IT Security Governance Officer

DOMA Technologies

Maryland

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Commence seeks a seasoned information security leader to manage CMS security controls, SA&A, and compliance for federal healthcare programs. You will develop SSP/POA&M, maintain training records, and coordinate with CMS IRT and auditors.

Responsibilities include enforcing CMS encryption standards, asset inventory, configuration management, and incident response liaison. Bachelor’s in IT related field preferred; CISSP/CISM/CISA encouraged.

Qualifications

  • Learn, document, and implement CMS information security controls in compliance with CMS IS2P2, FISMA, FedRAMP, HIPAA.
  • Oversee SA&A artifacts, SSP, POA&M, and related ATO documentation.
  • Ensure training and awareness across contractor personnel; maintain training records.
  • Manage encryption standards, asset inventory, configuration management, vulnerability scanning, and patch timelines.
  • Serve as liaison to CMS on information security and privacy matters; respond to incidents promptly.
  • Oversee DUA processes and CMS data access policies through EPPE.
  • Maintain complete IT asset inventory and ensure CMS/HHS encryption and configuration standards.
  • Support CMS audits, assessments, and annual performance reviews; facilitate government access as required.

Responsibilities

  • Oversee Security Assessment and Authorization (SA&A) process and maintain SSP/POA&M.
  • Coordinate CMS incident response and liaison with IRT when directed.
  • Enforce CMS encryption standards and asset inventory procedures.
  • Manage policy interpretation and training across CMS-related personnel.
  • Support audits, assessments, and governance activities for CMS contracts.

Skills

CMS information security
FISMA
FedRAMP
HIPAA
SA&A processes
Encryption standards
Vendor liaison
Incident Response

Education

Bachelor's degree in Information Systems or Computer Science

Tools

SSP documentation
POA&M management
EPPE system

Job description

Overview

At Commence, we’re the start of a new age of data‑centric transformation, elevating health outcomes and powering more efficient patient and program health processes. We combine quality data‑driven solutions that fuel answers, technology that advances performance, and clinical expertise that builds trust to create a more efficient path to quality care. With human‑centered, healthcare‑relevant, and value‑based solutions, we create new possibilities with data. We provide proof beyond the concept and performance beyond the scope, with a focus on efficiencies that transform the lives of those we serve. With a culture driven by purpose, straightforward communication, and clinical domain expertise, Commence cuts straight to better care.

Requirements
  • Learn, document, and implement Federal and CMS information security controls in compliance with CMS IS2P2, FISMA, FedRAMP, HIPAA, and all applicable CMS security policies and procedures.
  • Disseminate and implement IT policy that aligns with CMS requirements; provide interpretation of current policies in response to inquiries or specific incidents.
  • Oversee Security Assessment and Authorization (SA&A) process, including development and maintenance of the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and related ATO documentation.
  • Ensure all contractor personnel complete required CMS Information Security Awareness, Privacy, and Records Management training annually; maintain training records per CMS procedures.
  • Manage compliance with CMS encryption standards, FIPS 140 requirements, asset inventory, configuration management, vulnerability scanning, and patch remediation timelines per CMS policy.
  • Serve as primary liaison to CMS on all information security and privacy matters; respond to security incidents within required timeframes and coordinate with the CMS Incident Response Team (IRT) as directed.
  • Oversee Data Use Agreement (DUA) processes and ensure compliance with CMS data access policies through the Enterprise Privacy Policy Engine (EPPE) system.
  • Maintain a complete and current inventory of all IT assets and ensure devices meet CMS and HHS‑specific encryption and configuration standards.
  • Support CMS audits, security assessments, and annual performance reviews; allow government access to facilities, systems, and personnel as required.
Qualifications
  • Minimum 5 years of combined work experience, with at least 3 of those years in the healthcare industry supporting either Federal Government agencies or commercial healthcare market in a role such as CIO, Information Technology Manager, Chief Technology Officer, or Network Administrator.
  • Knowledge of the Medicare Fee‑for‑Service (FFS) program and familiarity with CMS information security requirements, including FISMA, FedRAMP, HIPAA, CMS IS2P2, and the CMS Business Partner System Security Manual (BPSSM).
  • Bachelor’s degree in Information Systems, Computer Science, or other related technology field required. Relevant work experience in a related field may be considered in lieu of a bachelor's degree.
Preferred Qualifications
  • Prior IT security governance or CIO‑equivalent leadership experience on a CMS contract with demonstrated knowledge of CMS Security Assessment and Authorization (SA&A) processes.
  • Relevant certification such as CISSP, CISM, CISA, or equivalent information security credential.
  • Experience managing FedRAMP authorization packages and working with third‑party assessment organizations (3PAOs) for moderate‑impact federal systems.
  • Familiarity with CMS esMD, RACDW, IDR, and other CMS‑designated data systems used in Medicare medical review operations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Governance Officer
IT Security Governance Officer

Commence, LLC • Virginia Beach (VA)

On-site
USD 120,000 - 180,000
Healthcare IT Security Governance Lead
Healthcare IT Security Governance Lead

DOMA Technologies • Maryland

On-site
USD 120,000 - 180,000
Healthcare IT Security Governance Leader
Healthcare IT Security Governance Leader

Commence, LLC • Virginia Beach (VA)

On-site
USD 120,000 - 180,000
Security Lead
Security Lead

COMMENCE • Virginia Beach (VA)

Remote
USD 140,000 - 200,000
Director Chief Information Security Officer
Director Chief Information Security Officer

The Security Executive Council • Montana

On-site
USD 130,000 - 180,000
Director Chief Information Security Officer - IT Infrastructure and Operations
Director Chief Information Security Officer - IT Infrastructure and Operations

St. Peter's Health • Montana

On-site
USD 140,000 - 180,000
Security Engineer
Security Engineer

Cogent People • Columbia (MD)

Hybrid
USD 100,000 - 140,000
Medical, Dental, and Vision Insurance
401(k) with company match
Company‑paid life insurance
+1
IT Cybersecurity Specialist (Security)
IT Cybersecurity Specialist (Security)

U.S. Department of Health and Human Services • Woodlawn (MD)

On-site
USD 110,000 - 140,000
Head of Information Security
Head of Information Security

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000
IT Security Manager
IT Security Manager

Comtech LLC • Bethesda (MD)

On-site
USD 120,000 - 150,000