LI

Governance, Risk & Compliance / Cloud Security Subject Matter Expert

Lexical Intelligence, LLC
Posted 1 hour ago
United StatesHybridLegal & Compliance
Is this job info correct?

Lexical Intelligence provides software and services related to processing large-scale biomedical information sources. Our NLP and analytics software is used by policy and decision makers to evaluate and prioritize current and emerging areas of research.


Lexical Intelligence is seeking a senior Governance, Risk & Compliance / Cloud Security Subject Matter Expert (GRC / Cloud SME) to serve as the security subject matter expert for a complex, cloud-native system supporting the National Institutes of Health (NIH). The system is fully deployed in Amazon Web Services (AWS) across multiple accounts and hosts multiple applications that process and analyze large-scale biomedical data.

This is a hands-on Governance, Risk, and Compliance (GRC) leadership role. The GRC / Cloud SME will own the development and maintenance of the system's Authority to Operate (ATO) package within JCAM (NIH's enterprise GRC platform), advise the program on the security implications of change and configuration management, and serve as the system's Contingency Planning and Incident Response Coordinator. The GRC / Cloud SME will act as the trusted security advisor to a cross-functional team of software developers, DevOps engineers, data scientists, and program leadership.

Key Responsibilities

  • ATO Package Development & Maintenance
    • Develop, maintain, and continuously improve the system's ATO package in JCAM, including the System Security Plan (SSP), control implementation statements, security policies and procedures, and all supporting artifacts.
    • Ensure the ATO package accurately reflects the as-built, multi-account AWS environment and remains current as the system evolves.
    • Support security assessments, audits, and annual control assessments; coordinate evidence collection and respond to assessor findings.
    • Manage Plans of Action & Milestones (POA&Ms): track weaknesses, coordinate remediation with engineering teams, and report status to the Authorizing Official's staff.
  • Change & Configuration Management Advisory
    • Serve as the security voice in the change and configuration management process: review proposed system changes, perform Security Impact Analyses (SIA), and advise the team on whether changes affect the authorization boundary or control posture.
    • Ensure security-relevant changes are documented, assessed, and reflected in the ATO package and continuous monitoring reporting.
    • Advise on secure configuration baselines and monitor for configuration drift across AWS accounts.
  • Contingency Planning & Incident Response Coordination
    • Serve as the system's Contingency Planning Coordinator: develop and maintain the Information System Contingency Plan (ISCP), plan and facilitate annual contingency plan tests and tabletop exercises, and document test results and lessons learned.
    • Serve as the system's Incident Response Coordinator: maintain the Incident Response Plan, coordinate incident detection, reporting, and response activities in accordance with NIH and HHS requirements, and lead incident response exercises.
    • Ensure backup, recovery, and resilience capabilities are documented, tested, and aligned with system recovery objectives.
  • Cloud Security Engineering & Team Advisory
    • Advise developers, DevOps engineers, and data scientists on secure architecture and AWS security best practices across a multi-account environment, including IAM, AWS Organizations and service control policies, encryption and key management (KMS), logging and monitoring (CloudTrail, CloudWatch, GuardDuty, Security Hub, AWS Config), and network security.
    • Support vulnerability management: review scan results, prioritize findings, and partner with engineering teams on remediation.
    • Advise on secure development and DevSecOps practices, including CI/CD pipeline security and infrastructure as code.
    • Serve as the day-to-day security advisor to the program, translating federal security requirements into practical guidance the team can act on.

Minimum Qualifications

  • 7+ years of information security experience, including direct support of federal systems and the full ATO lifecycle under the NIST Risk Management Framework (SP 800-37).
  • Deep, demonstrated expertise in NIST SP 800-53 control selection, implementation, and assessment, including authoring SSPs and control implementation statements.
  • Hands-on experience securing AWS environments, preferably multi-account architectures (AWS Organizations), including IAM, logging/monitoring services, and encryption/key management.
  • Experience developing and maintaining complete ATO packages within an enterprise GRC platform (e.g., JCAM, CSAM, eMASS, Xacta, or similar).
  • Experience performing Security Impact Analyses and advising change control processes on security-relevant changes.
  • Experience developing, maintaining, and testing contingency plans (NIST SP 800-34) and incident response plans (NIST SP 800-61).
  • Experience with vulnerability management and POA&M lifecycle management, including tools such as Tenable, Inspector, or similar scanners.
  • Strong technical writing and documentation skills with meticulous attention to detail.
  • Proven ability to communicate security requirements effectively to engineers, data scientists, and program leadership.
  • One or more of the following certifications: CISSP, CISM, AWS Certified Security - Speciality.
  • Cloud process knowledge
  • Linux familiarity

Preferred Qualifications

  • Direct experience with JCAM and supporting systems within NIH or other HHS agencies.
  • Experience with containerized environments and orchestration platforms (e.g., Kubernetes, Amazon EKS).
  • Exposure to infrastructure as code (e.g., Terraform) and automation of compliance or continuous monitoring activities.
  • Familiarity with large-scale data platforms, biomedical data, or research-focused systems, including data privacy considerations for sensitive or regulated data.
  • Experience supporting public-facing federal systems or APIs.
  • Additional relevant certifications such as CISSP, CGRC/CAP, CISM, CCSP, or AWS Certified Security – Specialty.
  • Cloud architecture / DevOps experience or knowledge

All candidates will be required to undergo a background check, must be authorized to work in the United States, and must be able to obtain and maintain an NIH badge with Public Trust Level Two suitability.

Location

Preference will be given to candidates within reasonable commuting distance of Bethesda, MD. Candidates outside the greater Washington, D.C. / Maryland / Virginia area may be responsible for their own transportation costs for badging, equipment retrieval, and in-person attendance when required.


Salary and benefits

We offer a competitive salary and a generous benefits package, including at no cost: full health and dental for you and your dependents, HSA account, 401k, short- and long-term disability insurance, life and accident insurance, paid time off, and 11 federal holidays.


Equal Employment Opportunity Policy

Lexical Intelligence, LLC, provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.


This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Similar jobs