bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCareers Cvpcorp Icims ComRisk Manager

Risk Manager

Careers Cvpcorp Icims Com · Rockville, MD, US · Hybrid · Active · $155 · iCIMS

Job facts

FieldValue
CompanyCareers Cvpcorp Icims Com
TitleRisk Manager
Normalized title-
Department / teamManagement
LocationRockville, MD, United States
Work modelHybrid / Hybrid
Employment typeFull Time
Salary$155
Statusactive
ATS provideriCIMS
Posted / first seen2024-06-06 / 2026-05-31
Changed / last seen2026-06-06 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Careers Cvpcorp Icims Com.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through iCIMS.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Rockville.Open
Department jobsActive postings in Management.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCareers Cvpcorp Icims Com
Source0e0b1975-95dc-4fd8-a2df-38e059f2a650
ATS provideriCIMS

Description

Overview CVP is seeking an Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency’s CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks. Responsibilities Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency. Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency’s Information Security Program related to governance, optimizations, automation, and supporting tools. Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for Information Systems and Organizations and SP 800-39, Managing Information Security Risk (as revised). Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency’s Information Security Risk Assessment Report Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization’s information security risk management and security assessment and authorization (A&A) activities. Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things. Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations. Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities. Provide risk management and information security continuous monitoring program implementation recommendations to program offices Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support. Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency’s data and operations. Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested. Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates. Qualifications Minimum of six years’ experience in cybersecurity. 10+ years’ experience is preferred. Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years’ experience is preferred. Shall have at least one of the following industry-recognized certifications: Certified Information System Security Professional (CISSP) Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) Certified in Risk and Information Systems Control (CRISC) Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM. Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks. Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation. Desired Skills PMP Certification CISSP Certification Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect) NIH/HHS experience Location Rockville, MD (Hybrid) Salary Band: $155-165k (Depending on experience) About CVP CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.

