Leading system security and risk management, the full-time remote ISSO Program Manager will oversee Risk Management Framework activities, maintain system Authorization to Operate, and serve as a trusted advisor to stakeholders at the Centers for Medicare & Medicaid Services (CMS). Key responsibilities Manage the implementation and ongoing maintenance of information security controls for assigned systems Conduct continuous monitoring activities, including security event logging and vulnerability scanning, to ensure compliance with security requirements Advise the Authorizing Official on risk-based authorization decisions and maintain security and privacy controls in accordance with federal policies Required qualifications Bachelor's degree and at least seven years of relevant cybersecurity experience, particularly with federal contracts Strong background in Risk Management Framework (RMF) and Authorization to Operate (ATO) management Experience leading security assessments and managing Plans of Action and Milestones (POA&Ms) Proven ability to manage large-scale projects with significant complexity and risk Familiarity with agile frameworks and experience in leading agile development teams