Lexical
NLM Security Specialist I - III
Bethesda, Maryland · Mid
Sponsorship not specified$53k-$800kDetected 33 days ago
GitAWSGCPAzureCloud PlatformsDockerKubernetesTerraformAnsibleCI/CDGitHub ActionsLinuxPrometheusGrafanaDevOpsRESTData AnalysisData ScienceNLPCybersecurityPenetration TestingComplianceJiraConfluence
About the role
- Security Specialist I - III Lexical Intelligence provides software and services related to processing large-scale biomedical information sources.
- Our Natural Language Processing (NLP) and analytics software is used by policy and decision makers to evaluate and prioritize current and emerging areas of research.
- The Security Specialists will have experience in federal information security and compliance, vulnerability assessment and risk management, and cloud and application security operations.
Responsibilities
- Support or lead the design and implementation of secure computing environments in accordance with Government FISMA policies, including firewalls, intrusion detection systems, and disaster recovery planning
- Track and manage known vulnerabilities using Tenable Security Center and related security tools, ensuring resolution in alignment with HHS vulnerability management timelines
- Support or provide security management and oversight to identify and address security vulnerabilities in both Windows and Linux systems
- Assist in or lead secure coding quality assurance activities in accordance with US-CERT standards and OWASP guidelines
- Assist in or lead Privacy Impact Assessments (PIA) and Privacy Threshold Analyses (PTA) in coordination with the NIH Office of the Senior Official for Privacy, ensuring assessments are reviewed and updated at l
- Support or lead cybersecurity and risk management activities across NLM enterprise systems, networks, databases, and application development environments, ensuring alignment with FISMA, NIST, HHS, and NIH security policies and requirements
- Conduct or oversee vulnerability assessments and threat identification activities; document findings and support or lead remediation efforts within prescribed timelines in accordance with HHS Policy for Vulnerability Management and POAM requirements
Requirements
- 4 years of relevant information security or cybersecurity experience
- Bachelor's degree or other degree(s) in Computer Science, Information Security, Information Technology, or related fields
- Knowledge and practice of the Federal Information Security Modernization Act (FISMA) and related compliance frameworks
- Experience with NIST Special Publications including SP 800-53, SP 800-171, SP 800-88, and SP 800-64
- Experience supporting or maintaining Authority to Operate (ATO) documentation and System Security Plans (SSPs)
- Familiarity with vulnerability scanning and management tools such as Tenable Security Center, Nessus, or Prowler
- Strong written and oral communication skills, including the ability to convey technical security concepts in plain language
- 6 years of progressive information security or cybersecurity experience in a federal or government contracting environment
- Bachelor's degree or other degree(s) in Computer Science, Information Security, Information Technology, Cybersecurity, or related fields
- Demonstrated expertise in FISMA compliance, including full lifecycle management of ATO documentation and SSP development and maintenance
Nice to have
- Experience with application security scanning tools such as Netsparker, Checkmarx, or OWASP-based tools
- Familiarity with security assessment tools and penetration testing methodologies
- Experience supporting cloud security operations across AWS, GC, and/or Microsoft Azure environments, including IAM administration and cloud resource monitoring
- Knowledge of container security and orchestration platforms such as Kubernetes, Docker, OpenShift, or Anthos
- Experience with CI/CD pipeline security integration using tools such as GitLab, GitHub Actions, Nexus, or equivalent platforms
- Familiarity with Infrastructure as Code (IaC) security practices using tools such as Terraform, Ansible, Puppet, or AWS CDK
- Experience with monitoring and logging tools such as EFK stack, Prometheus, Grafana, or Splunk for security event analysis
- Experience with Privacy Impact Assessments (PIA), Privacy Threshold Analyses (PTA), and handling of PII and PHI in compliance with the Privacy Act, HIPAA, and applicable federal regulations
Compensation
- Assist in or manage the lifecycle of Authority to Operate (ATO) documentation and System Security Plans (SSPs), supporting annual reviews and updates in response to evolving programmatic and security requirements
Benefits
- Support or oversee the security of FISMA-moderate environments such as FEHRDI, ensuring that systems handling sensitive clinical and health-related data comply with all applicable security and privacy requirements
Apply directly at Lexical →Create a free account for alerts like thisView Lexical immigration profile
This listing is sourced directly from Lexical's careers page and normalized into a canonical job model.