- Company Name
- Brighton Marine
- Job Title
- Senior Cybersecurity Governance, Risk & Compliance (GRC) and Cyber Operations Specialist
- Job Description
-
Job Title: Senior Cybersecurity Governance, Risk & Compliance (GRC) and Cyber Operations Specialist
Role Summary: Lead the design, implementation, and sustainment of a CMMC Level 2–aligned cybersecurity program for a complex healthcare and DoD‑adjacent environment, integrating policy development with operational support such as vulnerability tracking, log analysis, evidence generation, and audit readiness.
Expectations: Deliver a compliant, auditable security posture; maintain real‑time evidence, control ownership, and risk registers; support annual self‑assessments and external C3PAO reviews; provide limited cyber operations assistance while ensuring all documentation and controls meet federal standards.
Key Responsibilities
- Conduct CMMC Level 2 gap assessments (technical, documentation, evidence).
- Draft, update, and maintain CMMC policies, SOPs, SSPs, network/trust boundary diagrams, POA&M, risk register, Incident Response Playbooks, DR/COOP docs, hardening guides, and audit plans.
- Implement and operationalize controls: evidence generation, logging, monitoring, MFA, RBAC, vulnerability management, configuration management, and integrate with IT service delivery.
- Sustain compliance: perform recurring control checks, update documentation, coordinate remediation, produce quarterly risk posture reports, and manage the live POA&M.
- Provide limited cyber operations support: vulnerability tracking, patch coordination, SIEM log review, low/medium incident triage, IR exercise participation, configuration baseline maintenance, and audit binder refresh.
Required Skills
- In‑depth knowledge of CMMC Level 2, NIST SP 800‑171, DFARS 252.204‑7012, FedRAMP, C3PAO readiness, and federal compliance frameworks.
- Proficiency with SIEM platforms, vulnerability management tools, logging/monitoring systems, and incident response processes.
- Strong documentation and policy writing abilities.
- Excellent communication and stakeholder engagement skills for technical and executive audiences.
- Ability to secure U.S. Government personnel security clearance.
- Adherence to federal CUI handling, DFARS, and NIST requirements.
Required Education & Certifications
- Bachelor’s degree (or equivalent work experience).
- Minimum 5 years federal cybersecurity/GRC experience.
- Preferred certifications: CISSP, CISM, Security+, CCAK; other relevant federal cybersecurity or audit credentials.
Washington dc-baltimore, United states
Hybrid
Senior
13-01-2026