Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Officer

eSimplicity

Description

About Us:

eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow.

Purpose of Scope: The Senior Information Security Analyst will provide security compliance, risk management, vulnerability management, audit, and continuous monitoring support for a Centers for Medicare & Medicaid Services (CMS) program. This role requires extensive knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS Acceptable Risk Safeguards (ARS). The analyst will independently develop and maintain detailed security control implementation statements, evaluate supporting evidence, conduct Security Impact Analyses, support Authorization to Operate activities, and prepare systems for security assessments and audits. The analyst will also manage vulnerability and compliance findings throughout their lifecycle, including validation, remediation coordination, POA&M management, risk exception development, retesting, and closure. This position will work closely with CMS ISSOs, product owners, engineers, infrastructure teams, security assessors, auditors, and program leadership. The successful candidate must be able to produce accurate, audit-ready security documentation, identify compliance gaps, communicate security risks clearly, and drive assigned activities to completion with minimal supervision. Responsibilities: Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership. Interpret FISMA, NIST RMF, NIST SP 800-53, CMS ARS, and agency security requirements and translate them into clear technical and operational actions. Develop, review, and maintain detailed security control implementation statements that accurately reflect the system environment, responsible parties, processes, technologies, and supporting evidence. Maintain and support ATO artifacts, including System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related documentation. Lead Security Impact Analyses for proposed system, application, infrastructure, cloud, data, and configuration changes. Support security assessments and audits by coordinating evidence collection, reviewing artifacts, responding to assessor inquiries, documenting gaps, and tracking corrective actions through closure. Review vulnerability and compliance scan results; validate findings; assess risk; and coordinate remediation with product, engineering, infrastructure, and DevSecOps teams. Develop and review vulnerability documentation, remediation plans, POA&Ms, false-positive determinations, and risk exception requests to ensure they are complete, accurate, and appropriately supported. Track vulnerability and compliance findings through assignment, remediation, mitigation, risk acceptance, retesting, and closure. Support continuous monitoring activities, access reviews, security data calls, compliance reporting, and security posture assessments. Identify control, evidence, and documentation gaps and recommend corrective actions or process improvements to reduce security risk. Develop security metrics, dashboards, status reports, and risk summaries for government stakeholders and program leadership. Maintain timely and accurate communication regarding security risks, decisions, dependencies, overdue actions, and remediation status. Mentor security team members and perform quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables. Requirements Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles, with demonstrated technical depth and increasing responsibility. A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline. Demonstrated experience supporting federal systems subject to FISMA and the NIST Risk Management Framework. Experience applying NIST SP 800-53 security and privacy controls and CMS ARS or comparable federal security requirements. Demonstrated experience developing, reviewing, and maintaining detailed, system-specific security control implementation statements and supporting evidence. Experience supporting ATO activities and maintaining System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related security artifacts. Experience leading or supporting security assessments and audits, including evidence collection, assessor responses, gap identification, corrective action planning, remediation tracking, and closure validation. Experience managing vulnerability and compliance findings through validation, assignment, remediation, mitigation, risk acceptance, retesting, and closure. Experience with vulnerability and compliance tools such as Tenable, Snyk, AWS Security Hub, AWS Inspector, or comparable platforms. Ability to prepare technically supported risk exception requests and vulnerability documentation that includes affected assets, vulnerability-specific risk, compensating controls, mitigation analysis, remediation plans, owners, target dates, and validation methods. Demonstrated ability to develop accurate, audit-ready documentation and communicate security requirements, risks, findings, and remediation activities to technical and non-technical stakeholders. Demonstrated ability to manage concurrent assignments, meet established deadlines, maintain accurate status reporting, and escalate risks or blockers as appropriate. Ability to obtain and maintain a Public Trust clearance and have resided in the United States for at least 3 of the last 5 years. Desired Qualifications: Direct experience supporting CMS systems, CMS security programs, or CMS ATO activities. Advanced experience applying CMS ARS 5.0 or later to security control implementation, documentation, assessment, and continuous monitoring activities. Demonstrated expertise writing and reviewing security control statements that clearly describe responsible parties, implementation methods, technologies, procedures, frequency, inheritance, and supporting evidence. Experience leading control-statement reviews or control-mapping efforts resulting from CMS ARS updates, NIST SP 800-53 revisions, cloud migrations, system modernization, or authorization boundary changes. Experience conducting Security Impact Analyses for application, infrastructure, cloud, data, integration, and configuration changes. Experience supporting Security Control Assessments, FISMA audits, Office of Inspector General reviews, internal audits, penetration tests, or independent verification and validation activities. Experience communicating directly with CMS ISSOs, security assessors, auditors, system owners, and government program leadership. Experience securing or assessing AWS cloud environments and reviewing cloud security, access management, logging, monitoring, encryption, and configuration controls. Familiarity with DevSecOps, CI/CD pipelines, source-code scanning, software composition analysis, container scanning, and security release reviews. • Experience using Jira, Confluence, and ServiceNow to manage security documentation, vulnerabilities, compliance activities, risks, and corrective actions. Experience developing security metrics, dashboards, audit-readiness reports, vulnerability reports, and executive-level risk summaries. Current certification such as CISSP, CISM, CISA, CRISC, CAP/CGRC, CCSP, or an equivalent security or audit certification. Experience mentoring security analysts and performing quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables. Working Environment: eSimplicity supports a remote work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by your manager. Occasional travel for training and project meetings. It is estimated to be less than 5% per year. Benefits: eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms. Reasonable Accommodation: eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources. Equal Employment Opportunity: eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Information Security Officer in Oregon State vacancy
  • $115.4k - $230.7k

     ...Are you passionate about driving security compliance in complex cloud environments and helping...  ...decisions. By bringing clarity to information, we ultimately help make communities safer...  ...experienced Information System Security Officer (ISSO) to lead and maintain the security... 
    Suggested
    Full time
    For contractors
    Work experience placement
    Local area

    RELX

    Oregon State
    1 day ago
  •  ...associated equipment and software. Assists Information Technology Director, and Information...  ...maintenance and upgrades. Maintains network security, reliability, and integrity.   Ensures...  ...Work will take place in a small office environment with occasional exposure to... 
    Suggested
    Work at office

    Chinook Winds Casino Resort Hotel

    Lincoln City, OR
    7 days ago
  •  ...****@*****.***, based in Medford, Oregon, seeks a dynamic, service-oriented executive to serve as its next Chief Information Officer (CIO) for the health system. Reporting to the Senior Vice President, this is an extraordinary opportunity for a talented,... 
    Suggested

    Asante

    Medford, OR
    4 days ago
  •  ...accommodation or an alternative application process. Director of Information Technology Albany, OR, US Director of Information...  ...semiconductor customer expectations (e.g., NIST, supply‑chain security). Establish business continuity and disaster recovery strategies... 
    Suggested
    Contract work

    Petersen

    Albany, OR
    5 days ago
  • $90k

     ...manage your insurance and deal with all of your business administration, as well as ensuring that you have the financial stability and security to think long term. The Joint Chiropractic is growing so fast that we can barely keep up our supply for the demand for our... 
    Suggested
    Full time
    Part time
    Monday to Friday
    Flexible hours
    Weekend work

    Joint Ventures , LLC

    Beaverton, OR
    4 days ago
  •  ...services across a diverse client base. The Director leads technical teams, drives process, and partners with clients to deliver scalable, secure, and reliable IT services. Team Management & Technical Oversight Lead and manage the IT Desktop Support team and Systems... 

    WorkSource Oregon

    Eugene, OR
    2 days ago
  • $120k

     ...hands- on experience, or an experienced DC looking for financial security, we have a supportive and welcoming team, dedicated to family...  ...healthcare. Please send your resume to ****@*****.*** Brian Torchin | CEO HCRC Staffing Office (***) ***-**** ****@*****.***
    Full time
    Part time
    Work at office
    Weekend work

    National Coalition of Healthcare Recruiters

    Wood Village, OR
    1 day ago
  •  ...Oregon is seeking an IT Manager to provide day-to-day leadership for our technology infrastructure and Service Desk, ensuring reliable, secure solutions across clinical, administrative, and operational needs in alignment with the CIO’s strategic direction. You will... 

    Mosaic Community Health

    Bend, OR
    5 days ago
  • $9.23k - $13.64k

     ...Deputy Chief Information OfficerDeputy Chief Information Officer (Manager 3) Limited Duration | Full TimeAt the Oregon Public Defense Commission, we are committed...  ..., and abilities:Data Governance & StewardshipData Security & Technical ExpertiseStrategic Thinking & Executive... 
    Permanent employment
    Full time
    Work experience placement
    Work at office
    Flexible hours
    2 days per week
    3 days per week

    State of Oregon

    Salem, OR
    2 days ago
  • Part Time Chiropractor Oregon Integrated Health is an Integrated Primary Care Medical Home that is hiring for a Part Time Chiropractor for our Clinic in Florence Oregon. We are currently a Tier 4 Patient Centered Primary Care Medical Home, Vaccine for Children Program...
    Part time
    Flexible hours
    2 days per week
    1 day per week

    Oregon Integrated Health

    Florence, OR
    5 days ago
  • $85k - $120k

     ...as well as ensuring that you have the financial stability and security to think long term. Underpinning all of this is a clear set of...  ...an innovative force, where healthcare meets retail. For more information, visit   Business Structure The Joint Corp. is a franchisor... 
    Full time
    Part time
    Weekend work

    The Joint Chiropractic

    Bend, OR
    3 days ago
  •  ...including upper and lower extremity conditions. You’ll collaborate closely with acupuncturists and massage therapists to deliver evidence-informed, patient-centered care with strong outcomes and clear communication. Values Attunement: Returning to harmony—body, mind, and... 
    Flexible hours
    Shift work

    Attunement Wellness

    Portland, OR
    1 day ago
  • Looking for the right chiropractor to join our small team environment and make a big impact. We utilize acupuncture, massage, and chiropractic care in a welcoming upbeat environment to treat patients who are seeking auto injury rehabilitation, as well as private insurance...

