Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for A&A working sessions and pilots (typically 1-2 days/week during the first 120 days, then as scheduled).
Citizenship: U.S. Citizenship required
Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation.
Salary Range: $90,000-$100,000 yearly salary
Overview:
You will map NIH's FISMA systems to the Zero Trust controls they can inherit and help make Zero Trust assessable inside NIH's A&A process under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Risk & Policy Pod on Task 4 and Subtasks 2.5 and 1.2, reporting technically to the Security Lead.
Responsibilities:
- Pull the CSAM inventory and map the control set of each of NIH's 72 FISMA-registered systems against the Centrally Provided Services Matrix. Identify inherited, hybrid, and uncovered controls for the Inherited Controls Mapping and Remediation Roadmap (Subtask 2.5, due at 120 days, refreshed quarterly).
- Score residual gaps by FIPS 199 impact, data sensitivity, and internet exposure.
- Support the Task 4 pipeline baseline: time per phase, rework loops, inherited versus re-documented controls, and upcoming authorizations.
- Build the ZTA Overlay mappings and evidence expectations, tagging each control as central, hybrid, or system-specific. Support the CSAM import and the three-system pilot.
- Maintain records in the shared NIH ZTA control library.
- Develop package templates (SSP, SAP/SAR, POA&M) and continuous-monitoring cadences (SP 800-137) for the three authorization tiers.
- Keep the IC-inheritable controls content current on the OCIO ZTA Wiki, and answer control questions routed from the ZTA help desk.
Tools & Technology Environment: CSAM (primary), Xacta, RSA/SGRC Archer, ServiceNow; Excel and Power BI; Confluence/SharePoint and the OCIO ZTA Wiki.
Required Qualifications:
- Bachelor's degree plus 4+ years of RMF/A&A experience in a federal environment.
- Working knowledge of NIST SP 800-37 Rev 2, 800-53 Rev 5, 800-53A, and FISMA.
- Hands-on POA&M management and experience with CSAM or a comparable GRC tool.
- Security+ or CAP/CGRC certification.
- Current T2 (BI) or higher federal background investigation, acceptable through reciprocity.
Preferred Qualifications:
- HHS or NIH A&A experience in CSAM.
- Common-control and inheritance modeling; experience with Zero Trust control mapping.
- FedRAMP experience; CGRC or CISA certification.
- Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred.