Description
Presidio, Where Teamwork and Innovation Shape the Future At Presidio, we're at the forefront of a global technology revolution, transforming industries through cutting-edge digital solutions and next-generation AI. We empower businesses - and their internal customers - to achieve more through innovation, automation, and intelligent insights. The Role This position is responsible for managing and maintaining all documentation, governance activities, compliance initiatives, and operational processes necessary to attain and maintain security authorizations and certifications supporting State, Local, Education, and Government (SLED) customers. The individual will possess strong knowledge of NIST-based security frameworks, including NIST SP 800-53 Moderate, FedRAMP, GovRAMP, StateRAMP, CJIS Security Policy, NIST Cybersecurity Framework (CSF), NIST SP 800-171, HIPAA, and related regulatory requirements. The individual will be experienced in information security governance, risk management, compliance, authorization package development, audit readiness, security documentation, incident response planning, business continuity planning, and continuous monitoring activities. The position requires strong technical writing skills, the ability to analyze risk, develop policies and procedures, coordinate with technical and business stakeholders, and support enterprise-wide compliance initiatives. Responsibilities Include:
- Leads the development and maintenance of security architecture, governance frameworks, policies, standards, procedures, and control implementation guidance.
- Supports security authorization initiatives aligned to NIST SP 800-53 Moderate, FedRAMP Moderate, GovRAMP, StateRAMP, CJIS Security Policy, HIPAA, NIST SP 800-171, and related regulatory frameworks.
- Assembles, develops, maintains, and updates System Security Plans (SSP), supporting documentation, and authorization package artifacts.
- Maps implemented security control requirements to NIST SP 800-53 Moderate baselines, CJIS Security Policy, FedRAMP, GovRAMP, and other applicable control overlays.
- Documents implemented, inherited, hybrid, and customer-responsibility controls within authorization packages.
- Collects, validates, organizes, and maintains technical, administrative, and procedural evidence supporting compliance and assessment activities.
- Establishes and maintains centralized control evidence repositories utilizing governance and compliance management platforms such as Vanta or equivalent technologies.
- Supports independent assessors, auditors, regulators, customers, and internal stakeholders during assessments, walkthroughs, interviews, demonstrations, and evidence reviews.
- Develops, maintains, and tracks Plan of Action and Milestones (POA&M) documentation, remediation activities, corrective action plans, and risk mitigation efforts.
- Tracks security findings, compliance gaps, remediation activities, risk acceptances, and corrective action plans through closure.
- Evaluates existing information security policies, standards, procedures, and governance documentation and recommends improvements ensuring compliance with applicable frameworks.
- Develops, maintains, and updates compliance-aligned policies, standards, procedures, and governance documentation supporting authorization readiness.
- Defines roles, responsibilities, accountability requirements, and separation-of-duty controls supporting governance and compliance programs.
- Establishes processes supporting risk management, control assessment, continuous monitoring, and control validation.
- Aligns organizational security policies and governance requirements with implemented technical controls and operational practices.
- Develops and maintains governance framework documentation, security program documentation, and compliance operating procedures.
- Develops and maintains Incident Response Plans (IRP), incident response procedures, and incident response playbooks aligned to regulatory reporting and notification requirements.
- Develops and maintains Business Continuity Plans (BCP), Disaster Recovery Plans (DRP), backup strategies, recovery procedures, and restoration processes.
- Conducts tabletop exercises, functional exercises, continuity exercises, and after-action reviews to validate incident response and disaster recovery capabilities.
- Maintains documentation and evidence supporting Incident Response (IR), Contingency Planning (CP), and other control families.
- Defines and documents operational security processes including access request management, identity lifecycle management, privileged access controls, change management, configuration management, vulnerability management, and security exception processes.
- Establishes onboarding and offboarding workflows supporting personnel security and access control requirements.
- Supports implementation and operation of change management processes.
- Participates in internal and external audits, compliance assessments, control reviews, and continuous monitoring activities.
- Defines security awareness, role-based training, and compliance training requirements.
- Maintains training records, compliance evidence, and authorization readiness documentation.
- Collaborates with cross-functional teams including security engineering, cloud engineering, infrastructure, service delivery, legal, compliance, and executive leadership teams.
- Participates in incident response activities, risk assessments, and compliance audits.
- Supports current system analysis to identify and recommend technical and administrative controls required to satisfy compliance obligations.
- Provides technical expertise and compliance guidance for the information security program.
- Collaborates as a member of the Information Security Office to maintain compliance objectives and authorization readiness.
- Maintains communication with the Director, Information Security, regarding security posture, compliance initiatives, audit readiness, authorization activities, risks, and remediation efforts.
- Ensures Presidio maintains compliance with security requirements and authorization obligations.
- Ensures compliance with framework requirements necessary to obtain and maintain certifications and government authorizations.
- Provides emergency on-call support as required.
