hirly

LOGC2

Risk Governance and POA&M SME

Springfield, VA

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at LOGC2 first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Stated salary
$110,000 per year
Country
US
Work mode
Remote-friendly
First seen by hirly
1 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Description

Contingent on Contract Award

National Capital Region (Hybrid On-site/Telework if approved)

Connected Logistics is seeking a Risk Governance and POA&M SME to assist in providing the Department of State Directorate of Technology (DT), Enterprise Architecture (EA), Cyber Security Team (CST) comprehensive cybersecurity support services to protect critical consular systems and data. The CST Cyber portfolio ensures compliance with federal mandates including the Federal Information Security Modernization Act (FISMA) and the Risk Management Framework (RMF), encompassing security monitoring, incident response, threat detection, vulnerability management, and continuous authorization activities.

The Risk Governance and POA&M SME will support assigned IASS personnel and RMF Leads in translating control deficiencies, vulnerability findings, and operational issues into defensible risk records and achievable remediation plans. Government officials retain risk-acceptance and authorization authority.

Key Responsibilities:

Responsible for consistent risk characterization, POA&M development, remediation tracking, closure-evidence review, and portfolio risk analysis across RMF delivery teams.

  • Review findings for control mapping, risk rationale, system applicability, residual exposure, and remediation priority.
  • Support POA&M development with accountable owners, realistic milestones, dependencies, and required closure evidence.
  • Track overdue, stalled, recurring, and cross-system findings and recommend escalation to the ISSO Lead.
  • Review closure packages for technical sufficiency and traceability before the applicable validation or approval process.
  • Develop risk-response recommendations and supporting risk-acceptance materials for Government consideration.
  • Analyze portfolio trends and support authorization briefings, audits, and reporting without altering independent assessor conclusions.

Requirements

  • U.S. citizenship and a final Secret clearance or higher
  • Relevant degree in cybersecurity, computer science, information systems, or a related discipline, subject to the LCAT and permitted substitutions.
  • Senior-level Federal cybersecurity risk and POA&M management experience spanning authorization and continuous monitoring.
  • Strong understanding of NIST controls, vulnerability prioritization, remediation planning, residual risk, and evidence-backed closure.
  • Ability to produce clear technical risk analysis and executive summaries.
  • Meet applicable LCAT certification requirements and maintain required credentials.

Preferred Qualifications

  • CGRC, CRISC, CISSP, or CISM.
  • DOS ArchAngel and authorization risk-briefing experience.
  • Experience analyzing KEV/BOD actions, inherited-control risks, and cross-system remediation dependencies.

Success in this position will be demonstrated by consistent risk records, achievable POA&M milestones, defensible closure packages, and timely visibility into material portfolio risks.

Total Rewards Statement

We believe in fairness and clarity throughout our hiring process. The anticipated salary range for this position is $110,000.00-$120,000.00 USD. This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly.

Beyond salary, we provide a robust benefits package and encourage ongoing professional development, because your growth and well-being matter to us. We’re excited to support you in building a rewarding career with us!

Connected Logistics respects the need for confidentiality for all applicants.

Connected Logistics has been named a 2026 WTOP Top Workplace in the medium sized business category. Our mission is clear: we deliver mission-focused IT, cybersecurity, logistics, and enterprise modernization support to federal agencies. When we invest in our people and create an environment where they feel valued and empowered, we deliver stronger outcomes for our clients and the missions we support.

Connected Logistics offers an excellent benefits package that includes health, dental, vision, life, and disability insurance, a great 401(k) package, and generous Paid Time Off.

EOE/Disability/Veterans

Original posting on LOGC2's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job