Governance, Risk & Compliance / Cloud Security Subject Matter Expert
Lexical Intelligence, LLC
Job Description
Job Description
Lexical Intelligence provides software and services related to processing large-scale biomedical information sources. Our NLP and analytics software is used by policy and decision makers to evaluate and prioritize current and emerging areas of research.
Lexical Intelligence is seeking a senior Governance, Risk & Compliance / Cloud Security Subject Matter Expert (GRC / Cloud SME) to serve as the security subject matter expert for a complex, cloud-native system supporting the National Institutes of Health (NIH). The system is fully deployed in Amazon Web Services (AWS) across multiple accounts and hosts multiple applications that process and analyze large-scale biomedical data.
This is a hands-on Governance, Risk, and Compliance (GRC) leadership role. The GRC / Cloud SME will own the development and maintenance of the system's Authority to Operate (ATO) package within JCAM (NIH's enterprise GRC platform), advise the program on the security implications of change and configuration management, and serve as the system's Contingency Planning and Incident Response Coordinator. The GRC / Cloud SME will act as the trusted security advisor to a cross-functional team of software developers, DevOps engineers, data scientists, and program leadership.
Key Responsibilities
- ATO Package Development & Maintenance
- Develop, maintain, and continuously improve the system's ATO package in JCAM, including the System Security Plan (SSP), control implementation statements, security policies and procedures, and all supporting artifacts.
- Ensure the ATO package accurately reflects the as-built, multi-account AWS environment and remains current as the system evolves.
- Support security assessments, audits, and annual control assessments; coordinate evidence collection and respond to assessor findings.
- Manage Plans of Action & Milestones (POA&Ms): track weaknesses, coordinate remediation with engineering teams, and report status to the Authorizing Official's staff.
- Change & Configuration Management Advisory
- Serve as the security voice in the change and configuration management process: review proposed system changes, perform Security Impact Analyses (SIA), and advise the team on whether changes affect the authorization boundary or control posture.
- Ensure security-relevant changes are documented, assessed, and reflected in the ATO package and continuous monitoring reporting.
- Advise on secure configuration baselines and monitor for configuration drift across AWS accounts.
- Contingency Planning & Incident Response Coordination
- Serve as the system's Contingency Planning Coordinator: develop and maintain the Information System Contingency Plan (ISCP), plan and facilitate annual contingency plan tests and tabletop exercises, and document test results and lessons learned.
- Serve as the system's Incident Response Coordinator: maintain the Incident Response Plan, coordinate incident detection, reporting, and response activities in accordance with NIH and HHS requirements, and lead incident response exercises.
- Ensure backup, recovery, and resilience capabilities are documented, tested, and aligned with system recovery objectives.
- Cloud Security Engineering & Team Advisory
- Advise developers, DevOps engineers, and data scientists on secure architecture and AWS security best practices across a multi-account environment, including IAM, AWS Organizations and service control policies, encryption and key management (KMS), logging and monitoring (CloudTrail, CloudWatch, GuardDuty, Security Hub, AWS Config), and network security.
- Support vulnerability management: review scan results, prioritize findings, and partner with engineering teams on remediation.
- Advise on secure development and DevSecOps practices, including CI/CD pipeline security and infrastructure as code.
- Serve as the day-to-day security advisor to the program, translating federal security requirements into practical guidance the team can act on.
Minimum Qualifications
- 7+ years of information security experience, including direct support of federal systems and the full ATO lifecycle under the NIST Risk Management Framework (SP 800-37).
- Deep, demonstrated expertise in NIST SP 800-53 control selection, implementation, and assessment, including authoring SSPs and control implementation statements.
- Hands-on experience securing AWS environments, preferably multi-account architectures (AWS Organizations), including IAM, logging/monitoring services, and encryption/key management.
- Experience developing and maintaining complete ATO packages within an enterprise GRC platform (e.g., JCAM, CSAM, eMASS, Xacta, or similar).
- Experience performing Security Impact Analyses and advising change control processes on security-relevant changes.
- Experience developing, maintaining, and testing contingency plans (NIST SP 800-34) and incident response plans (NIST SP 800-61).
- Experience with vulnerability management and POA&M lifecycle management, including tools such as Tenable, Inspector, or similar scanners.
- Strong technical writing and documentation skills with meticulous attention to detail.
- Proven ability to communicate security requirements effectively to engineers, data scientists, and program leadership.
- One or more of the following certifications: CISSP, CISM, AWS Certified Security - Speciality.
- Cloud process knowledge
- Linux familiarity
Preferred Qualifications
- Direct experience with JCAM and supporting systems within NIH or other HHS agencies.
- Experience with containerized environments and orchestration platforms (e.g., Kubernetes, Amazon EKS).
- Exposure to infrastructure as code (e.g., Terraform) and automation of compliance or continuous monitoring activities.
- Familiarity with large-scale data platforms, biomedical data, or research-focused systems, including data privacy considerations for sensitive or regulated data.
