Cybersecurity Risk Advisor

ASSYST

Baltimore (MD)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
401(k)
Disability insurance
Flexible spending accounts

Job summary

ASSYST is seeking a Cybersecurity Risk Advisor to support federal cybersecurity programs. The role focuses on evaluating risk posture, RMF expertise, and guiding stakeholders on actions for risk reduction, with emphasis on PII/PHI handling and regulatory alignment.

The ideal candidate will have over a decade of experience in information security programs, a strong RMF background, and the ability to communicate complex risk to executive leadership.

Qualifications

  • 10+ years of professional experience developing information security and risk management programs per frameworks and standards (FISMA, NIST, HIPAA).
  • Proven ability to evaluate risk posture for multiple systems and communicate executive-level findings.
  • Strong understanding of RMF, ATO processes, and security controls implementation.

Responsibilities

  • Evaluate and communicate risk posture of each system to executive leadership and make risk-based recommendations.
  • Ensure risk management framework requirements are implemented and enforced across systems.
  • Verify information security testing within the SDLC and apply results to development.
  • Review security artifacts and provide recommendations to improve posture.
  • Approve selected system configuration deviations from the baseline as the authority.
  • Coordinate with ISSO and PII/PHI data owners to classify information and ensure legal authority.
  • Determine privacy impacts and manage information security and privacy risk.

Skills

RMF knowledge
FISMA experience
NIST SP 800-series
Risk assessment
Stakeholder communication
MS Office

Education

Bachelor's degree in Computer Science, Information Technology, Cyber Security, or related field
CISSP
CISM

Job description

ASSYST is seeking a Cybersecurity Risk Advisor to support federal Cybersecurity program.

The Cybersecurity Risk Advisor will be responsible for evaluating, maintaining, and communicating the risk posture of each FISMA system to executive leadership and making risk-based recommendations. They will act as the subject matter expert in all areas of the Risk Management Framework (RMF) and provide guidance to stakeholders on required actions, strategies, and best practices for closure of identified weaknesses.

Responsibilities
  • Support stakeholders in ensuring that all requirements specified by the Acceptable Risk Safeguards and the procedures and standards of the risk management framework are implemented and enforced
  • Ensure information security and privacy testing is performed throughout the SDLC as appropriate, and results are considered during the development phase of the SDLC
  • Monitor system security posture by reviewing all proposed information security and privacy artifacts to provide recommendations to the ISSO
  • Provide guidance to stakeholders on required actions, strategies, and best practices for closure of identified weaknesses
  • Serve as the authority to approve selected system configuration deviations from the required baseline
  • Coordinate with the point of contact, including ISSO, for each FISMA system or collection of Personally Identifiable Information (PII)/Protected Health Information (PHI) to identify the types of information processed, assign appropriate security categorizations to information systems, ensure legal authority for activities involving PII/PHI.
  • Determine privacy impacts and manage information security and privacy risk
Job Requirements
  • Bachelor's degree in Computer Science, Information Technology, Cyber Security, or related field
  • CISSP, CISM, or other relevant certifications preferred
  • 10+ years of professional experience developing and implementing information security/assurance programs, policies, processes, and procedures per various security frameworks/laws/standards/directives, e.g. FISMA; OMB directives; Presidential Directives; NIST (SP-800 series; FIPS); HIPAA of 1996; Privacy Act
  • Comprehensive knowledge of the FISMA, HIPAA laws and Privacy Act of 1974
  • In-depth knowledge of the NIST SP 800 series documents, especially 800-34, 37,39 47, 53, 53A, 60, 63, 64, 137 and FIPS 140, 199, 200 and 201
  • In-depth knowledge of the 800‑53 security control requirements and standard methods for implementing them
  • Practical knowledge of IT System contingency planning
  • Understanding of risk assessment and risk management concepts
  • Good understanding of continuous monitoring and continuous authorization concepts
  • Good understanding of the protection of PII and PIA concepts
  • Expert use of MS Office, especially Word, PowerPoint, and Outlook
ASSYST Benefits

We are proud to offer a robust benefits package including medical, dental, vision, 401(k) retirement plan, disability insurance, flexible spending accounts and more in order for our employees to maintain a secure work/life balance.

ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Risk Advisor
Cybersecurity Risk Advisor

ASSYST, Inc. • Baltimore (MD)

On-site
USD 140,000 - 190,000
Medical benefits
Dental benefits
Vision benefits
+3
Security & Compliance Analyst
Security & Compliance Analyst

ASSYST • Sterling (VA)

On-site
USD 70,000 - 110,000
Medical benefits
Dental benefits
Vision benefits
+3
Security & Compliance Analyst
Security & Compliance Analyst

ASSYST, Inc. • Washington

On-site
USD 70,000 - 90,000
medical
dental
vision
+3
Security & Compliance Analyst
Security & Compliance Analyst

ASSYST, Inc. • Sterling (VA)

On-site
USD 65,000 - 95,000
medical
dental
vision
+3
Senior Cybersecurity Risk Advisor (RMF/FISMA Expert)
Senior Cybersecurity Risk Advisor (RMF/FISMA Expert)

ASSYST • Baltimore (MD)

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+3
Senior Cybersecurity Risk Advisor - RMF & FISMA Expert
Senior Cybersecurity Risk Advisor - RMF & FISMA Expert

ASSYST, Inc. • Baltimore (MD)

On-site
USD 140,000 - 190,000
Medical benefits
Dental benefits
Vision benefits
+3
Security & Compliance Analyst
Security & Compliance Analyst

Socket.dev • Sterling (VA)

On-site
USD 70,000 - 95,000
Medical benefits
Dental benefits
Vision benefits
+3
Audit Specialist – Cyber Security (Mid-Level)
Audit Specialist – Cyber Security (Mid-Level)

ASSYST, Inc. • Baltimore (MD)

On-site
USD 80,000 - 110,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ASSYST • Maryland

On-site
USD 120,000 - 160,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ASSYST • Baltimore (MD)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+3