Enterprise Cybersecurity Federal Compliance ISSO
About the role
The Opportunity: Enterprise Cybersecurity (ECS) Governance, Risk and Compliance (GRC) play a pivotal role in safeguarding the organization's sensitive information and ensuring compliance with stringent cybersecurity regulation and guidance. The GRC team is responsible for assessing and managing compliance and regulatory requirements in partnership with key stakeholders. ECS is seeking a definitive Subject Matter Expert in Cybersecurity Maturity Model Certification (CMMC) Levels 2 and 3 and National Institute of Standards and Technology (NIST) frameworks to lead compliance architecture and assessment within our Extended Enterprise Environment (EEE).
Responsibilities
- Audit controls and actively engineer compliance.
- Review and assess technical and environmental details.
- Provide a hands-on approach to ensure security compliance and regulatory requirements are achieved.
- Collaborate with cross-functional teams across the Booz Allen enterprise and client teams.
Requirements
- 10+ years of experience in cybersecurity or GRC.
- Experience in cybersecurity roles such as Security Control Assessor (SCA), Validator, Information System Security Officer (ISSO), Information System Security Engineer (ISSE), or Information Systems Security Manager (ISSM).
- Experience with security controls alignment, and assessment against CMMC, National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, NIST SP 800-171 rev. 2 and rev. 3, Risk Management Framework (RMF), Federal Information Processing Standards (FIPS) 199, FIPS 200 and associated SPs, and Federal Risk and Authorization Management Program (FedRAMP).
- Experience translating CMMC Level 3, NIST SP 800-171, and NIST SP 800-172 requirements into actionable engineering directives, leading the validation of evidence requirements for Level 2 and Level 3 assessments and meticulously analyze environment records, and identifying compliance gaps in complex systems, and driving remediation.
- Experience managing the full risk lifecycle, from identification to implementation of risk reducing strategies and final closure, using both qualitative and quantitative frameworks.
- Experience performing in-depth continuous monitoring and assessment of cybersecurity controls, evidence, and scan results to evaluate effectiveness and ensure continuous compliance.
- Experience partnering with IT, operations, and delivery teams to provide expert guidance, drive GRC initiatives, and foster a culture of awareness and knowledge for security compliance.
- Leverage GRC automation platforms, such as eMASS, ServiceNow, RSA Archer, CSAM, or Telos Xacta.
Qualifications
- HS diploma or GED.
- Ability to work independently and manage resources effectively to drive successful outcomes.
- Ability to negotiate, influence stakeholders, and drive issues to closure.
- Ability to engage senior and executive leadership.
- Ability to assess complex issues, draw logical conclusions, and make sound decisions.
- Excellent communication and collaboration skills.
- Excellent analytical thinking and problem solving skills.
Skills
- Ability to develop, maintain, and communicate metrics and reports regarding compliance and vulnerability management.
Benefits
- Health, life, disability, financial, and retirement benefits.
- Paid leave, professional development, tuition assistance, work-life programs, and dependent care.
- Recognition awards program.
Pay
$99,000.00 to $225,000.00 (annualized USD).
Schedule
Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits.