Security & Privacy Lead ( Must Be A US Citizen)

Washington, DC
Full Time
Experienced

Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services.


Position Overview

The Security and Privacy Lead will provide leadership and technical oversight for cybersecurity, privacy, risk management, and platform security activities supporting the EEOC. This individual will serve as the primary security and privacy subject-matter expert and will work closely with the Chief Information Security Officer (CISO), program leadership, technical teams, and federal stakeholders to ensure that systems, cloud platforms, applications, and data are protected in accordance with federal security requirements.

The Security and Privacy Lead will guide the implementation of security controls, oversee compliance and risk-management activities, and ensure alignment with the National Institute of Standards and Technology (NIST), Federal Risk and Authorization Management Program (FedRAMP), and Federal Information Security Modernization Act (FISMA) requirements.
 

Key Responsibilities

  • Serve as the program’s lead subject-matter expert for cybersecurity, privacy, risk management, and platform security.
  • Work directly with the EEOC CISO and other security stakeholders to support agency cybersecurity objectives, policies, and governance requirements.
  • Lead the implementation and continuous monitoring of security and privacy controls across applications, infrastructure, cloud environments, and technology platforms.
  • Ensure systems and services comply with applicable NIST standards, guidelines, and security control frameworks.
  • Support FedRAMP compliance and authorization activities for cloud-hosted platforms and services.
  • Ensure compliance with FISMA and other applicable federal cybersecurity and privacy requirements.
  • Assess security risks, vulnerabilities, threats, and compliance gaps and recommend appropriate corrective actions.
  • Develop, review, and maintain security documentation, including System Security Plans, security policies, risk assessments, control assessments, Plans of Action and Milestones, and incident-response procedures.
  • Provide security oversight throughout the system development life cycle, including architecture, design, development, testing, deployment, operations, and maintenance.
  • Review platform architectures and configurations to ensure secure access controls, identity management, data protection, encryption, logging, monitoring, and vulnerability management.
  • Coordinate security assessment and authorization activities and support the maintenance of system Authorizations to Operate.
  • Work with cloud architects, engineers, developers, administrators, and vendors to incorporate security and privacy requirements into technical solutions.
  • Support security incident response, investigation, reporting, remediation, and lessons-learned activities.
  • Monitor compliance findings and ensure that identified weaknesses are documented, tracked, and remediated within required timeframes.
  • Provide cybersecurity and privacy guidance to program leadership and communicate technical risks to both technical and nontechnical stakeholders.
  • Prepare and deliver security reports, compliance updates, risk briefings, and other required program deliverables.
  • Ensure that personally identifiable information and other sensitive agency information are handled, stored, transmitted, and protected appropriately.

Required Qualifications

  • Demonstrated experience serving in, supporting, or working closely with a Chief Information Security Officer (CISO) organization or federal cybersecurity leadership function.
  • Strong knowledge of NIST cybersecurity standards, guidelines, and security control frameworks.
  • Demonstrated experience implementing or assessing NIST security and privacy controls.
  • Strong knowledge of FedRAMP requirements and cloud security authorization processes.
  • Demonstrated knowledge of FISMA compliance, reporting, continuous monitoring, and risk-management requirements.
  • Experience overseeing platform security for cloud-hosted systems, enterprise applications, infrastructure, and integrated technology environments.
  • Experience identifying security risks, evaluating vulnerabilities, and developing effective mitigation and remediation strategies.
  • Knowledge of federal security assessment and authorization processes, including system documentation and continuous monitoring.
  • Experience integrating security and privacy requirements throughout the system development life cycle.
  • Strong understanding of access control, identity and access management, encryption, network security, vulnerability management, incident response, logging, and security monitoring.
  • Ability to communicate cybersecurity and privacy requirements clearly to agency executives, program managers, engineers, developers, and other stakeholders.
  • Strong written and verbal communication, analytical, organizational, and leadership skills.
  • Ability to work effectively with federal government stakeholders in Washington, DC.

Preferred Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline.
  • Relevant professional certification, such as CISSP, CISM, CCSP, CAP/CGRC, or an equivalent cybersecurity certification.
  • Experience supporting a federal civilian agency.
  • Experience securing FedRAMP-authorized cloud platforms or services.
  • Familiarity with federal privacy requirements, privacy impact assessments, and the protection of personally identifiable information.
  • Experience supporting enterprise modernization, cloud migration, or platform-integration initiatives within a federal environment.
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*