Defensive Cybersecurity Advisor — RMF/A&A Lead
About QBE, LLC
QBE, LLC is a small business dedicated to delivering innovative technology, cybersecurity, and mission-support solutions to federal government customers. Our experienced professionals work closely with our customers to solve complex challenges, protect critical information, and support essential government missions.
At QBE, we turn the possible into the proven.
Overview
QBE, LLC is seeking an experienced Defensive Cybersecurity Advisor — RMF/A&A Lead to support comprehensive information security services for the National Institutes of Health, Office of the Director, Office of Information Technology (NIH/OD-OIT).
Responsibilities
- Lead and coordinate Risk Management Framework (RMF) and Assessment and Authorization (A&A) activities for federal information systems and applications.
- Provide subject-matter expertise related to federal cybersecurity requirements, security authorization processes, and risk management.
- Guide system owners and technical teams through the full system authorization lifecycle.
- Develop, review, and maintain security authorization documentation, including:
o System Security Plans
o Security Assessment Plans and Reports
o Plans of Action and Milestones
o Risk assessments
o Security control implementation statements
o Contingency planning documentation
o Continuous monitoring documentation
- Evaluate system security controls using applicable NIST guidance and federal security requirements.
- Coordinate security assessments, control testing, evidence collection, and remediation activities
- Review system changes to determine potential impacts on security authorizations and organizational risk.
- Identify cybersecurity risks, control deficiencies, and compliance gaps and recommend appropriate corrective actions.
- Track security findings, vulnerabilities, and remediation activities through closure
- Support continuous monitoring activities for Low- and Moderate-impact systems.
- Review technical and nontechnical security documentation for accuracy, consistency, and compliance.
- Provide cybersecurity guidance for on-premises, cloud-based, hybrid, and third-party systems.
- Support Governance, Risk, and Compliance initiatives across the customer environment.
- Collaborate with Security Operations and Engineering teams to ensure technical security activities align with RMF and authorization requirements.
- Assist with the development and improvement of cybersecurity policies, procedures, standards, and governance processes.
- Prepare cybersecurity status reports, risk summaries, dashboards, and briefing materials for technical and executive audiences.
- Participate in meetings with government stakeholders, system owners, auditors, assessors, and cybersecurity personnel.
- Provide recommendations that support the continued improvement and maturation of the organization’s cybersecurity program.
**This position will be primarily REMOTE but will require some onsite work in Bethesda, MD
#qf #qg