Security Lead

COMMENCE

Virginia Beach (VA)

On-site

USD 140,000 - 200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Commence is seeking a Security Lead to establish and oversee the cybersecurity, privacy, and compliance posture for a CMS case management program. You will act as the security advisor to leadership, collaborating with cloud, DevSecOps, and government security stakeholders to embed security in every layer.

The role requires coordinating ATO activities, enforcing Zero Trust, and guiding secure cloud designs, IAM, and incident response for health data protection.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field.
  • 10+ years of cybersecurity experience, including 2+ years supporting federal health programs.
  • Experience securing cloud-based solutions, including AWS.

Responsibilities

  • Lead the program's cybersecurity strategy and ensure compliance with CMS ARS, FISMA, HIPAA/HITECH, NIST 800-53, and FedRAMP requirements.
  • Develop and maintain security plans, policies, and procedures aligned to federal standards.
  • Support Authority to Operate (ATO) activities and coordinate with government security officials and compliance auditors.
  • Manage Plan of Action and Milestones (POA&M) activities and maintain the program risk register.
  • Review and approve AWS cloud architecture designs, ensuring secure implementation of cloud-native services and security controls.
  • Enforce IAM policies, MFA, encryption at rest and in transit, network segmentation, and Zero Trust principles.
  • Embed security controls into CI/CD pipelines and validate cloud configurations against security baselines.
  • Implement automated scanning for source code, containers, Kubernetes workloads, Infrastructure as Code (IaC), and open-source dependencies.
  • Conduct security risk assessments and threat modelling; identify vulnerabilities and develop mitigation strategies.
  • Evaluate third-party and integration partner security risks.
  • Define data classification, handling, retention, and destruction requirements to protect PII and PHI.
  • Review interoperability and data-sharing solutions for HIPAA privacy compliance.
  • Develop and maintain incident response procedures and support SIEM-based monitoring and alerting strategies.
  • Coordinate response activities for security incidents and vulnerabilities.
  • Participate in Architecture Review Boards (ARBs) and review application, integration, data, and infrastructure designs for security gaps.
  • Ensure secure API and interoperability implementations across all integrated systems

Skills

Security leadership
CMS/Federal compliance
Cloud security (AWS)
Threat modelling
DevSecOps integration
IAM & Zero Trust

Education

Bachelor's degree in Cybersecurity/Information Security

Tools

AWS

Job description

Description

At Commence, we’re the start of a new age of data-centric transformation, elevating health outcomes and powering better, more efficient process to program and patient health. We combine quality data-driven solutions that fuel answers, technology that advances performance, and clinical expertise that builds trust to create a more efficient path to quality care.

With human-centered, healthcare-relevant, and value-based solutions, we create new possibilities with data. We provide proof beyond the concept and performance beyond the scope with a focus on efficiencies that transform the lives of those we serve. With a culture driven by purpose, straightforward communication and clinical domain expertise, Commence cuts straight to better care.?

Requirements

The Security Lead will establish and oversee the cybersecurity, privacy, and compliance posture for a CMS case management program. You'll serve as the primary security advisor to program leadership, working closely with the Program Manager, Solutions Architect, Cloud Architect, DevSecOps team, and government security stakeholders to ensure security is embedded into every layer of the solution.

  • Lead the program's cybersecurity strategy and ensure compliance with CMS ARS, FISMA, HIPAA/HITECH, NIST 800-53, and FedRAMP requirements
  • Develop and maintain security plans, policies, and procedures aligned to federal standards
  • Support Authority to Operate (ATO) activities and coordinate with government security officials and compliance auditors
  • Manage Plan of Action and Milestones (POA&M) activities and maintain the program risk register
  • Review and approve AWS cloud architecture designs, ensuring secure implementation of cloud-native services and security controls
  • Enforce IAM policies, MFA, encryption at rest and in transit, network segmentation, and Zero Trust principles
  • Embed security controls into CI/CD pipelines and validate cloud configurations against security baselines
  • Implement automated scanning for source code, containers, Kubernetes workloads, Infrastructure as Code (IaC), and open-source dependencies
  • Conduct security risk assessments and threat modelling; identify vulnerabilities and develop mitigation strategies
  • Evaluate third-party and integration partner security risks
  • Define data classification, handling, retention, and destruction requirements to protect PII and PHI
  • Review interoperability and data-sharing solutions for HIPAA privacy compliance
  • Develop and maintain incident response procedures and support SIEM-based monitoring and alerting strategies
  • Coordinate response activities for security incidents and vulnerabilities
  • Participate in Architecture Review Boards (ARBs) and review application, integration, data, and infrastructure designs for security gaps
  • Ensure secure API and interoperability implementations across all integrated systems
Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field
  • 10+ years of cybersecurity experience, including 2+ years supporting federal health programs
  • 5+ years securing cloud-based solutions, including AWS
  • Experience supporting healthcare or CMS-related systems
  • Experience with ATO processes and federal compliance frameworksExperience leading security teams in Agile and DevSecOps environments
Preferred Qualifications
  • CISSP – Certified Information Systems Security Professional Preferred
Commence's headquarters are in Virginia Beach, VA, however we are open to remote candidates in the following states: AZ, AR, CO, DE, FL, GA, IL, IN, KS, KY, MA, MD, MI, MS, MO, MT, NC, NE, NV, NY, OH, OK, PA, SC, TN, TX, VA, DC, WI, and WV
Work Environment/Physical Demands

The work environment and physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

This is a remote position. Candidates must be able to sit, read, work on a computer, and watch a computer screen for extended periods of time. Occasionally required to stand, walk, use hands and fingers, kneel or crouch.

Commence is an equal employment opportunity employer. All personnel processes are merit-based and applied without discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, marital status, age, disability, national or ethnic origin, military and veteran status or any other characteristic protected by applicable law.

Commence is committed to providing equal employment opportunities to all applicants, including individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Governance Officer
IT Security Governance Officer

DOMA Technologies • Maryland

On-site
USD 120,000 - 180,000
IT Security Governance Officer
IT Security Governance Officer

Commence, LLC • Virginia Beach (VA)

On-site
USD 120,000 - 180,000
Program Director - Federal Health (CMS)
Program Director - Federal Health (CMS)

DOMA Technologies • Maryland

Hybrid
USD 140,000 - 190,000
Program Director – Federal Health (CMS)
Program Director – Federal Health (CMS)

Commence, LLC • Baltimore (MD)

Hybrid
USD 130,000 - 185,000
Senior Salesforce Developer, Federal Health-CMS
Senior Salesforce Developer, Federal Health-CMS

Commence • Northern (KY)

Hybrid
USD 120,000 - 160,000
Remote Security Lead for Federal Health IT
Remote Security Lead for Federal Health IT

DOMA Technologies • Virginia Beach (VA)

On-site
USD 150,000 - 190,000
Full Stack Software Engineer
Full Stack Software Engineer

DOMA Technologies • Leesburg (VA)

On-site
USD 100,000 - 130,000
Senior Salesforce Developer, Federal Health-CMS
Senior Salesforce Developer, Federal Health-CMS

DOMA Technologies • Maryland

On-site
USD 110,000 - 170,000
Senior Full-Stack Software Engineer
Senior Full-Stack Software Engineer

Worky • Virginia Beach (VA)

On-site
USD 120,000 - 160,000
Remote work
Remote Security Lead: Federal Health Cloud & Compliance
Remote Security Lead: Federal Health Cloud & Compliance

COMMENCE • Virginia Beach (VA)

Remote
USD 140,000 - 200,000