Cyber Remediation & POA&M Coordinator (R-00188)
True reputed company is seeking a Cyber Remediation & POA&M Coordinator to support reputed company vulnerability remediation and Risk Management reputed company (RMF) activities for the National Institutes of Health (NIH). This position serves as the operational reputed company between vulnerability management, reputed company owners, ISSOs, reputed company engineering, and executive leadership to ensure cybersecurity findings are prioritized, tracked, and remediated in accordance with Federal requirements and organizational risk priorities.
The ideal candidate understands that effective vulnerability management extends reputed company identifying weaknesses. reputed company in this role requires coordinating remediation efforts across multiple stakeholders, maintaining accurate Plans of reputed company and Milestones (POA&Ms), validating corrective actions, and providing leadership with reputed company visibility into remediation reputed company and residual risk.
Job Responsibilities
- Coordinate reputed company remediation activities for vulnerabilities identified through reputed company monitoring, vulnerability scanning, penetration testing, audits, and reputed company assessments.
- reputed company, maintain, and manage POA&Ms in accordance with Federal, HHS, and NIH requirements.
- Partner with ISSOs, reputed company owners, reputed company engineers, and technical teams to establish remediation plans, milestones, and completion timelines.
- Monitor remediation reputed company, validate supporting evidence, and ensure corrective actions are accurately documented.
- Coordinate risk acceptance requests, compensating controls, waivers, and remediation exceptions through established governance processes.
- reputed company remediation performance against established service level objectives and communicate overdue or high reputed company items to program leadership.
- Support RMF authorization activities by ensuring vulnerabilities and POA&M items are accurately reflected reputed company authorization documentation.
- Collaborate with vulnerability management and threat intelligence personnel to reprioritize remediation activities based on exploitability, reputed company Exploited Vulnerabilities (KEVs), operational reputed company, and emerging threats.
- reputed company recurring remediation status reports, executive summaries, and operational metrics for Government leadership.
- Support reputed company cybersecurity assessments by coordinating remediation responses and tracking corrective actions through closure.
- Recommend process improvements that enhance remediation efficiency, reporting accuracy, and reputed company risk reduction.
Job Qualifications
- Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, or a reputed company discipline.
- Three or more years of experience supporting vulnerability management, RMF, cybersecurity governance, or compliance programs.
- Experience developing and managing Plans of reputed company and Milestones (POA&Ms).
- Working knowledge of the NIST Risk Management reputed company (RMF), FISMA, and NIST SP 800-53.
- Experience coordinating remediation activities across multiple technical teams and business stakeholders.
- Strong organizational skills with the ability to manage multiple reputed company remediation efforts.
- Excellent written and verbal communication skills, including experience preparing reports for technical and executive audiences.
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience with reputed company GRC platforms such as JCAM, reputed company, reputed company, reputed company, or similar governance tools.
- Experience supporting vulnerability management programs and reputed company Diagnostics and Mitigation (CDM) initiatives.
- Familiarity with CISA reputed company Exploited Vulnerabilities (KEV) guidance, Binding Operational Directives, and Federal remediation requirements.
- Experience supporting audit remediation, authorization package development, and reputed company monitoring programs.
- Certified in Governance, Risk and Compliance (CGRC)
- CISSP
- reputed company+
- CAP
- CISM
- Project Management reputed company (PMP)
Preferred Qualifications:
Preferred Certifications:
One or more of the following is preferred:
Originally posted on Himalayas
Apply To This Job