Talent.com
Manager, Governance Risk & Compliance
Manager, Governance Risk & ComplianceThe Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
Manager, Governance Risk & Compliance

Manager, Governance Risk & Compliance

The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Description

Are you interested in being part of a forward thinking Cybersecurity program?

Are you inquisitive and analytical with expertise in Cybersecurity Governance, Risk, and Compliance?

If so, we 're looking for someone like you to join our team at APL.

We are seeking a Supervisor for our Governance, Risk, and Compliance (GRC) section to provide vision, direction, and leadership for cybersecurity oversight and maintenance of Federal Information Systems Management Act (FISMA) compliant security programs supervise a team of cybersecurity analysts in a matrix organization partnering with cyber architecture & engineering, cyber hunt & incident response, and operational cyber research.

As a cybersecurity subject matter expert, you will support innovation and digital transformation across the Laboratory. Manage our enterprise Vulnerability Management program and proactively identify and lead opportunities to reduce vulnerabilities across IT systems and emerging platforms like cloud and Internet of Things. Use your comprehensive understanding of evolving tactics, techniques, and procedures used by Nation State adversaries to assess and determine risk to the organization. Work with IT compliance stakeholders to assess risks and provide relevant technical guidance in order for stakeholders to make effective decisions.

As the Supervisor for our Governance, Risk, and Compliance (GRC) section you will...

  • Maintain formalized IT Governance framework for APL's unclassified network. Review existing IT compliance controls for regulatory updates and perform necessary gap analysis create and participate in various internal and external audit and compliance activities. Monitor compliance with and develop organizational security policies and procedures for compliance with FISMA and NIST 800-53, NIST 800-171, HIPAA, as well as developing and evolving government regulations. Review and provide input on contracts for compliance. Create and maintain Systems Security Plans and document monitor and report on status of POA&M items. Present briefings to senior management.
  • Develop and enhance processes, work flows, and documentation for monitoring compliance and privacy requirements.
  • Participate in project and cross-functional security teams requiring interaction with system administrators, networking staff, application developers, IT operations staff, and cyber research and development areas within the organization in order to identify and implement information assurance controls and risk mitigation techniques for IT operations.
  • Work effectively with all levels of management and staff and participate in project and cross-functional security teams within the organization in order to identify and implement information assurance controls and risk mitigation techniques for IT operations and evolve cyber security awareness and training programs. Work with internal, industry and third party IT security partners to stay current on industry trends, controls and security technologies and services. Collaborate with other organizations to maintain knowledge and leverage best practices. Provide routine reporting on goals and objectives to management.
  • Establish strong relationships with staff, improve morale, conduct coaching, promote career growth, manage performance, and participate in recruiting and other line supervision activities as a member of the department 's extended management team.

Qualifications

You meet our minimum requirements if you...

  • Hold a Bachelor 's degree in Information Systems, Computer Science, Cybersecurity or equivalent years of relevant professional IT work experience.
  • Have 7+ years of hands-on operational IT cybersecurity experience.
  • Have an understanding of attack methodologies used by Nation State actors and the ATT&CK matrix to effectively assess risk with a pplied knowledge of NIST 800-53, NIST 800-171, and HIPAA regulations.
  • Have experience running vulnerability analysis tools, like Nessus, Qualys, or Rapid7.
  • Have experience with data analysis using tools like, Splunk, ELK, or SQL.
  • Have experience in assessing cloud technologies such as Amazon Web Services or Microsoft Azure.
  • Have 5+ years in management / supervision in an operational cybersecurity role.
  • Are able to self-direct and work independently as necessary.
  • Possess exceptional analytical and problem-solving skills.
  • Are an articulate and effective communicator with the ability to engage all levels of staff and management.
  • Possess a proven track record of successfully leading, coaching, and motivating direct reports in solving complex problems.
  • Are able to obtain a Secret level security clearance. If selected, you will be subject to a government security clearance investigation and must meet the requirements for access to classified information. Eligibility requirements include U.S. citizenship.
  • You go above and beyond our minimum requirements if you...

