Position Summary
The Cyber GRC Implementation Lead serves as the program-wide Federal GRC subject matter lead and establishes the cybersecurity governance, risk, compliance, and authorization implementation methodology executed across HHS delivery Pods. The position translates Federal and HHS requirements into standardized, reusable GRC processes and provides senior-level guidance for RMF/ATO, FISMA, FedRAMP, ISCM, assessment, POA&M, common controls, audit readiness, HVA, C-SCRM, and ongoing authorization activities.
Essential Duties and Responsibilities
· Establish and govern the enterprise GRC implementation methodology used across delivery Pods and HHS organizations.
· Provide senior subject matter expertise for NIST RMF/ATO lifecycle activities, NIST SP 800-53 controls, FISMA, OMB guidance, FedRAMP, and HHS cybersecurity requirements.
· Define standardized approaches for control implementation narratives, organizational parameters, evidence, common controls, inheritance, assessment, findings, risks, and POA&M management.
· Lead development and implementation of ISCM, risk thresholds, trigger events, continuous-monitoring workflows, and ongoing authorization decision-support processes.
· Provide guidance for HVA, Cyber Supply Chain Risk Management, audit readiness, FISMA metrics/reporting, and enterprise risk activities.
· Support security control assessment methodology and traceability among assessment objectives, evidence, findings, remediation, and risk decisions.
· Coordinate cybersecurity GRC requirements with privacy, data, architecture, training, platform, and integration workstreams.
· Translate Federal GRC requirements into functional requirements, reusable implementation patterns, workflows, metrics, dashboards, and acceptance criteria.
· Provide escalation support to PSAs and delivery Pods for complex Federal GRC questions and ensure consistent interpretation across OpDivs.
· Support gap analysis, policy/process modernization, stakeholder engagement, and change-control decisions.
· Review GRC deliverables and configured workflows for technical accuracy, consistency, traceability, and alignment with approved requirements.
· Promote document-once, assess-once, reuse-many practices and enterprise common-control/capability reuse where approved.
Recommended Education
Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, Information Systems, Engineering, or a related field.
Recommended Experience
10+ years of progressively responsible Federal cybersecurity GRC experience, including 5+ years leading Federal RMF/ATO, FISMA, FedRAMP, continuous monitoring, security assessment, audit, or enterprise GRC modernization activities.
Recommended Certifications / Qualifications
· CISSP or CGRC strongly preferred
· CISM or CRISC beneficial
· Security+ beneficial
· Federal RMF/ATO and NIST SP 800-53 expertise required
· RegScale experience preferred, not required
Application Question(s):
- Are you legally authorized to work in the United States?
- Desired Salary?
Security clearance:
Work Location: Remote