- Performs other duties as assigned.
Required Skills and Professional Experience:
- Associate degree (preferably in Computer Science, Cybersecurity, Information Systems, Information Security, or related field from an accredited college or university) or the equivalent work experience and/or military experience
- 3+ years of experience supporting information security, governance, risk, compliance, audit, or authorization programs.
- One or more security certifications such as Security+, CISSP, CISA, CGRC (CAP), CRISC, CASP+, CCSP, GIAC, CSA, or equivalent.
- Experience supporting NIST SP 800-53 Moderate, FedRAMP, GovRAMP, StateRAMP, CJIS Security Policy, NIST Cybersecurity Framework (CSF), NIST SP 800-171, HIPAA, or other SLED-related compliance programs.
- Experience developing and maintaining System Security Plans (SSP), POA&M documentation, security policies, standards, procedures, and authorization artifacts.
- Intermediate to advanced technical writing skills with demonstrated experience producing compliance and governance documentation.
- Experience supporting independent assessments, audits, reviews, and authorization activities.
- Experience with governance, risk, and compliance platforms including Vanta, Drata, Archer, ServiceNow, or similar technologies.
- Understanding of technical concepts and security technologies including cloud computing, identity and access management, VPNs, firewalls, web application firewalls, vulnerability management, endpoint protection, logging, monitoring, and network security controls.
- Skills in project prioritization, issue management, remediation tracking, risk assessment, and problem resolution.
- Exceptional writing skills combined with strong presentation and communication skills.
- Expert analytical thinking skills, including the ability to summarize information and clearly identify risks, findings, trends, and remediation requirements.
- Experience creating, generating, maintaining, and reporting on compliance metrics, audit evidence, control documentation, and security reporting.
- Experience utilizing artificial intelligence tools and technologies to improve documentation, compliance operations, and security processes.
- Ability to manage multiple projects, priorities, audits, and compliance initiatives simultaneously.
- Ability to communicate and translate security risks to technical and non-technical audiences.
- Ability to analyze complex security and compliance issues and develop practical solutions.
Preferred Skills and Professional Experience:
- Experience working with cloud service providers including Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
- Customer service skills and client focus.
- Strong communication skills, including the ability to communicate technical information in non-technical language.
- Strong time management and organizational skills.
- Strong problem-solving and analytical skills.
- Excellent interpersonal skills.
- Comprehensive verbal and written communication skills.
- Ability to remain calm and effective during audits, assessments, security incidents, and periods of increased workload.
- Ability to work on multiple projects simultaneously.
- Ability to work effectively with stakeholders across all organizational levels.
- Experience working with public-sector, education, healthcare, or regulated industry customers.
Your future at Presidio Joining Presidio means stepping into a culture of trailblazers - thinkers, builders, and collaborators - who push the boundaries of what's possible. With our expertise AI-driven analytics, cloud solutions, cybersecurity, and next-gen infrastructure, we enable businesses to stay ahead in an ever-evolving digital world. Here, your impact is real. Whether you're harnessing the power of Generative AI, architecting resilient digital ecosystems, or driving data-driven transformation, you'll be part of a team that is shaping the future. Ready to innovate? Let's redefine what's next-together. About Presidio Presidio is committed to hiring the most qualified candidates to join our amazing culture. We aim to attract and hire top talent from all backgrounds, including underrepresented and marginalized communities. We encourage women, people of color, people with disabilities, and veterans to apply for open roles at Presidio. Diversity of skills and thought is a key component to our business success. At Presidio, speed and quality meet technology and innovation. Presidio is a trusted ally for organizations across industries with a decades-long history of building traditional IT foundations and deep expertise in AI and automation, security, networking, digital transformation, and cloud computing. Presidio fills gaps, removes hurdles, optimizes costs, and reduces risk. Presidio's expert technical team develops custom applications, provides managed services, and enables actionable data insights and builds forward-thinking solutions that drive strategic outcomes for clients globally. For more information visit Applications will be accepted on a rolling basis. Presidio has a strong commitment to the community we serve and our employees. As an Equal Opportunity Employer, we strive to have a workforce that includes the community we serve. Presidio is an Equal Opportunity Employer Disability/Vets. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected categories. The "Know Your Rights" Poster is available here: https://www.eeoc.gov/poster Presidio EEO Policy Statement is available here: https://www.presidio.com/careers Presidio is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to recruitment@presidio.com and let us know the nature of your request and your contact information. Presidio is a VEVRAA Federal Contractor requesting priority referrals of protected veterans for its openings. State Employment Services, please provide priority referrals to. Notice of Massachusetts Candidates: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Recruitment Agencies, Please Note: Presidio does not accept unsolicited agency resumes/CVs. Do not forward resumes/CVs to our career's email address, Presidio employees or any other means. Presidio is not responsible for any feeds related to unsolicited resumes/CVs. #LI-PH1
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
|