Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Officer

eSimplicity Inc

About Us:


eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow.

Purpose of Scope:

The Senior Information Security Analyst will provide security compliance, risk management, vulnerability management, audit, and

continuous monitoring support for a Centers for Medicare & Medicaid Services (CMS) program. This role requires extensive

knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS Acceptable Risk Safeguards (ARS).

The analyst will independently develop and maintain detailed security control implementation statements, evaluate supporting

evidence, conduct Security Impact Analyses, support Authorization to Operate activities, and prepare systems for security

assessments and audits. The analyst will also manage vulnerability and compliance findings throughout their lifecycle, including

validation, remediation coordination, POA&M management, risk exception development, retesting, and closure.

This position will work closely with CMS ISSOs, product owners, engineers, infrastructure teams, security assessors, auditors, and

program leadership. The successful candidate must be able to produce accurate, audit-ready security documentation, identify

compliance gaps, communicate security risks clearly, and drive assigned activities to completion with minimal supervision.

Responsibilities:
  • Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership.
  • Interpret FISMA, NIST RMF, NIST SP 800-53, CMS ARS, and agency security requirements and translate them into clear technical and operational actions.
  • Develop, review, and maintain detailed security control implementation statements that accurately reflect the system environment, responsible parties, processes, technologies, and supporting evidence.
  • Maintain and support ATO artifacts, including System Security Plans, Security Impact Analyses, POA&M, risk assessments, contingency plans, incident response plans, configuration management plans, and related documentation.
  • Lead Security Impact Analyses for proposed system, application, infrastructure, cloud, data, and configuration changes.
  • Support security assessments and audits by coordinating evidence collection, reviewing artifacts, responding to assessor inquiries, documenting gaps, and tracking corrective actions through closure.
  • Review vulnerability and compliance scan results; validate findings; assess risk; and coordinate remediation with product, engineering, infrastructure, and DevSecOps teams.
  • Develop and review vulnerability documentation, remediation plans, POA&M, false-positive determinations, and risk exception requests to ensure they are complete, accurate, and appropriately supported.
  • Track vulnerability and compliance findings through assignment, remediation, mitigation, risk acceptance, retesting, and closure.
  • Support continuous monitoring activities, access reviews, security data calls, compliance reporting, and security posture assessments.
  • Identify control, evidence, and documentation gaps and recommend corrective actions or process improvements to reduce security risk.
  • Develop security metrics, dashboards, status reports, and risk summaries for government stakeholders and program leadership.
  • Maintain timely and accurate communication regarding security risks, decisions, dependencies, overdue actions, and remediation status.
  • Mentor security team members and perform quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables.
Requirements
  • Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles, with demonstrated technical depth and increasing responsibility.
  • A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline.
  • Demonstrated experience supporting federal systems subject to FISMA and the NIST Risk Management Framework.
  • Experience applying NIST SP 800-53 security and privacy controls and CMS ARS or comparable federal security requirements.
  • Demonstrated experience developing, reviewing, and maintaining detailed, system-specific security control implementation statements and supporting evidence.
  • Experience supporting ATO activities and maintaining System Security Plans, Security Impact Analyses, POA&M, risk assessments, contingency plans, incident response plans, configuration management plans, and related security artifacts.
  • Experience leading or supporting security assessments and audits, including evidence collection, assessor responses, gap identification, corrective action planning, remediation tracking, and closure validation.
  • Experience managing vulnerability and compliance findings through validation, assignment, remediation, mitigation, risk acceptance, retesting, and closure.
  • Experience with vulnerability and compliance tools such as Tenable, Snyk, AWS Security Hub, AWS Inspector, or comparable platforms.
  • Ability to prepare technically supported risk exception requests and vulnerability documentation that includes affected assets, vulnerability-specific risk, compensating controls, mitigation analysis, remediation plans, owners, target dates, and validation methods.
  • Demonstrated ability to develop accurate, audit-ready documentation and communicate security requirements, risks, findings, and remediation activities to technical and non-technical stakeholders.
  • Demonstrated ability to manage concurrent assignments, meet established deadlines, maintain accurate status reporting, and elevate risks or blockers as appropriate.
  • Ability to obtain and maintain a Public Trust clearance and have resided in the United States for at least 3 of the last 5 years.
Desired Qualifications:
  • Direct experience supporting CMS systems, CMS security programs, or CMS ATO activities.
  • Advanced experience applying CMS ARS 5.0 or later to security control implementation, documentation, assessment, and continuous monitoring activities.
  • Demonstrated expertise writing and reviewing security control statements that clearly describe responsible parties, implementation methods, technologies, procedures, frequency, inheritance, and supporting evidence.
  • Experience leading control-statement reviews or control-mapping efforts resulting from CMS ARS updates, NIST SP 800-53 revisions, cloud migrations, system modernization, or authorization boundary changes.
  • Experience conducting Security Impact Analyses for application, infrastructure, cloud, data, integration, and configuration changes.
  • Experience supporting Security Control Assessments, FISMA audits, Office of Inspector General reviews, internal audits, penetration tests, or independent verification and validation activities.
  • Experience communicating directly with CMS ISSOs, security assessors, auditors, system owners, and government program leadership.
  • Experience securing or assessing AWS cloud environments and reviewing cloud security, access management, logging, monitoring, encryption, and configuration controls.
  • Familiarity with DevSecOps, CI/CD pipelines, source-code scanning, software composition analysis, container scanning, and security release reviews. Experience using Jira, Confluence, and ServiceNow to manage security documentation, vulnerabilities, compliance activities, risks, and corrective actions.
  • Experience developing security metrics, dashboards, audit-readiness reports, vulnerability reports, and executive-level risk summaries.
  • Current certification such as CISSP, CISM, CISA, CRISC, CAP/CGRC, CCSP, or an equivalent security or audit certification.
  • Experience mentoring security analysts and performing quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables.
Working Environment:

