12 Required deep focus on: Governance, Risk, and Compliance (GRC), Enterprise Security and Security Architecture, Vulnerability Management and Penetration Testing , Cloud Security and hybrid environments
10 Required Proven experience owning SSP development end to end
10 Required Hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks
10 Required Strong expertise in: Control implementation documentation, Audit evidence collection and validation, POA&M creation, tracking, and remediation management
8 Required Ability to translate technical security issues into compliance aligned remediation actions
8 Required Strong stakeholder management skills across security, infrastructure, and application teams
8 Required Excellent written and verbal communication skills, particularly for executive stakeholders
8 Required Knowledge of NIST 800 53, NIST RMF, and privacy controls
8 Required Knowledge of Secure SDLC and DevSecOps practices
5 Preferred Experience operating in multi-vendor, multi-platform environments
5 Preferred Demonstrated ability to reduce repeat audit findings and improve compliance maturity
5 Preferred Experience mentoring or guiding teams on security governance best practices
1 Preferred Experience supporting HHSC systems, including SSP development and compliance