- Experience supporting public-facing federal systems or APIs.
- Additional relevant certifications such as CISSP, CGRC/CAP, CISM, CCSP, or AWS Certified Security – Specialty.
- Cloud architecture / DevOps experience or knowledge
All candidates will be required to undergo a background check, must be authorized to work in the United States, and must be able to obtain and maintain an NIH badge with Public Trust Level Two suitability.
Location
Preference will be given to candidates within reasonable commuting distance of Bethesda, MD. Candidates outside the greater Washington, D.C. / Maryland / Virginia area may be responsible for their own transportation costs for badging, equipment retrieval, and in-person attendance when required.
Salary and benefits
We offer a competitive salary and a generous benefits package, including at no cost: full health and dental for you and your dependents, HSA account, 401k, short- and long-term disability insurance, life and accident insurance, paid time off, and 11 federal holidays.
Equal Employment Opportunity Policy
Lexical Intelligence, LLC, provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
- ...& Authorization – Subject Matter Expert (SME) At B&A, we... ...understanding of how security controls identified in... ...and small enclaves, Cloud Hosted Services, Operational... ...the residual risk of an identified vulnerability... ...with DoD or Federal Government cybersecurity...CloudFull timeWork at officeLocal areaRemote work
- ...Mytonomy Subject Matter Expert Job Description: Gynecology Oncology Mytonomy is a market leader in enterprise cloud solutions for video-based patient engagement, education, and experience. Our platform delivers broadcast-quality microlearning videos and intelligent,...CloudRelief
- ...Principal Network Architect / Subject Matter Expert (SME) to serve as the... ...supporting our government customer. Today the customer... ...and internal teams across cloud, WAN, LAN, and security, which slows incident resolution... ...rollback plans and risk assessments, to protect the...CloudFull timeContract workTemporary workFor contractorsInterim roleWork at office
$130k - $140k
...mission. Our AI, cloud, cyber, and modernization... ...national security, and strengthen health... ...1,500+ AI & data experts, and 100+ prime... ...Architect and Subject Matter Expert (SME) to join... ...needs of the government. This position is... ...practices. Ensure compliance with Enterprise Informatics...CloudTemporary workWorldwide- ...high-visibility national security program requiring... ...expertise in enterprise risk management, RMF, and security governance. The Cybersecurity SME serves... ...RESPONSIBILITIES • Provide expert-level cybersecurity... ...stakeholders to ensure compliance with applicable federal...SuggestedFull time
- ...Job Description Job Description Subject Matter Expert (SME) Cybersecurity ???? Bethesda, MD... ...Subject Matter Expert to support critical government and intelligence initiatives by... ...defense program. If you excel at improving security operations, enhancing cyber response...Full time
- ...Traumatic Brain Injury (TBI) Subject Matter Expert (SME) to support the... .... ~ Ability to pass a T3 security/background investigation.... ...major agency across the U.S. government, defense and intelligence community... ...-ready capabilities in AI, cloud, cyber and software...CloudTemporary workImmediate startRemote workWork from homeWorldwideFlexible hours
$73.45k - $132.78k
...What You’ll Work On Serve as the primary subject matter expert (SME) for Integrated Undersea... ...operational procedures. Interface with government customers, fleet representatives, and... ...disciplinary teams. Ability to obtain an interim security clearance. Desired Qualifications...Interim roleLocal areaImmediate start$150k - $180k
...mission. Our AI, cloud, cyber, and modernization... ...national security, and strengthen health... ...1,500+ AI & data experts, and 100+ prime... ...) Architect and Subject Matter Expert (SME) to... ...specific needs of the government. This position is... ...team Assess risks and impacts of...CloudTemporary workWorldwide$55k - $130k
...SHINE Systems is looking for an IUSS Subject Matter Expert to join our team. What You'll Work... ...operational procedures. Interface with government customers, fleet representatives, and... .... ~ Ability to obtain an interim security clearance. Desired Qualifications...Contract workInterim roleLocal area$120k - $150k
...for the Welfare, Defense, and Security of Our Nation Blake... ...Group (BWG) unites deep domain experts with technologists who leverage... ...processes for alignment with federal government-wide financial management... ...identify gaps, dependencies, risks, and opportunities to improve...Local area- ...Job Description Job Description Subject Matter Expert (SME) Big Data ???? Bethesda, MD | McLean... ...Matter Expert to support critical government and intelligence initiatives by providing... ...required , including additional security screenings Education and Experience Requirements...Full time
- ...Human Capital Analyst Expert: At B&A, we foster... ...to support a federal government client within the National... ...intelligence, cloud technologies, and emerging... ...Responsibilities: ~ Serve as the subject matter expert in data... ...data governance and security requirements. ~Two (...CloudFull timeWork at officeLocal area
