Hiring.Camp

Security & Privacy Lead ( Must Be A US Citizen)

BTI

·

Yesterday

Location
Washington, DC
Type
Full-time
Department
Security
Seniority
Lead
Experience
25+ years
Closing date
Today
Source
ApplyToJob

Description

Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services.


Position Overview

The Security and Privacy Lead will provide leadership and technical oversight for cybersecurity, privacy, risk management, and platform security activities supporting the EEOC. This individual will serve as the primary security and privacy subject-matter expert and will work closely with the Chief Information Security Officer (CISO), program leadership, technical teams, and federal stakeholders to ensure that systems, cloud platforms, applications, and data are protected in accordance with federal security requirements.

The Security and Privacy Lead will guide the implementation of security controls, oversee compliance and risk-management activities, and ensure alignment with the National Institute of Standards and Technology (NIST), Federal Risk and Authorization Management Program (FedRAMP), and Federal Information Security Modernization Act (FISMA) requirements.
 

Key Responsibilities

  • Serve as the program’s lead subject-matter expert for cybersecurity, privacy, risk management, and platform security.
  • Work directly with the EEOC CISO and other security stakeholders to support agency cybersecurity objectives, policies, and governance requirements.
  • Lead the implementation and continuous monitoring of security and privacy controls across applications, infrastructure, cloud environments, and technology platforms.
  • Ensure systems and services comply with applicable NIST standards, guidelines, and security control frameworks.
  • Support FedRAMP compliance and authorization activities for cloud-hosted platforms and services.
  • Ensure compliance with FISMA and other applicable federal cybersecurity and privacy requirements.
  • Assess security risks, vulnerabilities, threats, and compliance gaps and recommend appropriate corrective actions.
  • Develop, review, and maintain security documentation, including System Security Plans, security policies, risk assessments, control assessments, Plans of Action and Milestones, and incident-response procedures.
  • Provide security oversight throughout the system development life cycle, including architecture, design, development, testing, deployment, operations, and maintenance.
  • Review platform architectures and configurations to ensure secure access controls, identity management, data protection, encryption, logging, monitoring, and vulnerability management.
  • Coordinate security assessment and authorization activities and support the maintenance of system Authorizations to Operate.
  • Work with cloud architects, engineers, developers, administrators, and vendors to incorporate security and privacy requirements into technical solutions.
  • Support security incident response, investigation, reporting, remediation, and lessons-learned activities.
  • Monitor compliance findings and ensure that identified weaknesses are documented, tracked, and remediated within required timeframes.
  • Provide cybersecurity and privacy guidance to program leadership and communicate technical risks to both technical and nontechnical stakeholders.
  • Prepare and deliver security reports, compliance updates, risk briefings, and other required program deliverables.
  • Ensure that personally identifiable information and other sensitive agency information are handled, stored, transmitted, and protected appropriately.

Required Qualifications

  • Demonstrated experience serving in, supporting, or working closely with a Chief Information Security Officer (CISO) organization or federal cybersecurity leadership function.
  • Strong knowledge of NIST cybersecurity standards, guidelines, and security control frameworks.
  • Demonstrated experience implementing or assessing NIST security and privacy controls.
  • Strong knowledge of FedRAMP requirements and cloud security authorization processes.
  • Demonstrated knowledge of FISMA compliance, reporting, continuous monitoring, and risk-management requirements.
  • Experience overseeing platform security for cloud-hosted systems, enterprise applications, infrastructure, and integrated technology environments.
  • Experience identifying security risks, evaluating vulnerabilities, and developing effective mitigation and remediation strategies.
  • Knowledge of federal security assessment and authorization processes, including system documentation and continuous monitoring.
  • Experience integrating security and privacy requirements throughout the system development life cycle.
  • Strong understanding of access control, identity and access management, encryption, network security, vulnerability management, incident response, logging, and security monitoring.
  • Ability to communicate cybersecurity and privacy requirements clearly to agency executives, program managers, engineers, developers, and other stakeholders.
  • Strong written and verbal communication, analytical, organizational, and leadership skills.
  • Ability to work effectively with federal government stakeholders in Washington, DC.

