IT Security Governance Officer

Commence, LLC

Virginia Beach (VA)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Commence, LLC is recruiting for an IT Security Governance Officer to implement CMS information security controls and lead SA&A activities. You will develop and maintain SSP/POA&M, coordinate training, and ensure encryption and asset management compliance.

This role requires collaboration with CMS teams and cross‑functional stakeholders. The ideal candidate brings 5+ years in healthcare IT security, familiarity with FISMA, FedRAMP, HIPAA, and CMS policies, and a track record in governance

Qualifications

  • Minimum 5 years in IT security with CMS or federal healthcare focus.
  • Strong knowledge of CMS requirements, FISMA, FedRAMP and HIPAA.
  • Experience leading security governance activities and audits.

Responsibilities

  • Learn, document, and implement CMS information security controls per CMS policies.
  • Oversee SA&A process and SSP/POA&M documentation.
  • Ensure security training and compliance records are maintained annually.
  • Coordinate with CMS Incident Response Team and respond within timeframes.
  • Maintain asset inventory and encryption/configuration standards per CMS.

Skills

IT security
CMS knowledge
Security governance
FISMA knowledge
HIPAA compliance
Incident response

Education

Bachelor's degree

Tools

EPPE system
BPSSM

Job description

All Jobs > IT Security Governance Officer

At Commence, we’re the start of a new age of data-centric transformation, elevating health outcomes and powering better, more efficient process to program and patient health. We combine quality data-driven solutions that fuel answers, technology that advances performance, and clinical expertise that builds trust to create a more efficient path to quality care.

With human-centered, healthcare-relevant, and value-based solutions, we create new possibilities with data. We provide proof beyond the concept and performance beyond the scope with a focus on efficiencies that transform the lives of those we serve. With a culture driven by purpose, straightforward communication and clinical domain expertise, Commence cuts straight to better care.

Responsibilities
  • Learn, document, and implement Federal and CMS information security controls in compliance with CMS IS2P2, FISMA, FedRAMP, HIPAA, and all applicable CMS security policies and procedures.
  • Disseminate and implement IT policy that aligns with CMS requirements; provide interpretation of current policies in response to inquiries or specific incidents.
  • Oversee the Security Assessment and Authorization (SA&A) process, including development and maintenance of the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and related ATO documentation.
  • Ensure all contractor personnel complete required CMS Information Security Awareness, Privacy, and Records Management training annually; maintain training records per CMS procedures.
  • Manage compliance with CMS encryption standards, FIPS 140 requirements, asset inventory, configuration management, vulnerability scanning, and patch remediation timelines per CMS policy.
  • Serve as primary liaison to CMS on all information security and privacy matters; respond to security incidents within required timeframes and coordinate with the CMS Incident Response Team (IRT) as directed.
  • Oversee Data Use Agreement (DUA) processes and ensure compliance with CMS data access policies through the Enterprise Privacy Policy Engine (EPPE) system.
  • Maintain a complete and current inventory of all IT assets and ensure devices meet CMS and HHS-specific encryption and configuration standards.
  • Support CMS audits, security assessments, and annual performance reviews; allow government access to facilities, systems, and personnel as required.
Qualifications
  • Minimum 5 years of combined work experience, with at least 3 of those years in the healthcare industry supporting either Federal Government agencies or commercial healthcare market in a role such as CIO, Information Technology Manager, Chief Technology Officer, or Network Administrator.
  • Knowledge of the Medicare Fee-for-Service (FFS) program and familiarity with CMS information security requirements, including FISMA, FedRAMP, HIPAA, CMS IS2P2, and the CMS Business Partner System Security Manual (BPSSM).
  • Bachelor's degree in Information Systems, Computer Science, or other related technology field required. Relevant work experience in a related field may be considered in lieu of a bachelor's degree.
Preferred Qualifications
  • Prior IT security governance or CIO-equivalent leadership experience on a CMS contract with demonstrated knowledge of CMS Security Assessment and Authorization (SA&A) processes.
  • Relevant certification such as CISSP, CISM, CISA, or equivalent information security credential.
  • Experience managing FedRAMP authorization packages and working with third-party assessment organizations (3PAOs) for moderate-impact federal systems.
  • Familiarity with CMS esMD, RACDW, IDR, and other CMS-designated data systems used in Medicare medical review operations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Governance Officer
IT Security Governance Officer

DOMA Technologies • Maryland

On-site
USD 120,000 - 180,000
Healthcare IT Security Governance Lead
Healthcare IT Security Governance Lead

DOMA Technologies • Maryland

On-site
USD 120,000 - 180,000
Healthcare IT Security Governance Leader
Healthcare IT Security Governance Leader

Commence, LLC • Virginia Beach (VA)

On-site
USD 120,000 - 180,000
Security Lead
Security Lead

COMMENCE • Virginia Beach (VA)

Remote
USD 140,000 - 200,000
IT Security/Compliance Analyst
IT Security/Compliance Analyst

US IT Solutions Inc • Columbia (SC)

On-site
USD 80,000 - 100,000
Senior Information Security Analyst -CISSP
Senior Information Security Analyst -CISSP

ARK Strategies • Rancho Cordova (CA)

On-site
USD 120,000 - 150,000
Director Chief Information Security Officer
Director Chief Information Security Officer

The Security Executive Council • Montana

On-site
USD 130,000 - 180,000
IT Security Manager
IT Security Manager

Comtech LLC • Bethesda (MD)

On-site
USD 120,000 - 150,000
Chief Information Security Officer (CISO) | PAM Health Corporate
Chief Information Security Officer (CISO) | PAM Health Corporate

PAM Health • Plano (TX)

Hybrid
USD 150,000 - 200,000
Cybersecurity Program Manager
Cybersecurity Program Manager

Carex Consulting Group • Madison (WI)

On-site
USD 125,000 - 170,000