A prominent technology company based in Austin, Texas is seeking a candidate with extensive knowledge in Governance, Risk, and Compliance (GRC) and Enterprise Security. The role demands proven experience in developing and managing Security System Plans (SSP), along with hands-on familiarity with federal/state security frameworks. Strong stakeholder management and communication skills are essential, alongside demonstrated expertise in audit processes and compliance maturity enhancement. This position is pivotal for maintaining the security integrity of the organization.
Qualifications
Must have deep experience in Governance, Risk, and Compliance (GRC) for SSP development and enterprise security architectures.
End-to-end ownership of SSP development and compliance delivery.
Hands-on familiarity with CMS MARS E v2.2 or comparable federal/state frameworks.
Proven ability to document controls, collect and validate audit evidence, and create/tracking/remediation POA&M.
Responsibilities
Lead SSP development end-to-end and ensure alignment with applicable security frameworks.
Document controls, collect audit evidence, and drive POA&M creation, tracking and remediation.
Translate technical security issues into remediation actions aligned with compliance requirements.
Coordinate with security, infrastructure, and application teams; communicate with executives.
Apply NIST RMF, 800-53 and privacy controls in ongoing security programs.
Enforce Secure SDLC and DevSecOps practices across projects.
Mentor teams on security governance best practices and drive maturity improvements.
Support HHSC systems with SSP development and compliance efforts.
Skills
Governance, Risk, and Compliance (GRC)
Enterprise Security and Security Architecture
Vulnerability Management
Penetration Testing
Cloud Security
Hybrid environments
Control implementation documentation
Audit evidence collection and validation
POA&M creation
Tracking and remediation management
Stakeholder management
Excellent written and verbal communication
Knowledge of NIST 800 53
NIST RMF
Privacy controls
Secure SDLC
DevSecOps practices
Job description
12 Required deep focus on: Governance, Risk, and Compliance (GRC), Enterprise Security and Security Architecture, Vulnerability Management and Penetration Testing , Cloud Security and hybrid environments
10 Required Proven experience owning SSP development end to end
10 Required Hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks
10 Required Strong expertise in: Control implementation documentation, Audit evidence collection and validation, POA&M creation, tracking, and remediation management
8 Required Ability to translate technical security issues into compliance aligned remediation actions
8 Required Strong stakeholder management skills across security, infrastructure, and application teams
8 Required Excellent written and verbal communication skills, particularly for executive stakeholders
8 Required Knowledge of NIST 800 53, NIST RMF, and privacy controls
8 Required Knowledge of Secure SDLC and DevSecOps practices
5 Preferred Experience operating in multi-vendor, multi-platform environments
5 Preferred Demonstrated ability to reduce repeat audit findings and improve compliance maturity
5 Preferred Experience mentoring or guiding teams on security governance best practices
1 Preferred Experience supporting HHSC systems, including SSP development and compliance