eSimplicity supports a remote work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by your manager.

Occasional travel for training and project meetings. It is estimated to be less than 5% per year.

Benefits:

eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms.

Reasonable Accommodation:

eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources.

Equal Employment Opportunity:

eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status.

#J-18808-Ljbffr
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Information Security Officer in Columbia, MD vacancy
  • $98.1k - $175.6k

     ...Public Sector is a trusted provider of secure, IP enabled, cloud-based, network solutions...  ...for anInformation Systems Security Officer to support the RIS I Government contract...  ...focused federal environment, helping ensure information systems remain compliant, protected, and... 
    Suggested
    Contract work
    Temporary work
    Work at office
    Local area
    Relocation

    AT&T

    Columbia, MD
    2 days ago
  • $146k - $234k

    ResponsibilitiesSeeking a System Engineer - Information Systems Security Officer (ISSO) to provide support for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies. Maintain operational security posture... 
    Suggested
    Contract work
    Shift work

    Peraton Corporation

    Annapolis Junction, MD
    15 hours ago
  • $103.8k - $218.1k

    Job Title: Information System Security Officer (ISSO)Job Category: SecurityTime Type: Full timeMinimum Clearance Required to Start: TS/SCI with PolygraphEmployee Type: RegularPercentage of Travel Required: Up to 10%Type of Travel: Local* * *The Opportunity:CACI as a Prime... 
    Suggested
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area
    Flexible hours

    CACI International

    Hanover, MD
    1 day ago
  • $131.3k - $237.35k

    Job DescriptionJob DescriptionInformation Systems Security Officer (ISSO)Leidos - Cyber & Analytics Business Area, Key Management & Analytics...  ....Leidos has an exciting opportunity for an experienced Information Systems Security Officer (ISSO) to join our Cyber & Analytics... 
    Suggested
    Full time
    Immediate start
    Remote work

    Leidos

    Laurel, MD
    15 hours ago
  •  ...These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on...  ...related to intelligence. INTELLIGENCE AND INFORMATION SECURITY CAREERS IN THE NAVY INTELLIGENCE OFFICER Analyze top-secret information, interpret spy... 
    Suggested
    Full time
    Part time
    Worldwide

    U.S. Navy

    Columbia, MD
    2 days ago
  • $131.3k - $237.35k

    Leidos has a new and exciting opportunity for a Senior Information System Security Officer in our National Security Sector's (NSS) Cyber & Analytics Business Area (CABA). Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission... 
    Full time
    Immediate start
    Flexible hours

