Governance, Risk & Compliance / Cloud Security Subject Matter Expert

Lexical Intelligence LLC

$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of information security experience with federal systems and ATO lifecycle under NIST RMF.
  • Expertise in NIST SP 800-53 control selection, implementation, and assessment.
  • Hands-on experience securing AWS multi-account architectures.
  • Experience with enterprise GRC platforms like JCAM or similar.
  • Knowledge of Security Impact Analyses and advising on security changes.
  • Development and testing of contingency plans and incident response plans.
  • Experience in vulnerability management with scanning tools.
  • Strong technical writing skills and attention to detail.
  • Effective communication of security requirements to various teams.
  • One or more relevant certifications like CISSP or AWS Certified Security - Specialty.

Responsibilities

  • Develop and maintain the system's ATO package in JCAM.
  • Support security assessments and coordinate evidence collection.
  • Advise on change and configuration management for security.
  • Develop contingency plans and coordinate incident response activities.
  • Advise on secure AWS architecture and security best practices.
  • Support vulnerability management and remediation efforts.
  • Translate federal security requirements into actionable guidance for teams.

Benefits

  • Full health and dental coverage for employee and dependents.
  • Health Savings Account (HSA) contributions.
  • 401k retirement plan options.
  • Short- and long-term disability insurance benefits.
  • Life and accident insurance coverage.
  • Generous paid time off policies.
  • 11 paid federal holidays annually.
Full Job Description
Lexical Intelligence is seeking a senior Governance, Risk & Compliance / Cloud Security Subject Matter Expert (GRC / Cloud SME) to serve as the security subject matter expert for a complex, cloud-native system supporting the National Institutes of Health (NIH). The system is fully deployed in Amazon Web Services (AWS) across multiple accounts and hosts multiple applications that process and analyze large-scale biomedical data.

This is a hands-on Governance, Risk, and Compliance (GRC) leadership role. The GRC / Cloud SME will own the development and maintenance of the system's Authority to Operate (ATO) package within JCAM (NIH's enterprise GRC platform), advise the program on the security implications of change and configuration management, and serve as the system's Contingency Planning and Incident Response Coordinator. The GRC / Cloud SME will act as the trusted security advisor to a cross-functional team of software developers, DevOps engineers, data scientists, and program leadership.

Key Responsibilities
  • ATO Package Development & Maintenance
    • Develop, maintain, and continuously improve the system's ATO package in JCAM, including the System Security Plan (SSP), control implementation statements, security policies and procedures, and all supporting artifacts.
    • Ensure the ATO package accurately reflects the as-built, multi-account AWS environment and remains current as the system evolves.
    • Support security assessments, audits, and annual control assessments; coordinate evidence collection and respond to assessor findings.
    • Manage Plans of Action & Milestones (POA&Ms): track weaknesses, coordinate remediation with engineering teams, and report status to the Authorizing Official's staff.
  • Change & Configuration Management Advisory
    • Serve as the security voice in the change and configuration management process: review proposed system changes, perform Security Impact Analyses (SIA), and advise the team on whether changes affect the authorization boundary or control posture.
    • Ensure security-relevant changes are documented, assessed, and reflected in the ATO package and continuous monitoring reporting.
    • Advise on secure configuration baselines and monitor for configuration drift across AWS accounts.
  • Contingency Planning & Incident Response Coordination
    • Serve as the system's Contingency Planning Coordinator: develop and maintain the Information System Contingency Plan (ISCP), plan and facilitate annual contingency plan tests and tabletop exercises, and document test results and lessons learned.
    • Serve as the system's Incident Response Coordinator: maintain the Incident Response Plan, coordinate incident detection, reporting, and response activities in accordance with NIH and HHS requirements, and lead incident response exercises.
    • Ensure backup, recovery, and resilience capabilities are documented, tested, and aligned with system recovery objectives.
  • Cloud Security Engineering & Team Advisory
    • Advise developers, DevOps engineers, and data scientists on secure architecture and AWS security best practices across a multi-account environment, including IAM, AWS Organizations and service control policies, encryption and key management (KMS), logging and monitoring (CloudTrail, CloudWatch, GuardDuty, Security Hub, AWS Config), and network security.
    • Support vulnerability management: review scan results, prioritize findings, and partner with engineering teams on remediation.
    • Advise on secure development and DevSecOps practices, including CI/CD pipeline security and infrastructure as code.
    • Serve as the day-to-day security advisor to the program, translating federal security requirements into practical guidance the team can act on.

Minimum Qualifications
  • 7+ years of information security experience, including direct support of federal systems and the full ATO lifecycle under the NIST Risk Management Framework (SP 800-37).
  • Deep, demonstrated expertise in NIST SP 800-53 control selection, implementation, and assessment, including authoring SSPs and control implementation statements.
  • Hands-on experience securing AWS environments, preferably multi-account architectures (AWS Organizations), including IAM, logging/monitoring services, and encryption/key management.
  • Experience developing and maintaining complete ATO packages within an enterprise GRC platform (e.g., JCAM, CSAM, eMASS, Xacta, or similar).
  • Experience performing Security Impact Analyses and advising change control processes on security-relevant changes.
  • Experience developing, maintaining, and testing contingency plans (NIST SP 800-34) and incident response plans (NIST SP 800-61).
  • Experience with vulnerability management and POA&M lifecycle management, including tools such as Tenable, Inspector, or similar scanners.
  • Strong technical writing and documentation skills with meticulous attention to detail.
  • Proven ability to communicate security requirements effectively to engineers, data scientists, and program leadership.
  • One or more of the following certifications: CISSP, CISM, AWS Certified Security - Speciality.
  • Cloud process knowledge
  • Linux familiarity

Preferred Qualifications
  • Direct experience with JCAM and supporting systems within NIH or other HHS agencies.
  • Experience with containerized environments and orchestration platforms (e.g., Kubernetes, Amazon EKS).
  • Exposure to infrastructure as code (e.g., Terraform) and automation of compliance or continuous monitoring activities.
  • Familiarity with large-scale data platforms, biomedical data, or research-focused systems, including data privacy considerations for sensitive or regulated data.
  • Experience supporting public-facing federal systems or APIs.
  • Additional relevant certifications such as CISSP, CGRC/CAP, CISM, CCSP, or AWS Certified Security - Specialty.
  • Cloud architecture / DevOps experience or knowledge

All candidates will be required to undergo a background check, must be authorized to work in the United States, and must be able to obtain and maintain an NIH badge with Public Trust Level Two suitability.

Location

Preference will be given to candidates within reasonable commuting distance of Bethesda, MD. Candidates outside the greater Washington, D.C. / Maryland / Virginia area may be responsible for their own transportation costs for badging, equipment retrieval, and in-person attendance when required.

Salary and benefits

We offer a competitive salary and a generous benefits package, including at no cost: full health and dental for you and your dependents, HSA account, 401k, short- and long-term disability insurance, life and accident insurance, paid time off, and 11 federal holidays.

Similar Jobs

More Jobs at Lexical Intelligence LLC

More Information Technology Jobs

Find similar Governance, Risk & Compliance / Cloud Security Subject Matter Expert jobs: