Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics solution. This role will focus on security advisory, control assessment, authorization readiness, and risk mitigation while complementing the prime contractor’s hands-on DevSecOps and cybersecurity engineering teams.
The successful candidate will help ensure cybersecurity requirements, security controls, documentation, and authorization-readiness activities are integrated throughout the solution lifecycle, including design, development, testing, deployment, and transition.
This position requires a cybersecurity professional who can bridge technical security requirements with federal compliance expectations while effectively communicating risks and recommendations to technical teams, program leadership, and government stakeholders.
Key Responsibilities:
Cybersecurity Governance & Risk Advisory
Provide cybersecurity governance, risk, and compliance guidance throughout the program lifecycle.
Advise project teams on federal cybersecurity requirements, policies, and security best practices.
Support interpretation and implementation of FISMA Moderate requirements and NIST security controls.
Participate in cybersecurity risk assessments, technical design reviews, and security governance discussions.
Identify security gaps, residual risks, control deficiencies, and recommended mitigation strategies.
Communicate cybersecurity risks and compliance requirements to technical teams, leadership, and federal stakeholders.
Compliance & Authorization Support
Review security architectures, control implementations, security documentation, and technical evidence.
Support development and review of security documentation, including:
Security plans
Control narratives
Risk assessments
Plans of Action and Milestones (POA&Ms)
Authorization-readiness documentation
Support preparation activities for audits, security assessments, inspections, and authorization reviews.
Evaluate cybersecurity artifacts for completeness, accuracy, and alignment with federal compliance expectations.
Assist with continuous monitoring and ongoing authorization activities.
Security Engineering & Technical Review
Review cybersecurity practices related to:
Vulnerability management
Audit logging and monitoring
Identity and access management
Incident response
Configuration management
Provide guidance on software supply-chain security, including:
Software Bill of Materials (SBOM)
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Dependency analysis
Vulnerability remediation tracking
Collaborate with technical architects, DevSecOps engineers, program managers, and federal security stakeholders.
Support cybersecurity training, awareness, and knowledge-transfer activities.
Requirements
Qualifications:
Bachelor’s degree in Cybersecurity, Information Assurance, Information Systems, Computer Science, Risk Management, or related discipline.
Minimum 8 years of experience in cybersecurity, information assurance, security compliance, risk management, or federal cybersecurity programs.
Demonstrated knowledge of:
Federal Information Security Modernization Act (FISMA)
NIST Risk Management Framework (RMF)
NIST Special Publication 800-53 security controls
Experience reviewing security documentation, control evidence, risk assessments, authorization packages, or compliance artifacts.
Ability to analyze cybersecurity risks and translate technical requirements into actionable recommendations.
Strong written and verbal communication skills with the ability to engage technical and executive audiences.
Ability to obtain and maintain client-required suitability requirements, including Public Trust eligibility if required.
Preferred Qualifications:
CISSP, CISM, CRISC, CAP/CGRC, Security+, or comparable cybersecurity certification.
Experience supporting FISMA Moderate systems, federal authorization activities, or Authority to Operate (ATO) processes.
Familiarity with:
Cloud security practices
Identity and Access Management (IAM)
Vulnerability management
DevSecOps methodologies
Software supply-chain security
SBOM, SAST, and DAST processes
Experience supporting federal cybersecurity assessments, audits, inspections, continuous monitoring, or compliance programs.
Experience working with federal agencies or government contractors in mission-critical environments.
Security Requirement: Ability to obtain and maintain client-required suitability clearance or Public Trust determination.
Location Requirement: Candidates must be able to support periodic onsite meetings in Virginia.
Benefits
For any questions (OR) to apply, please contact us at [email protected]
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the US.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast!
Find the best jobs in the US, apply in 1 click and get a job today!