Senior Cybersecurity Governance, Risk & Compliance (GRC) and Cyber Operations Specialist jobs in United States
cer-icon
Apply on Employer Site
company-logo

Brighton Marine · 23 hours ago

Senior Cybersecurity Governance, Risk & Compliance (GRC) and Cyber Operations Specialist

Brighton Marine is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) and Cyber Operations Specialist to design, implement, and sustain a full CMMC Level 2-aligned cybersecurity program. This role involves policy and compliance development along with hands-on cyber operational support, requiring significant federal cybersecurity experience and deep knowledge of CMMC Level 2 and NIST SP 800-171 requirements.

Health CareHealth DiagnosticsMedicalNon ProfitPrimary and Urgent Care
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Conduct full CMMC Level 2 gap assessments , including technical, documentation, and evidence requirements
Develop or refresh the complete suite of CMMC Level 2 policies, procedures, SOPs, standards, and artifacts
Establish and maintain evidence-generation processes, compliance workflows, and control owner mappings
Create and maintain the CMMC compliance boundary , including enclave definitions and trust boundary diagrams
Build or update all required cybersecurity documentation, including:
System Security Plan (SSP)•
Network / data flow / trust boundary diagrams•
Control implementation statements•
POA&M and risk register•
Incident Response Plan & playbooks•
Disaster Recovery & Continuity of Operations documents•
Configuration baselines and hardening guides•
Audit & assessment plans•
Implement assigned cybersecurity controls and develop repeatable processes to achieve and maintain CMMC compliance
Establish operational workflows to support evidence generation, logging, monitoring, MFA, RBAC, vulnerability management, and configuration management
Integrate cybersecurity controls with IT service delivery processes (e.g., onboarding, offboarding, patch cycles)
Maintain and continuously improve the CMMC Level 2 control environment
Perform recurring control checks, evidence collection, and documentation updates
Support annual self-assessments and external C3PAO assessments
Maintain a live POA&M and coordinate remediation and risk mitigation efforts
Produce quarterly risk posture reports and recurring GRC reporting
Track vulnerabilities, coordinate patching, and support remediation planning
Review and analyze security logs within SIEM tools for anomalies or potential security events
Provide triage and support for low/medium severity incidents; participate in IR exercises
Maintain configuration baselines, control mappings, and support security change management
Support audit and evidence binder refresh cycles

Qualification

CMMC Level 2NIST SP 800-171Federal CybersecuritySIEM platformsVulnerability management toolsIncident response processesDFARS 252.204-7012CISSPCISMSecurity+CCAKPolicy writingCommunication skills

Required

5+ years of experience in Federal Cybersecurity, GRC, CMMC, or NIST SP 800-171 environments
Hands-on experience supporting DoD, DHA, VA, or other federal agencies
Strong understanding of CMMC Level 2 / NIST SP 800-171
Strong understanding of DFARS 252.204-7012
Strong understanding of FedRAMP, C3PAO readiness, and federal compliance frameworks
Experience with SIEM platforms
Experience with Vulnerability management tools
Experience with Logging and monitoring systems
Experience with Incident response processes
Ability to write and maintain policies, SOPs, and comprehensive security documentation
Strong communication skills and the ability to work with technical and executive stakeholders
Must be able to obtain U.S. Government personnel security clearance as a condition of employment
Must comply with DFARS 252.204-7012, NIST SP 800-171, and CMMC Level 2 requirements
Must handle, store, and protect CUI in accordance with federal requirements
Contractor/employee systems accessing CUI must meet CMMC Level 2 requirements

Preferred

CISSP
CISM
Security+
CCAK
Other federal cybersecurity or audit certifications

Company

Brighton Marine

twittertwittertwitter
company-logo
Brighton Marine Health Center is a non-profit corporation that provides primary care, diagnostic, and behavioral health services.