    D'Vida Injury Clinic & Wellness Center

    Beaverton, OR
    4 days ago
  • $120k

     ...quality of life of so many! Whether you're a graduate looking for hands-on experience, or an experienced DC looking for financial security, we have a supportive and welcoming team, dedicated to family chiropractic and spine health. We invite you to join us in providing... 
    Full time
    Part time

    HCRC Staffing

    Troutdale, OR
    3 days ago
  • $122k - $240.5k

     ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this...  ...:Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent demonstrated experience... 
    Local area
    Visa sponsorship

    Deloitte

    Portland, OR
    1 day ago
  • $105.4k - $207.8k

     ...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support...  ..., and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation... 
    Local area
    Visa sponsorship

    Deloitte

    Portland, OR
    10 hours ago
  • $165.61k

     ...TimeCity of Portland, OregonChief Strategy & Change Management Officer Annual Salary: $165,609 to $240,739 The city offers a...  ...and guide Portland through sustained transformation.For more information and to apply, please go to the dedicated recruitment page at:... 
    Local area

    ICMA

    Portland, OR
    2 days ago
  • $163.4k - $322.1k

    Position Summary Drive strategic consulting, advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities, and build resilience across people, facilities, assets, and operations. This... 
    Local area
    Visa sponsorship

    Deloitte

    Portland, OR
    3 days ago
  • $91k

     ...core technology platforms, including monitoring performance, security, and compliance. Ensure that the team makes the most effective...  ...across the team. Also note, the compensation and benefits information provided in this posting is specific to candidates residing in... 
    Full time
    Local area
    Immediate start
    Remote work
    Monday to Friday

    New Roots Institute

    Portland, OR
    1 day ago
  • $134.5k - $265.1k

     ...resilient organizations must protect not only data and technology, but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address evolving threats through integrated security strategies, technologies, and managed... 
    Contract work
    Local area
    Visa sponsorship

    Deloitte

    Portland, OR
    3 days ago
  • $134.5k - $265.1k

     ...automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to...  ...:Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience... 
    Local area
    Visa sponsorship

    Deloitte

    Portland, OR
    10 hours ago
  • $75k - $85k

     ...Cyber is a leading platform-enabled unified security operations company providing a...  ...headquartered in McLean, Virginia, with global offices across the U.S. and in India.  We are...  ...for notable security events Monitor information security alerts through Splunk to respond... 
    Full time
    Temporary work
    Rotating shift

    Ultraviolet Cyber

    Portland, OR
    more than 2 months ago
  •  ...on the Team: Designs, tests, and implements state-of-the-art secure operating systems, networks, and database products. Conducts risk...  ...vulnerability analysis of various security technologies, and information technology security research. May prepare security reports to... 

    BizTek People

    Portland, OR
    1 day ago
  • $102.17k

     ...clients across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will...  ...mental disability, veteran status, citizenship status, genetic information or any other characteristic protected by applicable law. Background... 
    Work experience placement
    H1b

    Trinnex

    Salem, OR
    4 days ago
  •  ...Cyber Security Analyst As a Cyber Security Analyst, your role on the team will include leveraging your knowledge of industry best...  ...or related field, or equivalent work experience Five years of information technology experience with two years in an information security... 
    Work experience placement
    Shift work
    Afternoon shift

    BizTek People

    Beaverton, OR
    1 day ago
  • $50 - $52 per hour

     ...CW-Cyber Security Analyst III Immediate need for a talented CW-Cyber Security Analyst III. This is a 18+ months contract opportunity...  ...transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers... 
    Contract work
    Local area
    Immediate start

    Pyramid Corporation

    Portland, OR
    2 days ago
  •  ...CW-Cyber Security Analyst III The Sr. Info Security Analyst drafts, communicates, implements, enforces and monitors the organization...  ...to ensure the security and safety of the organization's information. Key Responsibilities and Duties Ensures implementation... 
    Work experience placement

    eTeam

    Portland, OR
    1 day ago
  •  ...This position is open to current Cyber Security Analyst I's (Paygrade Opportunity) and Cyber Security Analyst II's within the City of Los Angeles. Please see attachment for further information. How to apply Interested candidates, please e-mail a City Application... 

    City of Los Angeles

    Brookings, OR
    1 day ago
  • $228k - $260k

     ...Company Fasteners Division /*generated inline style */ Function Information Technology /*generated inline style */ Workplace Type On-...  ...growth and acquisition integration activities.Ensure the security, integrity, and availability of all information systems and data... 
    Permanent employment
    Full time
    Local area
    Worldwide
    Relocation

    Precision Castparts Corp

    Portland, OR
    10 hours ago
  •  ...environments. Evaluate application functionality, workflows, roles, security, databases, and system integrations. Support application...  ...’s license required.   Technology Environment Microsoft Office 365 Microsoft Azure / Entra ID / Active Directory Tyler... 
    Full time
    Contract work
    Work at office
    Remote work
    Monday to Friday

    Robert Half

    Beaverton, OR
    14 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!