    Leidos

    Annapolis Junction, MD
    1 day ago
  •  ...leadership ~ Strong documentation discipline ~ Active TS/SCI security clearance with a current polygraph is required....  ...#MDPM #MDFSP Peraton Labs is seeking a poly cleared Information System Security Officer for a mission-critical, highly complex HPC environment... 
    Full time
    For subcontractor
    Relocation package

    Jobleads-US

    Laurel, MD
    3 days ago
  •  ...Summary CTC Group is seeking Information Systems Security Officers (ISSO) , for a contingent program supporting the security and accreditation of classified information systems. In this role, you will help maintain a strong operational security posture, evaluate... 
    Full time

    CTC Group

    Maryland, MD
    5 days ago
  •  ...Directing and/or participating in the testing phase of the security controls assessments using specialized knowledge of network protocols...  ...researching and evaluating emerging technologies relevant to information systems security Interpreting agency specific and federal... 
    Full time
    Work experience placement

    nDepth Security, LLC

    Columbia, MD
    2 days ago
  •  ...Overview Position Title: Information System Security Officer  Location: Annapolis Junction, MD Reports To: Technical Task Lead Job Type: Full-time Clearance Requirement: TS/SCI with polygraph, U.S. citizen Summary: Leave things better than you... 
    Full time
    Contract work
    Work at office
    Local area
    Immediate start

    LufCo

    Annapolis Junction, MD
    more than 2 months ago
  •  ...What You Will Do: At Independent Software, as a Senior Information Systems Security Officer, you will provide senior-level cybersecurity and information assurance support for classified systems supporting IC and DoD missions. You will maintain and strengthen system... 
    Full time

    Independent Software

    Annapolis Junction, MD
    22 days ago
  •  ...in advance to identify qualified candidates for potential openings.* Description Responsible for determining enterprise information security standards. Develop and implements information security standards and procedures. Provide tactical information security... 
    Full time
    Contract work

    Orion Consortium

    Maryland, MD
    26 days ago
  •  ...Position Summary Base-2 Solutions is seeking a Senior Information Systems Security Officer responsible for safeguarding computer networks and systems to the highest standards, ensuring data security, integrity, and confidentiality. Essential Duties and Responsibilities... 

    Jobleads-US

    Elkridge, MD
    3 days ago
  • $155k - $195k

     ...been voted Baltimore Business Journal's (BBJ) Best Places to Work 2026! Belay Technologies is seeking an experienced Information Systems Security Officer (ISSO) for a large software development program. The program includes software maintenance and development, IT... 
    Full time
    Contract work
    Work experience placement
    Flexible hours

    Belay Technologies

    Annapolis Junction, MD
    19 days ago
  • $50k - $80k

     ...Description Are you looking for the opportunity to utilize your Information Systems experience and be part of a growing and innovative...  ...functioning at peak performance. Information Systems Security Officer – Entry Job Description: Provides support for a program,... 
    Work experience placement

    Roseman Advance Computer Technology and Solutions Corp

    Columbia, MD
    23 days ago
  •  ...License Additional courses in physical therapy are advantageous Additional Skills/Competencies Medicine – Knowledge of the information and techniques needed to diagnose and treat human injuries, diseases, and deformities. This includes symptoms, treatment... 
    Local area
    Relocation package

    Excelsia Injury Care

    Columbia, MD
    3 days ago
  •  ...compensation (based on experience) Supportive team and fully equipped office Opportunity for growth and additional hours...  ...your resume and a brief cover letter to ****@*****.*** or call at (***) ***-**** for more information. Powered by JazzHR... 
    Hourly pay
    Part time
    Work at office
    Flexible hours

    The Joint Chiropractic

    Columbia, MD
    2 days ago
  • $78k - $117k

     ...Job Description Job Description Overview Information Systems Security / Information System Security Officer (ISSO) LOCATION: Columbia, MD JOB STATUS: Full-time CLEARANCE: Ability to obtain TS CERTIFICATION: CAP, CISSM, or CISSP TRAVEL: Less than... 
    Full time
    Local area

    Astrion

    Columbia, MD
    27 days ago
  •  ...motivated, career driven, and customer-focusedInformationSystem Security Officer (ISSO) to join our team inAnnapolis Junction, Maryland. You...  ..., and customers, including delivering presentations. Must be able to exchange accurate information in these situations ManTech
    Work at office

    ManTech

    Annapolis Junction, MD
    2 days ago
  • Information Systems Security Officer (ISSO) II BTS Software Solutions is seeking an Information Systems Security Officer (ISSO) II with an active TS/SCI w/ POLY to join our team in Laurel, MD What You'll Get To Do: Provides support for a program, organization, system,... 
    Local area

    BTS Software Solutions

    Laurel, MD
    1 day ago
  • Job Description Quevera is seeking an Information Systems Security Officer to join our team. At Quevera, we don’t just offer jobs—we provide opportunities to be part of a dynamic, forward-thinking community that fosters innovation, collaboration, and personal growth. You... 
    Temporary work
    Work experience placement

    Quevera

    Odenton, MD
    1 day ago
  • $250k - $300k

     ...who depend on them. As Chief Technology Officer, you will define and lead the technical...  ...that translate deep domain expertise into secure, innovative technology that makes a...  ...Business, Engineering, Computer Science, Information Technology, or related discipline. ~... 
    Full time
    Remote work

    eSimplicity Inc

    Columbia, MD
    4 days ago
  • $140k - $155k

     ...Job Description Job Description Position Overview TAP Engineering is seeking an Information Systems Security Officer (ISSO) to help deliver enhanced HPC capabilities across multi-vendor HPC servers, HPC clusters, and specialized processing environments. You'll... 
    Temporary work
    Flexible hours

    TAP Engineering

    Annapolis Junction, MD
    7 days ago
  • $90k - $110k

    Chiropractor Columbia MD Full Time | $90K - $110K+ per year (DOE) + Bonus Opportunities | Full Benefits We are seeking a dynamic, motivated Chiropractor to join our growing multidisciplinary practice full time in Maryland with floating/coverage role serving Columbia...
    Full time
    Temporary work

    HCRC Staffing

    Columbia, MD
    3 days ago
  •  ...Base-2 Solutions seeks a Senior Information Systems Security Officer to safeguard networks and systems to the highest standards, ensuring data security, integrity, and confidentiality across environments. The role emphasizes implementing IA controls, conducting vulnerability... 

    Jobleads-US

    Elkridge, MD
    3 days ago
  • $112.5k - $170k

     ...responsibility is to ensure that Allegis Global Solutions, Inc.’s (AGS) information security and data privacy initiatives support the global business...  ...corporate headquarters as well as local and global remote offices adhere to all applicable laws and regulations. In... 
    Permanent employment
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work

    Allegis Global Solutions

    Hanover, MD
    20 days ago
  • $110k - $220k

     ...vulnerabilities of and attacks against specific systems. Produce formal and informal reports, and briefings to present to the Government Customer....  ...design/development, programming, information/cyber/network security, systems engineering, and/or network and/or system... 
    Work experience placement
    Local area

    BTS Software Solutions

    Columbia, MD
    2 days ago
  •  ...communications domains. You will work with cybersecurity and CNO specialists, conduct reverse engineering, and contribute to next‑generation mobile and embedded systems, while ensuring secure development practices and high-quality deliverables. #J-18808-Ljbffr Jobleads-US

    Jobleads-US

    Columbia, MD
    1 day ago
  •  ...members with industry partners in real-world job experiences. More information can be found here: Eligibility Requirements: Meet all DoW...  ...required Must be able to report daily to Columbia, MD office Minimum six (6) years of experience in one or more of the following... 
    Contract work
    Apprenticeship
    Work experience placement
    Internship
    Work at office
    Local area

    IntelliGenesis LLC

    Columbia, MD
    1 day ago
  • $185k

     ...required. Maintain JIRA and Confluence pages for all products, tracking progress, features, and objectives, and keeping the government informed on any items that are falling behind schedule. Manage teams during Program Increment (PI) events, ensuring alignment with... 

    X8

    Columbia, MD
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!