Security Manager

Jimmy Jazz

United States

Remote

USD 140,000 - 190,000

Full time

31 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

APV is seeking a mission-driven Security Manager to oversee a large federal healthcare technology program. You will lead cybersecurity, compliance, risk management, continuous monitoring, incident response, and governance across complex federal information systems.

The role requires 8+ years of information security experience, with deep RMF/800-53 knowledge and CMS/FedRAMP familiarity. U.S. work authorization and high-trust access are required for program participation.

Qualifications

  • Requires 8+ years in information security/cybersecurity with 3+ years leading security for complex systems.
  • Knowledge of RMF, NIST SP 800-53, FISMA, continuous monitoring, and risk management.
  • Ability to obtain and maintain High-Risk Public Trust and U.S. work authorization.

Responsibilities

  • Lead security strategy, compliance, risk management, and continuous monitoring for federal systems.
  • Maintain ATO documentation, security artifacts, assessments, and authorization support packages.
  • Oversee vulnerability management, POA&M development, remediation tracking, and security reporting.
  • Coordinate security assessments, audits, penetration testing, and continuous monitoring.
  • Ensure compliance with NIST RMF, NIST SP 800-53, FISMA, HIPAA, CMS requirements, and federal standards.
  • Support incident response, threat management, and security operations activities.
  • Collaborate with architects, DevSecOps, developers, and government stakeholders to integrate controls.
  • Own the System Security Plan, security control assessments, and ATO package including reauthorization.
  • Manage POA&M lifecycle end-to-end with monthly government reporting.
  • Apply CMS ARS and HIPAA controls to AWS cloud environments.
  • Coordinate independent assessments and ensure security evidence is pipeline-automated.

Skills

Security leadership
RMF & 800-53
Vulnerability management
Security assessments & POA&M
Incident response
Government stakeholder coordination

Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related discipline

Tools

CMS ARS
FedRAMP

Job description

CLEARANCE: Must be able to obtain aHigh-RiskPublic Trust

COMPANY OVERVIEW

At APV,we’remore than a technology company —we’rea mission-driven powerhouse transforming organizations through advanced technology and human ingenuity. Ourexpertisespans AI/ML, data architecture, low-code/no-code development, AgileDevSecOps, and cloud services, delivering scalable and meaningful solutions.

In our Emerging Technology Lab, innovation drives progress. Our teams create intelligent chatbots, AI-powered assistants, robotic process automation (RPA), essay graders, and data analytics platforms. Ifyou’repassionate about solving complex challenges and shaping the future, APV is the place for you. Since 2007,we’vepartnered with federal and state agencies to deliver IT, training, and consulting solutions that achieve mission-critical outcomes. Built on accountability, integrity, and quality, we go beyond expectations.With 70+ prime contracts and a proven record of client success, APV continues to grow — andwe’relooking for exceptional talent to grow with us.

At APV, we Always Provide Value
POSITION SUMMARY

Seeking a mission-driven Security Manager to support a large-scale federal healthcare technology program. This role provides leadership across cybersecurity, compliance, risk management, continuous monitoring, incident response, and federal security governance.

DUTIES
  • Lead security strategy, compliance, risk management, and continuous monitoring activities for complex federal information systems.
  • Maintain ATO documentation, security artifacts, assessments, and authorization support packages.
  • Oversee vulnerability management, POA&M development, remediation tracking, and security reporting.
  • Coordinate security assessments, audits, penetration testing, and continuous monitoring activities.
  • Ensure compliance with NIST RMF, NIST 800-53, FISMA, HIPAA, CMS security requirements, and federal cybersecurity standards.
  • Support incident response, threat management, and security operations activities.
  • Collaborate with architects, DevSecOps teams, developers, and government stakeholders to integrate security controls throughout the system lifecycle.
  • Own the System Security Plan, security control assessments, and Authority to Operate (ATO) package, including support for reauthorization and for extending authorization to lower environments.
  • Manage the POA&M lifecycle end to end: intake, risk rating, remediation planning, evidence, and closure within agency-defined timelines, with monthly reporting to government stakeholders.
  • Apply NIST RMF, NIST SP 800-53, FISMA, HIPAA, and agency-specific control baselines such as CMS Acceptable Risk Safeguards (ARS) to a cloud-hosted AWS environment.
  • Coordinate independent assessments, penetration testing, and continuous monitoring, and serve as the primary security interface to government security and privacy officials.
  • Work shoulder to shoulder with the DevSecOps Lead so that scanning, patching, and control evidence are automated in the pipeline instead of collected by hand.
EDUCATION

Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related discipline.

REQUIRED QUALIFICATIONS
  • Minimum 8 years of information security/cybersecurity experience, including at least 3 years leading security activities for complex information systems.
  • Demonstrated knowledge of NIST Risk Management Framework (RMF), NIST SP 800-53, FISMA, continuous monitoring, vulnerability management, incident response, security assessments, POA&M management, and system authorization processes. Ability to integrate security requirements and controls throughout the system development lifecycle and coordinate security activities with Government stakeholders.
  • Must be able to obtain and maintain a High-Risk Public Trust or equivalent federal client access.This role supports sensitive federal programs and involves elevated access to systems and data.
  • Position requires the current ability to obtain and maintain required access without interruption in alignment with long-term program needs.
  • Mustbe authorized towork in the United States without employer sponsorship now or in the future.
PREFERRED QUALIFICATIONS
  • CISSP, CISM, CGRC, or equivalent cybersecurity credentials. Direct experience with CMS or HHS authorization processes, CFACTS, the CMS Acceptable Risk Safeguards (ARS), FedRAMP-authorized cloud services, and HIPAA/PHI environments is strongly preferred.
ABOUT APV

APV is an Equal Employment Opportunity employer. All qualified applicants are considered without regard to race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity, veteran status, or marital status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

System Architect
System Architect

Jimmy Jazz • United States

Remote
USD 140,000 - 190,000
Project Manager
Project Manager

Jimmy Jazz • Columbia (MD)

On-site
USD 95,000 - 135,000
Human Centered Design SME
Human Centered Design SME

Jimmy Jazz • United States

Remote
USD 110,000 - 160,000
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth Corporate Support Center • Louisville (KY)

On-site
USD 180,000 - 240,000
Information Assurance Specialist Senior
Information Assurance Specialist Senior

Avum Inc. • Agoura Hills (CA)

On-site
USD 110,000 - 145,000
Medical, dental, and vision insurance
401(k)
PTO
+2
Data Management SME
Data Management SME

Jimmy Jazz • United States

Remote
USD 110,000 - 150,000
Technical Project Manager
Technical Project Manager

ECS • Richmond (VA)

On-site
USD 110,000 - 125,000
Senior Public Sector Compliance Manager
Senior Public Sector Compliance Manager

Jobgether SRL • United States

Remote
USD 110,000 - 170,000
Remote work within United States
Exposure to federal security programs
Cross-functional collaboration
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Nava • Washington, Northern (KY)

On-site
USD 86,000 - 202,000
Medical insurance
Dental insurance
Disability insurance
+5
Security | ATO Compliance Lead
Security | ATO Compliance Lead

BLUMEPROT+ technology • Gaithersburg (MD)

On-site
USD 120,000 - 145,000
401k Matching
Holidays Eleven
Technology Reimbursement
+3