Turn this role into an interview — a resume and cover letter built around what this employer wants.
Nava is seeking a Senior Program Manager (ISSO) to lead system security, risk management, and infrastructure oversight in support of CMS. You will drive RMF activities, maintain the ATO, oversee security controls and risk assessments, support continuous monitoring and incident response, and advise CMS stakeholders on security posture.
The ideal candidate has a bachelor’s degree and 7+ years of relevant experience with RMF, ATO, cybersecurity, and federal compliance.
Nava is a consultancy and public benefit corporation working to make government services simple and effective. Since 2015, federal, state, and local agencies have trusted Nava to help solve highly scrutinized technology modernization challenges.
As a client services company, we guide agencies constrained by legacy systems to a future with sharp user experiences built on secure, reliable, fault-tolerant cloud infrastructure. We bill for our time, offering our expertise and problem-solving approach to help our government partners enhance their digital products and services. People are at the heart of our work, from members of the public who rely on benefit programs to government agency staff. Through human-centered design and modern engineering best practices, we help our government partners understand user needs and deliver on their missions more effectively. This focus gives everyone at Nava the opportunity to do work that is meaningful, impactful, and deeply connected to public good.
Nava is seeking a Senior Program Manager (ISSO) to lead system security, risk management, and infrastructure oversight in support of the Centers for Medicare Medicaid Services (CMS).
In this role, you'll lead Risk Management Framework (RMF) activities, maintain the system's Authorization to Operate (ATO), oversee security controls and risk assessments, support continuous monitoring and incident response, and serve as a trusted advisor to CMS stakeholders on the program's overall security and privacy posture.
The ideal candidate will have a bachelor's degree and at least seven years of relevant experience, with a strong background in the Risk Management Framework (RMF), Authorization to Operate (ATO) management, cybersecurity, and federal compliance. Experience leading security assessments, managing POA Ms, and implementing federal security controls in an operational environment is essential. While Nava and CMS provide onboarding through the ISSO Handbook and ISSO Boot Camp, candidates should bring established experience managing RMF activities and supporting federal information security programs. Although no specific certification is required under the contract, credentials such as CISSP, CISM, or CompTIA Security+ are highly desirable.
This is an opportunity to take on a highly visible leadership role supporting one of CMS's mission‑critical systems. You'll work closely with engineering teams, program leadership, and federal stakeholders to strengthen the program's security posture while helping deliver secure, reliable digital services that support millions of Americans.