Preferred Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline.
  • Relevant professional certification, such as CISSP, CISM, CCSP, CAP/CGRC, or an equivalent cybersecurity certification.
  • Experience supporting a federal civilian agency.
  • Experience securing FedRAMP-authorized cloud platforms or services.
  • Familiarity with federal privacy requirements, privacy impact assessments, and the protection of personally identifiable information.
  • Experience supporting enterprise modernization, cloud migration, or platform-integration initiatives within a federal environment.

Skills

CybersecurityRisk ManagementComplianceProgram ManagementCISSP

Similar Jobs

30

Acquisition Security & Privacy Analyst (Job 1456)

Dlhcorporation · Bethesda, Maryland

4 days ago

Principal Security & Privacy Engineer

Medtronic · USA-MN Rice Creek East, United States of America · Onsite

5 days ago

Principal Security & Privacy Engineer

Medtronic · USA-MN Rice Creek East, United States of America · Onsite

5 days ago

Privacy Expert, Japan Privacy Group, RTS - Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 week ago

Principal AI Risk Management Specialist - AI Governance Management Section, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 week ago

Senior Program Manager - ISPD Operation Section, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 week ago

Privacy & Security Enterprise Engagement Officer

Centene and its subsidiary companies · Remote-MO, United States of America +3 · Remote

1 week ago

Group Manager, Rakuten Mobile & RTS Support Group - Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 week ago

Manager / Senior Manager - Security & Privacy

Rsmaus · Sydney, Australia +1

2 weeks ago

IT Security Specialist, IT Security Group - Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

3 weeks ago

Privacy & Security Engagement Officer

Centene and its subsidiary companies · Remote-MO, United States of America +3 · Remote

3 weeks ago

Technical Program Manager, Security & Privacy

Figureai · San Jose, CA +1 · Onsite

3 weeks ago

Principal Architect — Large Scale Enterprise Solutions, Agentic AI, Security, Privacy and Governance

Adobe · San Jose, United States of America · Remote, Hybrid, Onsite

1 month ago

Information Security Specialist - Global ISMS Operation & Support Group, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 month ago

Privacy Security Analyst

Owensborohealth · Owensboro Health Regional Hospital - Owensboro, KY, United States of America · Remote

1 month ago

AI Risk Management Specialist - AI Governance Management Section, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 month ago

Director of Security & Privacy

Freetrade · London · Hybrid

2 months ago

Head of Privacy & Security

Playlab · Remote · Remote

2 months ago

Software Engineer II – AI Engineer (w/ skills in AI Data Privacy, Security & Governance Specialty)

RobertHalf · SAN RAMON, United States of America · Remote

2 months ago

Legal Counsel, Privacy & Security

Comcast · Great Britain - London, 1 St Giles High St, United Kingdom

2 months ago

Senior Manager, Privacy & Security Regulatory Engagement

Centene and its subsidiary companies · Remote-MO, United States of America +2 · Remote

2 months ago

Data Security & Privacy Lead

Roche · Madrid Osiris, Spain · Onsite

2 months ago

Data Privacy & Security Analyst

Health Care District of Palm Beach County · West Palm Beach, Palm Beach, United States, US · Hybrid

2 months ago

Vice Manager, IT Security Group - Information Security Management Office, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

2 months ago

Privacy & Security Enterprise Engagement Officer

Centene and its subsidiary companies · Remote-MO, United States of America +3 · Remote

2 months ago

Information Governance Specialist/Domestic Group Company Support of Communication and Energy Company - Rakuten Mobile & RTS Support Group, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

2 months ago

Privacy & Security Manager

Nokia · India

3 months ago

Senior Counsel - AI, Privacy & Security Legal (Hybrid)

Transamerica · Denver, Colorado, United States of America +3

4 months ago

Specialist, Information Security & Privacy

Mindtickle · Pune, Maharashtra +1 · Hybrid

6 months ago

Vice Group Manager, Information Security Policy Group - Information Security Management Office, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

6 months ago