- Company Name
- Kentro
- Job Title
- Cybersecurity HVA/Audit SME
- Job Description
-
**Job Title:** Cybersecurity HVA/Audit SME
**Role Summary:**
Lead the Department of Commerce High‑Value Asset (HVA) program and cybersecurity audit readiness. Act as primary SME overseeing inventory, assessment coordination, remediation tracking, audit planning, risk register maintenance, and stakeholder communication to ensure compliance with federal standards (NIST RMF, CSF, FISMA, OMB, DOC policies).
**Expectations:**
- Manage all phases of HVA and audit activities for DOC operating units.
- Deliver actionable risk and remediation plans, executive briefings, and status updates.
- Maintain rigorous documentation, dashboards, and audit playbooks.
- Uphold federal cybersecurity mandates and secure Public Trust clearance.
**Key Responsibilities:**
- Lead HVA program: inventory, categorization, documentation, scheduling, and remediation.
- Maintain HVA tools, reports, dashboards, and guidance documents.
- Track HVA findings and provide visibility to OCRM, OCOS, and senior leadership.
- Plan, coordinate, and track cybersecurity audits (FISMA, A‑123, FMFIA, OIG, internal controls).
- Maintain audit risk register, remediation plans, and progress metrics.
- Prepare audit artifacts, CAPs, responses, and closure documentation.
- Develop or update audit playbooks, process documents, and guidance materials.
- Monitor risks tied to HVAs and audit findings; produce risk summaries and dashboards.
- Ensure alignment with NIST RMF, CSF, FISMA, OMB guidance, and DOC cybersecurity policies.
- Serve as primary liaison among OCRM, OCOS, ESOC, operating units, auditors, and assessment teams.
- Communicate status, issue escalation, and actionable recommendations to leadership and stakeholders.
**Required Skills:**
- 8+ years in federal cybersecurity programs.
- Deep understanding of NIST RMF, NIST CSF, FISMA, OMB A‑130, A‑123, FMFIA, DHS BOD 18‑02, FedRAMP, DOC policies.
- Experience with audit frameworks, internal control environments, and enterprise risk management.
- Ability to translate complex findings into actionable remediation strategies.
- Strong analytical, documentation, and executive‑level briefing skills.
- Proven cross‑functional stakeholder management.
- Experience managing high‑visibility cybersecurity programs and compliance with federal mandates.
**Required Education & Certifications:**
- Bachelor’s degree in Cybersecurity, IT, Engineering, or related field (or equivalent experience).
- U.S. citizenship; eligibility for Public Trust clearance.
- Preferred certifications: CISSP, CISM, CISA, CRISC, PMP.
---
Washington, United states
Hybrid
08-12-2025