  • Hold a Master's degree in Information Systems, Computer Science, or related field.
  • Have experience with supporting cybersecurity operation center processes and tools.
  • Have experience running IT projects involving at least 10 people.
  • Possess certifications such as CISSP, CISSP-ISSEP, or SANS GIAC Security Essentials.
  • Have extensive experience in cloud technologies such as Amazon Web Services or Microsoft Azure.
  • About Us

    Why Work at APL?

    The Johns Hopkins University Applied Physics Laboratory (APL) brings world-class expertise to our nation's most critical defense, security, space and science challenges. While we are dedicated to solving complex challenges and pioneering new technologies, what makes us truly outstanding is our culture. We offer a vibrant, welcoming atmosphere where you can bring your authentic self to work, continue to grow, and build strong connections with inspiring teammates.

    At APL, we celebrate our differences of perspectives and encourage creativity and bold, new ideas. Our employees enjoy generous benefits, including a robust education assistance program, unparalleled retirement contributions, and a healthy work / life balance. APL's campus is located in the Baltimore-Washington metro area. Learn more about our career opportunities at http : / / www.jhuapl.edu / careers .

    All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, physical or mental disability, genetic information, veteran status, occupation, marital or familial status, political opinion, personal appearance, or any other characteristic protected by applicable law. APL is committed to providing reasonable accommodation to individuals of all abilities, including those with disabilities. If you require a reasonable accommodation to participate in any part of the hiring process, please contact Accommodations@jhuapl.edu .

    The referenced pay range is based on JHU APL's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education / training and skill level with consideration for internal parity. For salaried employees scheduled to work less than 40 hours per week, annual salary will be prorated based on the number of hours worked. APL may offer bonuses or other forms of compensation per internal policy and / or contractual designation. Additional compensation may be provided in the form of a sign-on bonus, relocation benefits, locality allowance or discretionary payments for exceptional performance. APL provides eligible staff with a comprehensive benefits package including retirement plans, paid time off, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, education assistance, and training and development. Applications are accepted on a rolling basis.

    Minimum Rate

    $105,000 Annually

    Maximum Rate

    $265,000 Annually

    serp_jobs.job_alerts.create_a_job

    Compliance Manager • Laurel, MD, United States

    Job_description.internal_linking.related_jobs
    Risk Manager

    Risk Manager

    Coinbase • Washington, DC, United States
    serp_jobs.job_card.full_time
    Ready to be pushed beyond what you think you’re capable of?.At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Governance, Risk, and Compliance Lead

    Governance, Risk, and Compliance Lead

    Peraton • Bethesda, MD, United States
    serp_jobs.job_card.full_time
    Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field (Master’s preferred).Deep knowledge of cybersecurity frameworks (NIST, ISO 27001, CIS, COBIT).Strong un...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Manager - Risk Management

    Manager - Risk Management

    UHS • Washington, DC, United States
    serp_jobs.job_card.full_time
    Cedar Hill Regional Medical Center.Cedar Hill Regional Medical Center GW Health is the first new full-service hospital in Washington, DC in more than 20 years, integrating clinical care with existi...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Risk Manager

    Risk Manager

    AECOM • Washington, DC, United States
    serp_jobs.job_card.full_time
    At AECOM, we're delivering a better world.Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thr...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Director, Risk Governance & Strategy (Hybrid) (Richmond, VA or Columbia, MD)

    Director, Risk Governance & Strategy (Hybrid) (Richmond, VA or Columbia, MD)

    Atlantic Union Bank • Columbia, MD, United States
    serp_jobs.job_card.full_time
    The Director - Risk Governance & Strategy will ensure key Enterprise Risk Management ("ERM") processes including identification, assessment, monitoring, management, and reporting of risks appropria...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Manager, Security Governance Risk and Compliance

    Manager, Security Governance Risk and Compliance

    KPMG US • Washington, DC, United States
    serp_jobs.job_card.full_time
    Manager, Security Governance Risk and Compliance.Join KPMG US as a Manager, Security Governance Risk and Compliance.This is a remote work opportunity. Apply a thorough knowledge of risk, compliance ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Risk Manager

