Essnova Solutions, Inc.

Security / RMF Lead

Essnova Solutions, Inc.  •  United States (Remote)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Essnova Solutions, Inc. is an award-winning SBA 8(a) and HUBZone small business delivering innovative technology and professional services to government and commercial clients. As Security / RMF Lead, you will play a critical role in ensuring the integrity and compliance of federal information systems under the VISION contract for the National Center for Health Statistics (NCHS). Your leadership will directly impact the security posture and regulatory compliance of mission-critical systems supporting public health initiatives.

Key responsibilities include:

  • Maintain System Security Plans (SSPs) as living documents for all NCHS systems, ensuring timely updates after security-impacting changes.
  • Manage Plan of Action & Milestones (POA&Ms) with quarterly progress reviews, closure evidence, and remediation tracking.
  • Remediate vulnerabilities within mandated timelines, track findings through closure, and provide retesting evidence.
  • Prepare Authorization to Operate (ATO) packages—including SSPs, POA&M status, assessment results, and risk analysis—for Authorizing Official review.
  • Conduct annual security assessments of one-third-plus-key-controls using CSAM or equivalent tools.
  • Submit monthly authenticated vulnerability and application scan results by the fifth business day.
  • Coordinate among developers, system owners, and security staff, and liaise with CDC CSPO, NCHS SSPO, and CDC Enterprise Architects.
  • Follow CDC CSPO Change Management SOP, including security impact analysis for post-ATO changes.
  • Support implementation of the Risk Management Framework (RMF), FISMA compliance, and OMB directives.
  • Produce security-related EPLC artifacts for governance and stage-gate reviews.
  • Lead SSP development during the 30-day transition-in activation sequence and support SSP submission within 30 days of contract award.
  • Support PTA/PIA activities with CDC privacy officials.

Requirements

Required Qualifications:

  • Bachelor's degree in cybersecurity, information assurance, computer science, or a related field
  • 6+ years of federal information security experience applying NIST RMF (NIST SP 800-37)
  • Experience developing and maintaining SSPs, POA&Ms, and ATO packages for FIPS 199 Moderate or higher systems
  • Experience using vulnerability scanning results to track remediation to closure (including retesting evidence) in a federal environment
  • Hands-on experience with federal security management tools (CSAM and eMASS)
  • Working knowledge of NIST SP 800-53 Rev. 5 and NIST SP 800-53A
  • Knowledge of FISMA 2014 reporting and OMB security directives
  • Knowledge of Privacy Act and E-Government Act privacy provisions, including PTA/PIA processes
  • Experience coordinating with federal ISSOs/CISOs and security authorization officials
  • Active Tier 4 / High Risk / Public Trust Level 6+ clearance at proposal submission
  • Eligibility for HSPD-12/PIV
  • Availability to work during Eastern Time (ET) business hours

Preferred Qualifications:

  • CISSP, CISM, or CAP certification (or equivalent)
  • Experience supporting CDC, HHS, or federal health agencies
  • Experience with CIPSEA-protected data environments or federal statistical agencies
  • Experience with FedRAMP continuous monitoring and cloud security assessment

Benefits

Benefits

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off + federal holidays
  • Fast-track growth in a high-accountability culture

Why Essnova

  • Rapidly growing, innovation-focused GovCon firm
  • High-ownership environment where your wins matter
  • Direct access to leadership, zero bureaucracy
  • Culture built on speed, agility, and results
Essnova Solutions, Inc.

About Essnova Solutions, Inc.

Ranked at 163 in the INC. magazine’s prestigious list of 500 fastest growing companies in the U.S, Essnova is an award winning, and mature small business offering broad range of technology and programmatic support services to the governmental and commercial customers. Essnova’s CEO is proud to be awarded with the Alabama’s SBA 2020 Small Business Person of the Year recognition.

We offer specialization in SETA Services, Geospatial, Environmental and Medical Services. Our Technology Integration/VAR reseller unit augments our services with SME Support, products and licensing from hundreds of manufacturers.

Essnova offers a highly capable management team, delivering mature management services as demonstrated by our Federal and commercial exceptional past performance. We utilize ISO-registered commercial best practices to deliver highly efficient and responsive solutions. Our team works diligently to ensure that we continue to be the world-class small business in our customers’ vendor portfolio.

Comprised of solution architects, engineers, subject matter experts – Team Essnova stands ready to assist our customers with deploying enterprise, agency wide solutions from assessment, concept, design, technology solutions procurement, implementation, training and ongoing maintenance and management.

We are the American Dream- a company comprised of normal everyday people who have a shared vision of being a contributing part of how this country and its people communicate, work together, and share together through technology and connection. This vision is what gives us the continued drive and excitement of working with the Federal agencies and Commercial organizations that are our clients, who all share our desire and goal to facilitate the implementation of systems and services that help communication and collaboration expand and be available to all who can benefit.

Industry
IT & Software
Company Size
11-50 employees
Headquarters
Birmingham, Alabama
Year Founded
2005
Social Media