• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board Information Security Officer

$112,800–160,000/yr 1d ago

Information Security Officer

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

eSimplicity

Columbia, MD, US

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

The Senior Information Security Analyst will provide security compliance, risk management, and continuous monitoring support for CMS programs. Responsibilities include maintaining security control implementation statements, managing vulnerability findings, and supporting Authorization to Operate (ATO) activities.

Job Description

Description

About Us:

eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow.

Purpose of Scope:

The Senior Information Security Analyst will provide security compliance, risk management, vulnerability management, audit, and

continuous monitoring support for a Centers for Medicare & Medicaid Services (CMS) program. This role requires extensive

knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS Acceptable Risk Safeguards (ARS).

The analyst will independently develop and maintain detailed security control implementation statements, evaluate supporting

evidence, conduct Security Impact Analyses, support Authorization to Operate activities, and prepare systems for security

assessments and audits. The analyst will also manage vulnerability and compliance findings throughout their lifecycle, including

validation, remediation coordination, POA&M management, risk exception development, retesting, and closure.

This position will work closely with CMS ISSOs, product owners, engineers, infrastructure teams, security assessors, auditors, and

program leadership. The successful candidate must be able to produce accurate, audit-ready security documentation, identify

compliance gaps, communicate security risks clearly, and drive assigned activities to completion with minimal supervision.

Responsibilities:  

  • Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership. 
  • Interpret FISMA, NIST RMF, NIST SP 800-53, CMS ARS, and agency security requirements and translate them into clear technical and operational actions. 
  • Develop, review, and maintain detailed security control implementation statements that accurately reflect the system environment, responsible parties, processes, technologies, and supporting evidence. 
  • Maintain and support ATO artifacts, including System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related documentation. 
  • Lead Security Impact Analyses for proposed system, application, infrastructure, cloud, data, and configuration changes. 
  • Support security assessments and audits by coordinating evidence collection, reviewing artifacts, responding to assessor inquiries, documenting gaps, and tracking corrective actions through closure. 
  • Review vulnerability and compliance scan results; validate findings; assess risk; and coordinate remediation with product, engineering, infrastructure, and DevSecOps teams. 
  • Develop and review vulnerability documentation, remediation plans, POA&Ms, false-positive determinations, and risk exception requests to ensure they are complete, accurate, and appropriately supported. 
  • Track vulnerability and compliance findings through assignment, remediation, mitigation, risk acceptance, retesting, and closure. 
  • Support continuous monitoring activities, access reviews, security data calls, compliance reporting, and security posture assessments. 
  • Identify control, evidence, and documentation gaps and recommend corrective actions or process improvements to reduce security risk. 
  • Develop security metrics, dashboards, status reports, and risk summaries for government stakeholders and program leadership. 
  • Maintain timely and accurate communication regarding security risks, decisions, dependencies, overdue actions, and remediation status. 
  • Mentor security team members and perform quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables. 

Requirements

  • Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles, with demonstrated technical depth and increasing responsibility.
  • A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline.
  • Demonstrated experience supporting federal systems subject to FISMA and the NIST Risk Management Framework.
  • Experience applying NIST SP 800-53 security and privacy controls and CMS ARS or comparable federal security requirements.
  • Demonstrated experience developing, reviewing, and maintaining detailed, system-specific security control implementation statements and supporting evidence.
  •  Experience supporting ATO activities and maintaining System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related security artifacts. 
  • Experience leading or supporting security assessments and audits, including evidence collection, assessor responses, gap identification, corrective action planning, remediation tracking, and closure validation. 
  • Experience managing vulnerability and compliance findings through validation, assignment, remediation, mitigation, risk acceptance, retesting, and closure. 
  • Experience with vulnerability and compliance tools such as Tenable, Snyk, AWS Security Hub, AWS Inspector, or comparable platforms. 
  • Ability to prepare technically supported risk exception requests and vulnerability documentation that includes affected assets, vulnerability-specific risk, compensating controls, mitigation analysis, remediation plans, owners, target dates, and validation methods. 
  • Demonstrated ability to develop accurate, audit-ready documentation and communicate security requirements, risks, findings, and remediation activities to technical and non-technical stakeholders.
  • Demonstrated ability to manage concurrent assignments, meet established deadlines, maintain accurate status reporting, and escalate risks or blockers as appropriate. 
  • Ability to obtain and maintain a Public Trust clearance and have resided in the United States for at least 3 of the last 5 years.

Desired Qualifications:

  •  Direct experience supporting CMS systems, CMS security programs, or CMS ATO activities. 
  • Advanced experience applying CMS ARS 5.0 or later to security control implementation, documentation, assessment, and continuous monitoring activities. 
  • Demonstrated expertise writing and reviewing security control statements that clearly describe responsible parties, implementation methods, technologies, procedures, frequency, inheritance, and supporting evidence. 
  • Experience leading control-statement reviews or control-mapping efforts resulting from CMS ARS updates, NIST SP 800-53 revisions, cloud migrations, system modernization, or authorization boundary changes. 
  • Experience conducting Security Impact Analyses for application, infrastructure, cloud, data, integration, and configuration changes.
  • Experience supporting Security Control Assessments, FISMA audits, Office of Inspector General reviews, internal audits, penetration tests, or independent verification and validation activities. 
  • Experience communicating directly with CMS ISSOs, security assessors, auditors, system owners, and government program leadership. 
  • Experience securing or assessing AWS cloud environments and reviewing cloud security, access management, logging, monitoring, encryption, and configuration controls. 
  • Familiarity with DevSecOps, CI/CD pipelines, source-code scanning, software composition analysis, container scanning, and security release reviews. • Experience using Jira, Confluence, and ServiceNow to manage security documentation, vulnerabilities, compliance activities, risks, and corrective actions. 
  • Experience developing security metrics, dashboards, audit-readiness reports, vulnerability reports, and executive-level risk summaries. 
  • Current certification such as CISSP, CISM, CISA, CRISC, CAP/CGRC, CCSP, or an equivalent security or audit certification. 
  • Experience mentoring security analysts and performing quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables. 

Working Environment:

eSimplicity supports a remote work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by your manager.

Occasional travel for training and project meetings. It is estimated to be less than 5% per year.

Benefits:

eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms.

Reasonable Accommodation:

eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources.

Equal Employment Opportunity:

eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status.

About the company

eSimplicity

eSimplicity is a trusted partner that integrates commercial and open-source solutions to empower government services and strengthen the country's defense and national security. Driven by our customers’ missions and their users, we transform design, data, and deep subject-matter expertise into measurable value that impact the lives and well-being of all Americans. We don’t just do more with less. We do better.

Founded

2016

Company size

201-500 employees

Industry

IT Services and IT Consulting

Org type

Privately Held

Headquarters

Silver Spring, Maryland

Apply Now

About the company

eSimplicity

eSimplicity is a trusted partner that integrates commercial and open-source solutions to empower government services and strengthen the country's defense and national security. Driven by our customers’ missions and their users, we transform design, data, and deep subject-matter expertise into measurable value that impact the lives and well-being of all Americans. We don’t just do more with less. We do better.

Founded

2016

Company size

201-500 employees

Industry

IT Services and IT Consulting

Org type

Privately Held

Headquarters

Silver Spring, Maryland

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.