Location: Rockville, MD ( Hybrid) Job Overview: This position is focused on maintaining robust security, compliance, and risk management practices across Client systems. The specialist will play a key role in supporting security governance, ensuring operational compliance, and contributing to the ongoing maturity of Client's cybersecurity program. The Senior specialist will serve as a subject-matter expert and key contributor, partnering closely with internal teams, external contractors, and federal stakeholders to ensure that all systems and documentation adhere to FISMA, NIST, and NIH security standards. The variable regular hours role should not exceed 8 hours a week. Key Responsibilities Primary Security and Compliance Duties
- Maintain compliance with federal, NIH, and Client cybersecurity frameworks, including FISMA, NIST SP 800-53, and FedRAMP guidelines.
- Assist in the implementation and monitoring of technical and procedural controls that ensure ongoing compliance with NIST security controls and NIH policies.
- Contribute to the preparation, organization, and version control of documentation for governance, risk, and compliance (GRC) initiatives, ensuring accuracy and audit readiness.
- Support the assessment of security baselines, configuration standards, and vulnerability management activities, coordinating with the Client Security Operations Center and other NIH offices.
- Perform hands-on reviews of security documentation such as System Security Plans (SSP), POA&Ms, risk assessments, and audit reports to verify completeness and adherence to standards. Track and report compliance metrics to inform NINDS management on risk posture and mitigation progress.
Mentorship
- Provide peer-level mentoring and expert guidance to LCG and RMB security staff, fostering growth in technical knowledge, documentation standards, and compliance procedures.
- Design and deliver short, targeted workshops focused on process improvement, control validation, and audit preparation (not general end-user training).
- Contribute to the development of reusable training content such as checklists, templates, and security reference guides to support process consistency.
- Collaborate with the training coordinator to identify knowledge gaps and recommend upskilling opportunities in NIST RMF and NIH-specific tools. Model strong documentation discipline and best practices for information assurance, compliance reporting, and risk tracking.
Contract and End-User Engagement
- Coordinate with vendors and contractors throughout the Authorization to Operate (ATO) lifecycle, reviewing compliance artifacts and providing actionable feedback on required corrections.
- Support external teams in preparing required system documentation (e.g., Security Assessment Reports, risk responses, user access documentation).
- Assist in onboarding new contractors and verifying their adherence to NIH and Client security policies, user account management standards, and data protection requirements.
- Facilitate communication between internal compliance teams and external entities to ensure consistent application of security controls.
- Provide ongoing oversight and validation for approximately 500 end users and 6-10 external contractors.
Operational Consistency and Reporting
- Ensure consistent execution of recurring compliance activities and maintain predictable delivery of documentation and audit support.
- Collaborate with other security analysts to schedule and perform routine control reviews, risk assessments, and vulnerability tracking in accordance with Client timelines.
- Document procedural updates and change management activities, maintaining traceability for audit purposes.
- Prepare security compliance summaries and contribute to periodic audit reports and internal program updates.
- Participate in recurring Client meetings, reviews, and data calls, representing LCG as a technical compliance resource.
Qualifications
- Bachelor's degree in Information Technology, Cybersecurity, Instructional Design, or a related field (or equivalent experience).
- Minimum of 3-5 years of hands-on experience in IT security compliance, audit preparation, or security operations in a federal or healthcare environment.
- Proven experience with FISMA, NIST RMF (800-53), FedRAMP, and NIH GRC tools.
- Demonstrated ability to analyze audit findings, develop remediation plans, and validate corrective actions.
- Hands-on experience in security documentation management, POA&M tracking, and vulnerability mitigation processes.
- Ability to mentor junior security staff through example and technical collaboration, not direct supervision.
- Familiarity with Client systems, policies, and security operations workflows is highly preferred.
- Strong written and verbal communication skills, including technical writing for audits and compliance reports.
Compensation and Benefits The projected compensation range for this position is $55.00/hr to $60.23/hr benchmarked in the Washington DC Metro area. The salary range provided is a good faith estimate representative of all experience levels. Salary at LCG is determined by various factors, including but not limited to role, location, the combination of education/training, knowledge, skills, competencies, certifications, and work experience. LCG offers a competitive, comprehensive benefits package which includes health insurance options (medical, dental, vision), life and disability insurance, retirement plan contributions, as well as paid leave, federal holidays, professional development, and lifestyle benefits. Devoted to Fair and Inclusive Practices All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. If you are interested in applying for employment with LCG and need special assistance or an accommodation to apply for a posted position, contact our Human Resources department by email at hr@lcginc.com. Securing Your Data Beware of fraudulent job offers using LCG's name. LCG will never request payment-related details or advancement of money during the application process. Legitimate communication will only come from lcginc.com or system@hirebridgemail.com emails, not free commercial services like Gmail or WhatsApp. If you receive suspicious emails asking for payment or personal information, contact us immediately at hr@lcginc.com. If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
|