Senior Cybersecurity Engineer - Compliance & Risk Management Job at Human Resources Research Organization, Alexandria, VA

a2Ricy93MmkwZ2lkSHRNY2ZhaFNVMDZCK1E9PQ==
  • Human Resources Research Organization
  • Alexandria, VA

Job Description

Senior Cybersecurity Engineer - Compliance & Risk Management The Human Resources Research Organization (HumRRO) is a non-profit leader in developing high-impact services and products in the arenas of employment, military, student testing, and professional credentialing and licensure. We work with federal and state government agencies, private sector organizations, and professional associations. About the Organization As a non-profit, HumRRO is dedicated to work that contributes to science and society. Our employees enjoy a highly collaborative and supportive environment that fosters innovation, ethical practice, and outstanding customer service. Our core operational staff includes Industrial-Organizational Psychologists, Educational Researchers, and Behavioral Science Consultants. About the Job We are seeking a Senior Cybersecurity Engineer to lead our enterprise compliance and security programs across federal, state, and private sector engagements. This role manages multiple compliance frameworks including CMMC, FedRAMP, SCRM, NIST, and ISO 27001:2022 regulatory requirements. You will work on compliance standards across hybrid cloud environments while leading a team of junior engineers conducting vulnerability assessments and security scanning operations. A significant portion of this role involves creating security documentation, developing compliance policies, responding to time-critical security requirements from clients, and managing third-party compliance audits. As a Senior Cybersecurity Engineer, you will:

  • Lead enterprise cybersecurity compliance programs (CMMC, FedRAMP, SCRM, NIST frameworks, ISO 27001:2022)
  • Manage monthly compliance reporting and KPI dashboards for executive leadership
  • Coordinate third-party compliance audits (NIST, CMMC, ISO 27001, FedRAMP) and remediation activities
  • Maintain compliance evidence catalogs and SaaS compliance implementation controls
  • Evaluate and implement security controls across software applications and cloud platforms AWS, Azure, and Office 365
  • Oversee Risk Management Framework (RMF) processes for government contract organizations as well as applications in the DoD space (ATO/IATT/IATO documentation)
  • Conduct weekly Plan of Action and Milestone (POA&M) reviews and monthly security assessments
  • Develop and maintain security policies, procedures, and technical standards
  • Lead vulnerability management programs & conduct security assessments and penetration testing coordination
  • Manage business continuity of operations (COOP) program including disaster recovery and crisis management plans
  • Lead incident response and security event investigation
  • Mentor and manage junior cybersecurity engineers and analysts
  • Interface with federal agencies, auditors, and compliance assessors
  • Work with system architects for security requirements on existing cloud workloads, cloud migrations and/or hybrid environments
  • Facilitate and oversee completion of all customers' cyber security questionnaires and qualifications with time-critical deadlines
  • Coordinate with HumRRO Contracts Division on written responses to RFPs regarding IT security, controls, data privacy and regulatory compliance
  • Assist with implementation and administration of cybersecurity supply chain risk management (C-SCRM) program
  • Develop compliance documentation and security narratives for proposals
  • Support business development with technical security expertise
  • Serve as subject matter expert on internal security controls and regulations
Minimum Requirements:
  • US Citizen with ability to obtain/maintain security clearance
  • Work on-site at Alexandria VA (Up to 2 remote days possible after 90-day introductory period)
  • Bachelor's degree in Cybersecurity, Computer Science, or equivalent field. Work experience may be considered in lieu of degree
  • 7+ years of cybersecurity engineering and compliance experience
  • 5+ years of enterprise experience managing Risk and Compliance efforts including multiple regulatory and standard security frameworks
  • Existing Security+ certification or the ability to obtain within 6 months (CISSP, CCSP, or CISM preferred)
  • Deep expertise in NIST,, RMF, and DoD compliance frameworks
  • Hands-on experience with CMMC and FedRAMP authorization processes
  • Proficiency in Office 365 security configuration and management
  • Experience with vulnerability scanning tools (e.g. ACAS, Nessus, Rapid7, Qualys or equivalent)
  • Strong analytical and information gathering skills with ability to work multiple tasks simultaneously under short deadlines
  • Excellent communication skills for stakeholder engagement
Preferred:
  • Active DoD clearance
  • Experience in the nonprofit sector managing IT or related activities
  • CMMC Certified Professional (CCP) or CMMC Certified Assessor (CCA)
  • Experience with FedRAMP 3PAO assessments
  • Knowledge of Supply Chain Risk Management (SCRM) frameworks
  • AWS certifications (Solutions Architect, Security Specialty preferred)
  • Experience with DevSecOps pipeline integration and IAC
  • CISSP, CCSP, CISM, or CISSP-ISSAP certifications
  • Knowledge of DoD STIG implementation and automated compliance tools
  • Federal contracting and audit experience
  • Experience with Atlassian suite (Jira, Confluence)
  • Experience with eMASS package development and continuous monitoring activities
  • Experience with STIG implementation and SCAP compliance validation
  • Experience with bi-annual COOP testing and crisis management plan development
  • Leadership experience managing technical teams
  • People Management Experience is a plus
The anticipated salary for this role is $100,000 to $155,000. Specific salary offers are based on candidate qualifications and experience. Benefits:
  • Health, dental and vision insurance
  • Life insurance equal to 2x annual salary
  • Retirement plan with company matching
  • Paid professional development and certification maintenance
  • Tuition reimbursement
  • 12 weeks of paid parental leave
  • Generous paid time off and 10 paid holidays
All qualified applications will receive consideration without regard to race, color, religion, sex, national origin, age, marital status, sexual orientation, veteran status, medical condition, or disability. EEO/Vet/Disabled. Named one of "50 Great Places to Work" by Washingtonian magazine and one of "Top Workplaces" by The Washington Post.

Job Tags

Contract work, Work experience placement, Work at office, Remote work,

Similar Jobs

Staffmark Group

Warehouse Associate Job at Staffmark Group

 ...off, and you can move up. People That Listen. Help That Hits Right. "The staff was friendly and patient with me," -Jorge, Staffmark Associate. Join a Team That Works for You At Staffmark, we're more than just a staffing company-we're your career partner... 

Constellis

Training Manager Job at Constellis

 ...Program Training Manager The Program Training Manager is responsible for developing, implementing, and maintaining a world-class training program that ensures all Security Protective Officers (SPOs) across the contract are fully trained, certified, and qualified in... 

LeaderStat

Licensed Building Engineer Job at LeaderStat

 ...Job Description Licensed Building Engineer Full-Time, Day Shift Location: Baltimore, MD Non-Profit | Award-Winning Multi-Care Center (the area's premier provider of services for older adults) About Us We are an award-winning, non-profit multi-care... 

Manpower

Onsite Supervisor Job at Manpower

Join Our Team at Manpower We're seeking an Onsite Supervisor to support one of our key client locations in Alameda, CA. In this role...  ...the bridge between talent and our client, managing daily HR and staffing responsibilities in a fast-paced manufacturing environment.... 

McCain Foods

Training Manager Job at McCain Foods

 ...Direct message the job poster from McCain Foods Position Title: Training Manager Position Type: Regular - Full-Time Position Location: Easton Requisition ID: 37507 About The Role As a member of the site leadership team, you will work collaboratively...