Similar Jobs
See allIT Security Analyst
Rubris
US
IT Security
NIST
SOC 2
Lead IT Security Administrator
Jobgether
Global
NIST
FedRAMP
HIPAA
Security and Compliance Engineer
Jobgether
Global
Cloud Security
FedRAMP
Risk Management
Cybersecurity Engineer (Remote)
GovCIO
US
RMF
NIST
Security
Cloud Security Engineer
Knox
US
Cloud Security
DevSecOps
FedRAMP
What You'll Do:
- Lead the end-to-end Certification & Authorization (C&A) process for information systems, including initial assessment, remediation, documentation, and ongoing monitoring.
- Maintain and update System Security Plans (SSPs), POA&Ms, and other FedRAMP/GovRAMP/NIST documentation artifacts.
- Oversee control gap analysis and drive remediation efforts across technical and administrative domains.
About You:
- Deep understanding of NIST SP 800-53 Rev 5, FedRAMP/ GovRAMP Moderate/High baselines, and CSF 2.0, and RMF 2.0 (Risk Management Framework).
- Experience with System Security Plans (SSPs), and POA&M management.
- Familiarity with cloud security architectures and FedRAMP-authorized cloud service providers (AWS, Azure).
Required Skills:
- Hands-on experience with tools such as: Tenable/Nessus, (vulnerability scanning) (XSIAM/Cortex, Sentinel 1, or other SIEM platforms, STIG Viewer, SCAP tools, and FedRAMP templates, ServiceNow or similar ticketing/change management systems)
- Minimum 5–7 years of experience in cybersecurity governance, risk, and compliance roles.
- Strong project management and organizational skills; able to manage multiple concurrent initiatives.
EBSCO Information Services
EBSCO Information Services (EBSCO) delivers a fully optimized research experience, seamlessly integrated with a powerful discovery platform to support the information needs of our end-users. Headquartered in Ipswich, MA, EBSCO employs more than 2,700 people worldwide, with most embracing hybrid or remote work models.