A leading security solutions provider based in Austin, Texas, is seeking a seasoned professional to lead end-to-end SSP/SSPP development and manage compliance efforts. The ideal candidate will have over 12 years of experience in GRC, enterprise security architecture, and cloud security, with a strong command of NIST standards. This role involves translating vulnerabilities into actionable plans and ensuring audit readiness while providing governance oversight across multiple security domains.
Qualifications
12+ years in GRC, enterprise security architecture, vulnerability management, and cloud security.
10+ years owning SSP development end-to-end.
Deep knowledge of NIST SP 800-53 and NIST Risk Management Framework.
Responsibilities
Lead end-to-end SSP/SSPP development and maintenance.
Manage POA&M remediation and compliance gap closure.
Translate pen test and vulnerability findings into actionable remediation plans.
Ensure audit readiness with complete, assessor-ready documentation.
Oversee risk-based vulnerability management across cloud and hybrid environments.
Provide governance oversight for endpoint, web, and cloud security controls.
Skills
GRC
Enterprise security architecture
Vulnerability management
Cloud security
Audit evidence collection
Stakeholder management
NIST SP 800-53
Job description
Lead end-to-end SSP/SSPP development and maintenance
Manage POA&M remediation and compliance gap closure
Translate pen test and vulnerability findings into actionable remediation plans
Ensure audit readiness with complete, assessor-ready documentation
Oversee risk-based vulnerability management across cloud and hybrid environments
Provide governance oversight for endpoint, web, and cloud security controls
Required Experience
12+ years in GRC, enterprise security architecture, vulnerability management, and cloud security
10+ years owning SSP development end-to-end
Experience with CMS MARS-E v2.2 or similar federal/state frameworks
Strong expertise in audit evidence collection, control documentation, and POA&M management
Deep knowledge of NIST SP 800-53 and NIST Risk Management Framework
Experience with Secure SDLC and DevSecOps practices
Strong executive communication and stakeholder management skills