    Risk Manager

    AtkinsRéalis • Washington, DC, United States
    serp_jobs.job_card.permanent
    Washington, DC and San Franscico, CA.The Risk Manager is responsible for developing, implementing, and maintaining risk management processes aligned with Federal Transit Administration (FTA) requir...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Manager, Crisis Response

    Security Manager, Crisis Response

    FHI 360 • Washington, DC, United States
    serp_jobs.job_card.part_time
    FHI 360 staff working in the United States are required to be fully vaccinated for COVID-19, regardless of the type of project or client they serve, or of their employment status (full / part-time, r...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Risk Manager

    Risk Manager

    A HOME OF OUR OWN HOWARD INC • Columbia, MD, United States
    serp_jobs.job_card.full_time
    The Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact the operations, reputation, and legal compliance of A Home of Our Own Howard, Inc.The Risk Manager...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    GRC Manager

    GRC Manager

    HR Force International • Arlington, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    We are seeking an experienced Governance, Risk, and Compliance (GRC) Manager with a proven background in RegTech (Regulatory Technology) and Identity Verification (IDV) to join our growing team at ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30
    Information Governance Compliance Manager

    Information Governance Compliance Manager

    Cooley LLP • Washington, DC, United States
    serp_jobs.job_card.full_time
    Information Governance Compliance Manager.Cooley is seeking an Information Governance (IG) Compliance Manager to join the IG & Privacy team. Cooley Information Governance & Privacy embraces a cultur...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Manager of Business Risk Guidance

    Manager of Business Risk Guidance

    Capital One • Washington, DC, United States
    serp_jobs.job_card.full_time
    We are excited to announce an opportunity at the Enterprise Services Business Risk Office, where we provide essential risk management support across several critical lines of business including Bra...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Risk Manager

    Risk Manager

    TradeJobsWorkforce • 22204 Arlington, VA, US
    serp_jobs.job_card.full_time
    Risk Manager job responsibilities : Leads the identification, communication, measurement, and management o...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Sailpoint Compliance & Risk Management

    Sailpoint Compliance & Risk Management

    Next Level Business Services, Inc. • Washington, DC, United States
    serp_jobs.job_card.full_time
    Mandatory Skills (Please detail as much as possible) Educational Qualifications and Experience : .Master’s or Bachelor’s degree(s) in Computer Science and / or Electrical Engineering.Minimum five conse...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    PAC & Government Relations Manager – DC, Compliance

    PAC & Government Relations Manager – DC, Compliance

    Nashville Public Radio • Washington, DC, United States
    serp_jobs.job_card.full_time
    A diversified company in Washington, DC is seeking a skilled professional to lead their Political Action Committee operations. The successful candidate will manage PAC activities, ensure compliance ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Head of Governance, Risk and Controls

    Head of Governance, Risk and Controls

    FGS Global • Washington, DC, United States
    serp_jobs.job_card.full_time
    We are recruiting for the Head of GRC to join our Information Security team based in London, Frankfurt, New York or Washington DC. Based in fabulous city centre offices, with a fantastic team, FGS i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Manager, Cybersecurity Governance and Risk

    Manager, Cybersecurity Governance and Risk

    Next Step Systems LTD • Washington, DC, United States
    serp_jobs.job_card.full_time
    Manager, Cybersecurity Governance and Risk, Washington, DC.The Manager, Cybersecurity Governance and Risk will lead IT risk management (ITRM) initiatives to increase the transparency of risk impact...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Managing Director, Cybersecurity, Information Governance

    Managing Director, Cybersecurity, Information Governance

    Ankura • Washington, DC, US
    serp_jobs.job_card.full_time
    Managing Director, Cybersecurity, Information Governance Ankura is a team of excellence founded on innovation and growth. Ankura's fast-growing global Cybersecurity and Data Privacy Practice offers ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted