Security Engineer
Information Systems Security EngineerThe Information Systems Security Engineer manages the compliance team that creates or updates security and privacy documentation according to NIST SP 800-53 Rev 4 requirements, including system security plans, security reports, and privacy assessments. The engineer works with department subject matter experts (SMEs) to develop and document control implementation descriptions that meet or exceed the security-control compliance requirements.The engineer develops policies and procedures based on security-control implementations for each business unit and system component in scope of the system boundary. The engineer inputs and maintains security-controls and associated artifacts in the organizations Governance, Risk and Compliance (GRC) system. The Information Systems Security Engineer performs other tasks as assigned, such as updating diagrams, taking screen captures for insertion into documentation, and planning documentation schedules to meet defined project milestones. The engineer should be comfortable working independently with guidance from a project manager and amongst a team.Responsibilities:Manage the security and compliance efforts for the migration project of a Medicaid eligibility system.Provide management and oversight for security and compliance team to ensure the successful authorization of a Medicaid eligibility systemReview and submit the System Security Plan (SSP), System Security Plan (SSP) Workbook, IRS Safeguard Security Report (SSR), Privacy Impact Assessment (PIA), Information Security Risk Assessment (ISRA), Computer Matching Agreement (CMA), Information Exchange Agreement (IEA), and Interconnection Security Agreement (ISA)Drive the development process for control implementation, policies, and procedures to meet federal requirementsCoordinate with department subject matter experts on all aspects of policies and proceduresCoordinate and develop risk mitigation and remediation efforts for all deficiencies identified for the systemMaintain security controls catalog and associated artifacts in department GRCPlan yearly security and compliance milestones and associated resources required to satisfy milestonesDevelop documentation plans and schedulesManage updates and revisions to existing documentationIdentify new documentation needs or opportunitiesCoordinate and lead meetings with relevant personnel for updates and completion of Plans of Action and Milestones (POAMs) and Corrective Action Plans (CAPs)Develop and deliver compliance report KPIs and body of evidence to federal partner reporting platforms and DHS leadershipAchieve and maintain relevant knowledge on organizations mission and information system structureCollaborate with team on meeting security and privacy requirementsParticipate in other security and compliance projects as neededNeeded Soft Skills:Time management skills with the ability to operate under short deadlinesSelf-starter with minimal management supervisionAbility to work under pressure and manage fluctuating workloadsWork in a team settingAbility to gain consensusMaintain confidentialityExcellent written and verbal communication skillsCandidates must bring samples of policies and procedures they have developed to interview.