eSimplicity
Information Security Officer
Columbia, MD
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 24 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Description
About Us:
eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow.
Purpose of Scope:
The Senior Information Security Analyst will provide security compliance, risk management, vulnerability management, audit, and
continuous monitoring support for a Centers for Medicare & Medicaid Services (CMS) program. This role requires extensive
knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS Acceptable Risk Safeguards (ARS).
The analyst will independently develop and maintain detailed security control implementation statements, evaluate supporting
evidence, conduct Security Impact Analyses, support Authorization to Operate activities, and prepare systems for security
assessments and audits. The analyst will also manage vulnerability and compliance findings throughout their lifecycle, including
validation, remediation coordination, POA&M management, risk exception development, retesting, and closure.
This position will work closely with CMS ISSOs, product owners, engineers, infrastructure teams, security assessors, auditors, and
program leadership. The successful candidate must be able to produce accurate, audit-ready security documentation, identify
compliance gaps, communicate security risks clearly, and drive assigned activities to completion with minimal supervision.
Responsibilities:
- Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership.
- Interpret FISMA, NIST RMF, NIST SP 800-53, CMS ARS, and agency security requirements and translate them into clear technical and operational actions.
- Develop, review, and maintain detailed security control implementation statements that accurately reflect the system environment, responsible parties, processes, technologies, and supporting evidence.
- Maintain and support ATO artifacts, including System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related documentation.
- Lead Security Impact Analyses for proposed system, application, infrastructure, cloud, data, and configuration changes.
- Support security assessments and audits by coordinating evidence collection, reviewing artifacts, responding to assessor inquiries, documenting gaps, and tracking corrective actions through closure.
- Review vulnerability and compliance scan results; validate findings; assess risk; and coordinate remediation with product, engineering, infrastructure, and DevSecOps teams.
- Develop and review vulnerability documentation, remediation plans, POA&Ms, false-positive determinations, and risk exception requests to ensure they are complete, accurate, and appropriately supported.
- Track vulnerability and compliance findings through assignment, remediation, mitigation, risk acceptance, retesting, and closure.
- Support continuous monitoring activities, access reviews, security data calls, compliance reporting, and security posture assessments.
- Identify control, evidence, and documentation gaps and recommend corrective actions or process improvements to reduce security risk.
- Develop security metrics, dashboards, status reports, and risk summaries for government stakeholders and program leadership.
- Maintain timely and accurate communication regarding security risks, decisions, dependencies, overdue actions, and remediation status.
- Mentor security team members and perform quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables.
Requirements
- Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles, with demonstrated technical depth and increasing responsibility.
- A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline.
- Demonstrated experience supporting federal systems subject to FISMA and the NIST Risk Management Framework.
- Experience applying NIST SP 800-53 security and privacy controls and CMS ARS or comparable federal security requirements.
- Demonstrated experience developing, reviewing, and maintaining detailed, system-specific security control implementation statements and supporting evidence.
- Experience supporting ATO activities and maintaining System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related security artifacts.
- Experience leading or supporting security assessments and audits, including evidence collection, assessor responses, gap identification, corrective action planning, remediation tracking, and closure validation.
- Experience managing vulnerability and compliance findings through validation, assignment, remediation, mitigation, risk acceptance, retesting, and closure.
- Experience with vulnerability and compliance tools such as Tenable, Snyk, AWS Security Hub, AWS Inspector, or comparable platforms.
- Ability to prepare technically supported risk exception requests and vulnerability documentation that includes affected assets, vulnerability-specific risk, compensating controls, mitigation analysis, remediation plans, owners, target dates, and validation methods.
- Demonstrated ability to develop accurate, audit-ready documentation and communicate security requirements, risks, findings, and remediation activities to technical and non-technical stakeholders.
- Demonstrated ability to manage concurrent assignments, meet established deadlines, maintain accurate status reporting, and escalate risks or blockers as appropriate.
- Ability to obtain and maintain a Public Trust clearance and have resided in the United States for at least 3 of the last 5 years.
Desired Qualifications:
- Direct experience supporting CMS systems, CMS security programs, or CMS ATO activities.
- Advanced experience applying CMS ARS 5.0 or later to security control implementation, documentation, assessment, and continuous monitoring activities.
- Demonstrated expertise writing and reviewing security control statements that clearly describe responsible parties, implementation methods, technologies, procedures, frequency, inheritance, and supporting evidence.
- Experience leading control-statement reviews or control-mapping efforts resulting from CMS ARS updates, NIST SP 800-53 revisions, cloud migrations, system modernization, or authorization boundary changes.
- Experience conducting Security Impact Analyses for application, infrastructure, cloud, data, integration, and configuration changes.
- Experience supporting Security Control Assessments, FISMA audits, Office of Inspector General reviews, internal audits, penetration tests, or independent verification and validation activities.
- Experience communicating directly with CMS ISSOs, security assessors, auditors, system owners, and government program leadership.
- Experience securing or assessing AWS cloud environments and reviewing cloud security, access management, logging, monitoring, encryption, and configuration controls.
- Familiarity with DevSecOps, CI/CD pipelines, source-code scanning, software composition analysis, container scanning, and security release reviews. • Experience using Jira, Confluence, and ServiceNow to manage security documentation, vulnerabilities, compliance activities, risks, and corrective actions.
- Experience developing security metrics, dashboards, audit-readiness reports, vulnerability reports, and executive-level risk summar
Similar jobs
- Security Officer/ConciergePMMA · Kirkwood, MO, United StatesFirst seen today
- Security Officer ArmedChoctaw · McAlester, OK, United StatesFirst seen today
- Security Officer - Security PART TIME DAYS 7A-730P- Mullica HillInspira Health · Mullica Hill, NJ, United StatesFirst seen today
- Security Officer 1FMOL Health Career Portal · Baton Rouge, LA, United StatesFirst seen today
- Security Officer - PRNAll Jobs · Clearwater, FL, United StatesFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job