Full job record

Job ID619d9500bbbefe5b5a40d73d2e360e1e2d1ebdcb
Org IDfead0b03-0a8a-4f51-821f-cb7e6649f3b3
Source ID0e0b1975-95dc-4fd8-a2df-38e059f2a650
Board ID0e0b1975-95dc-4fd8-a2df-38e059f2a650
Providericims
Provider Job Key3192
TitleRisk Manager
Normalized Title
Statusactive
Activeyes
Location TextRockville, MD, US
DepartmentManagement
Team
Employment Typefull_time
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionMD
CityRockville
Salary RawOverview CVP is seeking an Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency’s CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks. Responsibilities Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency. Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency’s Information Security Program related to governance, optimizations, automation, and supporting tools. Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for Information Systems and Organizations and SP 800-39, Managing Information Security Risk (as revised). Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency’s Information Security Risk Assessment Report Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization’s information security risk management and security assessment and authorization (A&A) activities. Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things. Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations. Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities. Provide risk management and information security continuous monitoring program implementation recommendations to program offices Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support. Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency’s data and operations. Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested. Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates. Qualifications Minimum of six years’ experience in cybersecurity. 10+ years’ experience is preferred. Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years’ experience is preferred. Shall have at least one of the following industry-recognized certifications: Certified Information System Security Professional (CISSP) Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) Certified in Risk and Information Systems Control (CRISC) Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM. Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks. Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation. Desired Skills PMP Certification CISSP Certification Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect) NIH/HHS experience Location Rockville, MD (Hybrid) Salary Band: $155-165k (Depending on experience) About CVP CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.
Salary Min155
Salary Max
Salary CurrencyUSD
Salary Period
Source URLhttps://careers-cvpcorp.icims.com/jobs/3192/risk-manager/job
Apply URLhttps://careers-cvpcorp.icims.com/jobs/3192/risk-manager/job
First Seen At2026-05-31 18:35:50Z
Last Seen At2026-06-06 19:05:47Z
Last Checked At2026-06-06 19:05:47Z
Last Changed At2026-06-06 19:05:47Z
Inactive At
Source Posted At2024-06-06 19:05:45Z
Source Updated At2026-05-21 16:41:27Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-cvpcorp.icims.com/date=2026-06-06/2026-06-06T19-05-45-026Z-8607102e63351996c364a70e40e7c0eb82f50ea9ef933e0db0f316aea8c9ce26.json
Event Fields
{
  "content_hash": "1455a59cd84ae771402346dd3141ba63c72a05f93815b6262cf50c6a2f82983d",
  "source_hash": "ce839f17bf9d40c6574a676f75d8f00d200f1c0838cd15fb9d9afb360f2d754a",
  "last_changed_at": "2026-06-06T19:05:47.582Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Rockville, MD, US",
    "city": "Rockville",
    "region": "MD",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": null,
  "salary_min": 155,
  "inferred_at": "2026-06-06T19:05:47.551Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Rockville, MD, US",
      "city": "Rockville",
      "region": "MD",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": null,
  "workplace_type": "hybrid",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "json_ld": {
    "url": "https://careers-cvpcorp.icims.com/jobs/3192/risk-manager/job",
    "@type": "JobPosting",
    "title": "Risk Manager",
    "@context": "http://schema.org",
    "datePosted": "2024-06-06T19:05:45.927Z",
    "description": "<h2>Overview</h2>\n<p>CVP is seeking an Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency’s CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks.</p>\n<p> </p>\n<h2>Responsibilities</h2>\n<ul>\n <li>Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency. </li>\n <li>Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency’s Information Security Program related to governance, optimizations, automation, and supporting tools. </li>\n <li>Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, <em>Risk Management Framework for Information Systems and Organizations </em>and SP 800-39, <em>Managing Information Security Risk </em>(as revised). </li>\n <li>Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment</li>\n <li>Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency’s Information Security Risk Assessment Report </li>\n <li>Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities </li>\n <li>Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements </li>\n <li>Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization’s information security risk management and security assessment and authorization (A&A) activities. </li>\n <li>Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things. </li>\n <li>Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations.</li>\n <li>Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities. </li>\n <li>Provide risk management and information security continuous monitoring program implementation recommendations to program offices</li>\n <li>Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support. </li>\n <li>Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency’s data and operations.</li>\n <li>Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested.</li>\n <li>Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates.</li>\n</ul>\n<h2>Qualifications</h2>\n<ul>\n <li>Minimum of six years’ experience in cybersecurity. 10+ years’ experience is preferred.</li>\n <li>Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years’ experience is preferred.</li>\n <li>Shall have at least one of the following industry-recognized certifications:\n  <ul>\n   <li>Certified Information System Security Professional (CISSP)</li>\n   <li>Certified Information Systems Auditor (CISA)</li>\n   <li>Certified Information Security Manager (CISM)</li>\n   <li>Certified in Risk and Information Systems Control (CRISC)</li>\n  </ul></li>\n <li>Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM.</li>\n <li>Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks.</li>\n <li>Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation.<strong></strong></li>\n</ul>\n<p><strong>Desired Skills</strong></p>\n<ul>\n <li>PMP Certification</li>\n <li>CISSP Certification</li>\n <li>Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)</li>\n <li>NIH/HHS experience</li>\n</ul>\n<p><strong>Location</strong></p>\n<ul>\n <li>Rockville, MD (Hybrid)</li>\n</ul>\n<p><strong>Salary Band:</strong> $155-165k (Depending on experience)</p>\n<p> </p>\n<p><strong>About CVP</strong></p>\n<p> </p>\n<p>CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.</p>\n<p> </p>",
    "directApply": true,
    "jobLocation": [
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "20850",
          "addressRegion": "MD",
          "streetAddress": "9609 Medical Center Dr",
          "addressCountry": "US",
          "addressLocality": "Rockville",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      }
    ],
    "validThrough": "2027-06-06T19:05:45.927Z",
    "employmentType": "FULL_TIME",
    "hiringOrganization": {
      "name": "Customer Value Partners",
      "@type": "Organization",
      "sameAs": "www.cvpcorp.com"
    },
    "occupationalCategory": "Management"
  },
  "detail_meta": {
    "url": "https://careers-cvpcorp.icims.com/jobs/3192/risk-manager/job?in_iframe=1",
    "http_status": 200,
    "content_type": "text/html;charset=UTF-8",
    "response_bytes": 42439,
    "compact_response_bytes": 8046,
    "original_response_bytes": 42439
  },
  "sitemap_job": {
    "id": "3192",
    "url": "https://careers-cvpcorp.icims.com/jobs/3192/risk-manager/job",
    "slug": "risk-manager",
    "lastmod": "2026-05-21T12:41:27-04:00"
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/619d9500bbbefe5b5a40d73d2e360e1e2d1ebdcb?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/fead0b03-0a8a-4f51-821f-cb7e6649f3b3JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/0e0b1975-95dc-4fd8-a2df-38e059f2a650JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/619d9500bbbefe5b5a40d73d2e360e1e2d1ebdcb/eventsJSON