- ...Description: Course Instructors serve as Subject Matter Experts (SMEs) responsible for designing,... ...requirements, and Section 508 compliance. Course Delivery Deliver instructor... ...professionals. Integrate guest speakers from government, academia, think tanks, and...For contractorsOverseas
- ...done. We share how the company is performing. We talk openly about what’s working, what isn’t, and what needs to change. Good ideas matter more than titles, and we expect people to challenge us when they see a better way. We’re remote‑first and work across the US, UK,...Remote work
- ...services to federal government clients, including program... ...our NHO status to secure federal contracts... ...heritage. You Are The Subject Matter Expert (SME) III will play a... ...to ensure compliance with quality assurance... ...Branch leads to identify risks and opportunities across...Full timeRemote work
$105.79k - $141.05k
...ecosystem. We enable secure, high‑... ...connectivity across cloud, edge, and AI... ...for enterprises, governments, and... ...and resilience matter.This is a high... ...ability to balance risk with business objectives... ..., risk, and compliance considerations... ...responsibilities are subject to change based...CloudFull timeContract workTemporary workRemote work- ...Risk Consulting - Risk Technology - Sap Grc & Security - Senior ConsultantLocation: New York Other locations: Anywhere... ...rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP... ...initiatives, including S/4HANA and cloud-based SAP solutions, under...CloudShift work
- ...Description Data Architect - Subject Matter Expert (SME) ????... ...in developing data governance models, ensuring... ...area, specializing in Cloud, Enterprise Architecture... ...federal standards, security compliance (e.g., FedRAMP, NIST... .... ~ Conduct risk assessments, vulnerability...CloudFull timeWork at office
$109k - $124.4k
...Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what... ...a step in the compliance process. You thrive... ...engineering best practices, cloud infrastructure,... ...when to pull in experts to inform your... ...locations will be subject to the pay range associated...CloudFull timePart timeH1bLocal area- ...operational excellence, compliance, and employee... ..., operational risk, compliance, and administrative... ...leadership governance processes,... ...employee relations matters and organizational... ...effectiveness. Ensure secure, reliable,... ...Precise specializes in cloud and hybrid infrastructure...CloudContract workFor contractorsWork at officeLocal area
$269.1k - $307.2k
...with enterprise platform, security, risk, compliance, and procurement teams. The... ...needs. Navigate enterprise governance (security, risk, compliance... ...and design patterns Cloud computing (AWS, Microsoft Azure... ...in other locations will be subject to the pay range associated...CloudFull timePart timeLocal areaRemote work$190.96k - $286.44k
...Management, Application Security and Penetration... ...resilient when it matters most. This is... ...ticket to modern, risk-based exposure... ...across engineering, cloud, product and... ...enterprise remediation governance and SLAs. Attack... ...with diverse experts to experimenting with...CloudTemporary workWork at officeWorldwideFlexible hours3 days per week$99k - $225k
...USA Information Security Risk Specialist As an... ...contractor and DoD government system owners, as well... ...insights from subject matter experts (SMEs) and engineers... ...skills in DevSecOps and cloud security. Join us... ...policies ~ Knowledge of compliance testing tools such...CloudFull timeContract workPart timeFor contractorsWork at officeLocal areaRemote work$130k - $155k
...active PCI DSS Qualified Security Assessor (QSA) for... ..., Continuity and Compliance position. T his is a... ...consultants and internal subject matter experts as needed. The... ...requirements to identify risks, vulnerabilities,... ...cardholder data flows, cloud infrastructure, networks...CloudFull timeWork at officeRemote work$102.5k - $187.9k
...opportunity With rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who understand risk management... ...initiatives, including S/4HANA and cloud-based SAP solutions, under the guidance of managers...CloudSummer holidayFlexible hoursShift work$102.5k - $187.9k
...opportunity With rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who understand risk management... ...initiatives, including S/4HANA and cloud-based SAP solutions, under the guidance of managers...CloudSummer holidayFlexible hoursShift work$229.9k - $262.4k
...Manager, Cyber Security (GPN) At... ...understanding of risk and security,... ...when to pull in experts and elevate.... ...comfortable with Cloud Service... ...cybersecurity subject matter expert and advise... ...operational, compliance, process, control... ...with industry governance or financial governance...CloudFull timePart timeH1bLocal area- ...GRC Consultant / Analyst / IT Risk & Compliance role Location: Norwalk,... ...on documentation, policy, governance and audit support Access... ...covering Artificial Intelligence, Cloud Migration, Custom Software... ...& Cloud Solutions, Cyber Security Services, etc. We make...Cloud
$155k - $165k
...Cybersecurity Risk Manager CVP is seeking a Cybersecurity... ...Manager for a large government agency enterprise-... ...such as information security policy development and... ...; security compliance monitoring; security audit... ..., but not limited to, cloud, mobile, and Internet...CloudContract workFor contractorsWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk & Compliance / Cloud Security Subject Matter Expert. Be the first to apply!




