Job Requirements
Remote
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
$130,000 - $140,000
Job Description
Position: Cybersecurity Compliance Manager
Our Value is in our People:
Praeses will allow you to work with cutting-edge technology alongside some of the brightest people in the industry. Every employee here has a voice in what we do and how we do it, and we are all passionate about our work. We believe in collaboration and creating an open platform to share ideas. We are focused on your success and provide an environment designed to foster personal and professional growth. Our benefits are competitive, and our culture makes this both a fun and rewarding place to be.
About the position:
The Compliance Manager (CM) will have responsibilities within Praeses’ Government Programs group as well as activities supporting Praeses’ IT division. The CM will effectively communicate security information to customers and internal resources and will utilize technical skills to respond to threats and emergency security incidents in a timely manner and in line with customer and internal processes and procedures.
Listed below is an outline of the major duties and responsibilities that you will be expected to perform in this role:
• Lead Risk Management Framework (RMF) activities supporting new and existing IATT, ATO, and ATC packages
• Perform necessary RMF activities to maintain the system’s ATO/ATC posture in good standing during the course of the effort
• Develop and maintain RMF documentation including SSPs, SARs, POA&Ms, Security Controls Traceability Matrices, and supporting artifacts.
• Occasional work on-site at government customer facilities gathering requirements, information, and reviewing documentation.
• Implement Security Technical Information Guide (STIG) requirements and guide others to implement them
• Support internal IT CMCC and NIST compliance and certification functions.
• Interpret CMMC requirements and advise leadership on compliance obligations
• Ensure continued CMMC compliance through periodic self-assessments
• Manage multiple compliance projects simultaneously
• Develop organizational cyber security policies, both for federal government programs and for internal company efforts.
• Work within Governance Risk and Compliance (GRC) platform to maintain and establish compliance with new frameworks.
• Support audits and security assessments
• Provide Recommendations and Input on Security Practices and Technologies needed to continue to automate and improve the DevSecOps pipeline to minimize effort required to maintain ATO and Authorization to Connect (ATC)
• Work as needed with Cloud One and other network security specialists and engineers regarding ATO/ATC documentation requests
• Lead internal and external personnel through new and ongoing compliance
• Provide status updates, attend status calls and participate in internal project reviews (via teleconference)
• Contribute to proposals and requests for proposals (to subcontractors) to more effectively document company RMF requirements and support needs.
• Handle routine, daily administrative tasks such as reporting and keeping open lines of communication with Praeses’ appropriate divisions.
• Travel expectations for this position: Up to 25%
Required Experience and Qualifications:
• Bachelor’s degree in Computer Science, IT, Systems Engineering or similar field – experience in lieu of degree will be considered
• 5 - 7 years in a Cyber Security Engineer, Compliance Engineer, or Compliance Manager role
• 2 + years experience obtaining or managing ATO
• Experience with Risk Management Framework (RMF) and federal Authority to Operate (ATO) process
• Currently hold Secret DoD security clearance, or be willing and able to obtain one, with the company’s assistance.
Preferred Additional Experience and Qualifications:
• CISSP (or equivalent) certification
• CAP or CCP certification
• CompTIA Security+ Certification.
What will set you apart:
• Willingness to learn about new technologies
• Motivated by solving challenging problems and continuously learning
• Work well in a dynamic developmental environment
About Praeses:
Praeses is a family-owned, privately held software company located in Shreveport, LA. Since its founding more than 35 years ago, Praeses has developed products and associated services for private industry as well as federal, state, and local government with solutions that specialize in data fusion and visualization. The company solves complex problems through expert software development and a laser focus on customer needs and is growing at a rapid pace. Today, Praeses’ products are utilized by customers across the country and our employee footprint of talented individuals extends from coast to coast.
Praeses provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Our Value is in our People:
Praeses will allow you to work with cutting-edge technology alongside some of the brightest people in the industry. Every employee here has a voice in what we do and how we do it, and we are all passionate about our work. We believe in collaboration and creating an open platform to share ideas. We are focused on your success and provide an environment designed to foster personal and professional growth. Our benefits are competitive, and our culture makes this both a fun and rewarding place to be.
About the position:
The Compliance Manager (CM) will have responsibilities within Praeses’ Government Programs group as well as activities supporting Praeses’ IT division. The CM will effectively communicate security information to customers and internal resources and will utilize technical skills to respond to threats and emergency security incidents in a timely manner and in line with customer and internal processes and procedures.
Listed below is an outline of the major duties and responsibilities that you will be expected to perform in this role:
• Lead Risk Management Framework (RMF) activities supporting new and existing IATT, ATO, and ATC packages
• Perform necessary RMF activities to maintain the system’s ATO/ATC posture in good standing during the course of the effort
• Develop and maintain RMF documentation including SSPs, SARs, POA&Ms, Security Controls Traceability Matrices, and supporting artifacts.
• Occasional work on-site at government customer facilities gathering requirements, information, and reviewing documentation.
• Implement Security Technical Information Guide (STIG) requirements and guide others to implement them
• Support internal IT CMCC and NIST compliance and certification functions.
• Interpret CMMC requirements and advise leadership on compliance obligations
• Ensure continued CMMC compliance through periodic self-assessments
• Manage multiple compliance projects simultaneously
• Develop organizational cyber security policies, both for federal government programs and for internal company efforts.
• Work within Governance Risk and Compliance (GRC) platform to maintain and establish compliance with new frameworks.
• Support audits and security assessments
• Provide Recommendations and Input on Security Practices and Technologies needed to continue to automate and improve the DevSecOps pipeline to minimize effort required to maintain ATO and Authorization to Connect (ATC)
• Work as needed with Cloud One and other network security specialists and engineers regarding ATO/ATC documentation requests
• Lead internal and external personnel through new and ongoing compliance
• Provide status updates, attend status calls and participate in internal project reviews (via teleconference)
• Contribute to proposals and requests for proposals (to subcontractors) to more effectively document company RMF requirements and support needs.
• Handle routine, daily administrative tasks such as reporting and keeping open lines of communication with Praeses’ appropriate divisions.
• Travel expectations for this position: Up to 25%
Required Experience and Qualifications:
• Bachelor’s degree in Computer Science, IT, Systems Engineering or similar field – experience in lieu of degree will be considered
• 5 - 7 years in a Cyber Security Engineer, Compliance Engineer, or Compliance Manager role
• 2 + years experience obtaining or managing ATO
• Experience with Risk Management Framework (RMF) and federal Authority to Operate (ATO) process
• Currently hold Secret DoD security clearance, or be willing and able to obtain one, with the company’s assistance.
Preferred Additional Experience and Qualifications:
• CISSP (or equivalent) certification
• CAP or CCP certification
• CompTIA Security+ Certification.
What will set you apart:
• Willingness to learn about new technologies
• Motivated by solving challenging problems and continuously learning
• Work well in a dynamic developmental environment
About Praeses:
Praeses is a family-owned, privately held software company located in Shreveport, LA. Since its founding more than 35 years ago, Praeses has developed products and associated services for private industry as well as federal, state, and local government with solutions that specialize in data fusion and visualization. The company solves complex problems through expert software development and a laser focus on customer needs and is growing at a rapid pace. Today, Praeses’ products are utilized by customers across the country and our employee footprint of talented individuals extends from coast to coast.
Praeses provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
group id: 50013799