Security Lead
RESULTS. INNOVATION. VALUES. ACCOUNTABILITY.
That’s RIVA.
We’re a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies. Since 2009, we’ve partnered with our customers to solve complex challenges through smart, practical innovation to deliver real outcomes where they matter most. Our teams are made up of industry-leading experts who are passionate about doing great work and making a difference. We don’t just develop solutions, we support efforts that strengthen communities and serve the public good.
RIVA’s culture is built on four core values: Results, Innovation, Values, and Accountability. They guide how we work, how we collaborate, and how we measure success. Our employee-first approach is rooted in trust, ownership, and meaningful work. By investing in our people and fostering a flexible, supportive environment, employees have the opportunity to grow their skills, contribute ideas, and make an impact from day one. all while supporting missions that matter.
POSITION SUMMARY
The Security Lead is the Government's focal point for the security posture of every contractor-provided FBIB system, tool, interface, and facility. This person obtains and maintains the Authority to Operate (ATO), runs continuous monitoring, and protects biometric data, PII, and Title 13 information across a nationwide network of sites, processing centers, and production facilities.
CORE RESPONSIBILITIES
- Lead all security documentation, assessment, and authorization activities to obtain ATO for contractor systems. This includes the System Security Plan, FIPS 199 categorization, Privacy Impact Assessment, E-Authentication Risk Assessment, contingency plan, security control assessment support, and POA&M management.
- Ensure compliance with FISMA, the Census Bureau IT Security Program and Cyber Security Policy, and NIST SP 800-18, 800-34, 800-37, 800-47, 800-53, and 800-60, along with privacy and records management requirements.
- Support FedRAMP requirements at the Government-designated level (Moderate or higher) for any cloud components.
- Respond to all continuous monitoring alerts with initial assessment, updates, and resolution within required timelines, and report incidents and suspected breaches as directed.
- Run continuous monitoring, including annual self-assessment of a portion of controls, scheduled vulnerability scanning of infrastructure and endpoints at sites, application and database scanning, and authenticated scan access for the Census Bureau.
- Engage OIS security engineers from requirements through deployment so security is designed in rather than added before assessment.
- Define and enforce security controls for enrollment sites based on each facility's security level as determined by the Census Bureau Office of Security, and complete facility walkthroughs and site authorizations before sites open.
- Oversee physical security for contractor facilities, people, equipment, and data, including separation of systems handling PII and restricted access to areas where Census Bureau and selectee data are handled.
- Manage personnel security processing for contractor staff, including DOC background investigations, Title 13 oaths and Special Sworn Status, OF-306, e-QIP, and required training before staff touch Census data.
- Secure interconnections with Government systems through ISAs, encryption in transit and at rest, and access management.
- Manage supply chain risk assessments for hardware, software, and subcontractors.
- Own security risks in the program risk register, such as ATO delay, cyber incidents, and PII incidents.
- Oversee data sanitization and Title 13 media certification at decommissioning.
MINIMUM QUALIFICATIONS
- Bachelor's degree in information systems, engineering, operations management, or a related field.
- 10 or more years of experience leading IT system implementations, including at least 5 years leading multi-site or nationwide deployments.
- Experience leading software releases with Agile methods and coordinated hardware and field deployments.
- Experience planning and running integration and operational readiness testing with Government stakeholders.
- Working knowledge of logistics, equipment deployment, and site activation at scale.
- Ability to obtain a Department of Commerce (DOC) Background Investigation and Census Special Sworn Status.
PREFERRED QUALIFICATIONS
- Bachelor's degree in cybersecurity, computer science, information systems, or a related field.
- 12 or more years of IT experience, including at least 8 years in information security and 5 years leading federal ATO efforts under the NIST Risk Management Framework.
- Experience with FedRAMP authorized cloud environments and continuous monitoring programs.
- Experience securing systems that process PII or sensitive identity data.
- Prior service as an ISSO or ISSM on a federal system.
- CISSP, CISM, or CAP/CGRC certification.
- Ability to obtain a Department of Commerce (DOC) Background Investigation and Census Special Sworn Status
This position is a contingent hire opportunity on a proposal proposal effort.
Pay range
$170,000 - $200,000 USD
EQUAL EMPLOYMENT OPPORTUNITY & ACCOMMODATION
We believe great teams are built from different backgrounds, perspectives, and lived experiences, and we mean that beyond the buzzwords.
RIVA is an equal opportunity employer. We welcome applicants of every race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, and any other characteristic protected by law.
If you need an accommodation at any point in our process, send an email to talent@rivasolutionsinc.com, we'll be happy to help.
VETERAN SUPPORT & ACCESSIBILITY
As a federal contractor, RIVA follows the requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, supporting the employment and advancement of protected veterans and individuals with disabilities. If you're a veteran, we encourage you to self-identify during the application process, it helps us track our hiring commitments and, in some cases, may support priority referral for open roles.
RIVA also invites applicants to voluntarily self-identify as having a disability during the application process, not because it affects your chances of being hired, but because it helps us measure how well we're living up to our commitments and identify where we can do better. Your response is confidential and entirely optional.
Apply for this job
*
indicates a required field