumen · Lumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People po ...


  • IXL Learning Raleigh, United States Regular, Full time

    IXL Learning, a leading EdTech company with products used by 15 million students worldwide, is seeking a Lead Account Manager to join our growing team in Raleigh, NC. The Lead Account Manager will serve in a leadership role on the Account Management team, managing a team of Accou ...


  • Leaf International LLC Raleigh, United States

    Reporting To: Marketing Director · Location: REMOTE · Department: Marketing · Role Overview: · As the Marketing Manager for Lead Generation within our Marketing team, you will be responsible for driving Leaf's demand generation and inbound strategy. You will define and assess ...


  • insightsoftware Raleigh, United States

    Company Description · insightsoftware is a leading provider of reporting, analytics, and performance management solutions. Over 30,000 organizations worldwide rely on us to support business needs in the areas of accounting, finance, operations, supply chain, tax, budgeting, plan ...


  • LanceSoft Raleigh, United States

    Typical Experience: 48-60 monthsIT Vendor Management Specialist Lead - Contract Development and Compliance Job Description Key Responsibilities As a member of the DHB Contract Management and Procurements Unit, work includes consulting with DHB leadership, business owners, and oth ...


  • Cloud Software Group, Inc. Raleigh, United States

    Do you thrive in a startup vibe? Were you built for a small, nimble and dynamic team that's ready to win? If you answered yes, we want to talk to you We are now going back to our roots as a standalone business unit to focus on our SaaS business-an area where we see growth potenti ...


  • Technology , Inc. Raleigh, United States

    We are looking for an experienced Senior Product Manager to join our team and lead the development of Managed Services to build a Google Cloud Practice. RapidScale, a leader in Managed Cloud Services has a established Public Cloud presence in AWS, Azure, Private Cloud is now look ...


  • WakeMed Raleigh, United States

    Job Description · About WakeMed: · Serving the community since 1961, WakeMed Health & Hospitals is a nationally recognized, private, not-for-profit health care organization founded and based in Raleigh, N.C. The largest health system in Wake County, WakeMed exists to improve the ...


  • LanceSoft Raleigh, United States

    Typical Experience: 48-60 months · IT Vendor Management Specialist Lead - Contract Development and Compliance Job Description · Key Responsibilities · As a member of the DHB Contract Management and Procurements Unit, work includes consulting with DHB leadership, business owner ...


  • S&P Global Raleigh, United States

    About the Role: · Grade Level (for internal use): · 12 · About the Role · The Team · With a plethora of technologies running on a multitude of platforms across traditional datacentres to cloud-native you will be exposed to it all. You will be part of a specialist team respons ...


  • insightsoftware Raleigh, United States

    Job Description · Job DescriptionCompany Description · insightsoftware is a leading provider of reporting, analytics, and performance management solutions. Over 30,000 organizations worldwide rely on us to support business needs in the areas of accounting, finance, operations, su ...

  • Actalent

    Senior Lab Analyst

    1 day ago


    Actalent Raleigh, United States Full time

    The Analytical Method Lifecycle High Level Associate will support the overall management and delivery of phase appropriate analytical method verification/qualification/validation and method transfer between stakeholders of our client and their customers. The Method Lifecycle Anal ...


  • Renaissance Raleigh North Hills Hotel Raleigh, United States

    **Description**: · We are hiring for an experience **Banquet Manager** · We are looking for someone that have a passion to serve others Our events at our hotel provide great exposure of our venue for receptions, meetings, trainings and even reunions. It's our place to really shin ...


  • North Carolina Dept of Natural and Cultural Resources Wake County, NC, United States

    **Description of Work**: · **This is a reposted vacancy announcement.** · **Previous applicants MUST REAPPLY in order to be considered.** · ** ** · **Recruitment Range: $34,936 - $52,415** · **_This position will be located at:_** · **11 W. Jones Street** · **Raleigh, NC 27601** ...


  • Zachry Construction Corporation Raleigh, United States

    Extraordinary commitment runs deep at Zachry. Here, dedicated men and women have the opportunity to work on challenging projects alongside those who value innovation and support team efforts in all our endeavors. We take care of our team members as family, within a culture of ser ...