About QBE, LLC
QBE, LLC is a small business dedicated to delivering innovative technology, cybersecurity, and mission-support solutions to federal government customers. Our experienced professionals work closely with our customers to solve complex challenges, protect critical information, and support essential government missions.
At QBE, we turn the possible into the proven.
Overview
QBE, LLC is seeking an experienced Defensive Cybersecurity Advisor — RMF/A&A Lead to support comprehensive information security services for the National Institutes of Health, Office of the Director, Office of Information Technology (NIH/OD-OIT).
Responsibilities
- Lead and coordinate Risk Management Framework (RMF) and Assessment and Authorization (A&A) activities for federal information systems and applications.
- Provide subject-matter expertise related to federal cybersecurity requirements, security authorization processes, and risk management.
- Guide system owners and technical teams through the full system authorization lifecycle.
- Develop, review, and maintain security authorization documentation, including:
o System Security Plans
o Security Assessment Plans and Reports
o Plans of Action and Milestones
o Risk assessments
o Security control implementation statements
o Contingency planning documentation
o Continuous monitoring documentation
- Evaluate system security controls using applicable NIST guidance and federal security requirements.
- Coordinate security assessments, control testing, evidence collection, and remediation activities
- Review system changes to determine potential impacts on security authorizations and organizational risk.
- Identify cybersecurity risks, control deficiencies, and compliance gaps and recommend appropriate corrective actions.
- Track security findings, vulnerabilities, and remediation activities through closure
- Support continuous monitoring activities for Low- and Moderate-impact systems.
- Review technical and nontechnical security documentation for accuracy, consistency, and compliance.
- Provide cybersecurity guidance for on-premises, cloud-based, hybrid, and third-party systems.
- Support Governance, Risk, and Compliance initiatives across the customer environment.
- Collaborate with Security Operations and Engineering teams to ensure technical security activities align with RMF and authorization requirements.
- Assist with the development and improvement of cybersecurity policies, procedures, standards, and governance processes.
- Prepare cybersecurity status reports, risk summaries, dashboards, and briefing materials for technical and executive audiences.
- Participate in meetings with government stakeholders, system owners, auditors, assessors, and cybersecurity personnel.
- Provide recommendations that support the continued improvement and maturation of the organization’s cybersecurity program.
**This position will be primarily REMOTE but will require some onsite work in Bethesda, MD
#qf #qg
Minimum Qualifications
- Associate degree in cybersecurity, information technology, computer science, information systems, or a related field, or an additional two or more years of relevant experience in place of the degree requirement.
- At least eight years of relevant cybersecurity, information assurance, risk management, or security compliance experience.
- Demonstrated experience leading RMF and A&A activities for federal information systems.
- Working knowledge of NIST Special Publication 800-37, NIST Special Publication 800-53, FIPS 199, FIPS 200, and related federal cybersecurity guidance.
- Experience developing, reviewing, and maintaining security authorization documentation.
- Experience assessing security controls and supporting security control validation activities.
- Experience managing Plans of Action and Milestones and tracking remediation activities.
- Experience supporting Low- and Moderate-impact federal information systems.
- Understanding of cybersecurity risks associated with hybrid, cloud-based, on-premises, and third-party environments.
- Ability to communicate complex cybersecurity and compliance requirements to technical and nontechnical stakeholders.
- Strong documentation, analytical, organizational, and problem-solving skills.
- CompTIA Security+ certification.
- CompTIA SecurityX certification.
- Ability to obtain and maintain the required Public Trust determination associated with the position.
Preferred Qualifications
- Bachelor’s degree in cybersecurity, information technology, computer science, information systems, or a related field.
- Experience supporting cybersecurity programs within the Department of Health and Human Services, National Institutes of Health, or another federal civilian agency.
- Experience supporting environments that process protected health information, personally identifiable information, research data, or other sensitive information.
- Familiarity with federal privacy, healthcare data protection, and information security requirements.
- Experience with Governance, Risk, and Compliance platforms or automated security authorization tools.
- Experience supporting cloud security assessments and authorization activities.
- Experience briefing senior government leadership on cybersecurity risks, findings, and remediation strategies.
- Additional certifications such as CISSP, CGRC, CISM, or other advanced cybersecurity credentials.
Physical Requirements
- Ability to remain in a stationary position for extended periods while working at a computer.
- Ability to operate standard office equipment and communicate effectively through virtual and in-person meetings.
- Ability to perform duties in an office, remote, or hybrid work environment based on program requirements.
Equal Opportunity Employer
QBE is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender, gender-identity and/or expression, age, disability, Veteran status, genetic information, pregnancy (including childbirth, lactation, or related medical conditions), marital status, neurodivergence, ethnicity, ancestry, caste, military/uniformed service-member status, or any other characteristic protected by applicable law.
The projected compensation range for this position is $149,282.00 - $207,459.00. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (for remote opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, QBE invests in its employees beyond just compensation. QBE's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections.