bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesBelleseInformation Systems Security Officer I (ISSO-1)

Information Systems Security Officer I (ISSO-1)

Bellese · United States · Remote · Deleted · $111,800–$134,200 / year · Lever

Job facts

FieldValue
CompanyBellese
TitleInformation Systems Security Officer I (ISSO-1)
Normalized title-
Department / teamEngineering / (HQR) Hospital Quality Reporting
LocationUnited States
Work modelRemote / Remote
Employment typeFull Time
Salary$111,800–$134,200 / year
Statusdeleted
ATS providerLever
Posted / first seen2026-03-26 / 2026-05-29
Changed / last seen2026-06-17 / 2026-06-15

Related slices

PageWhat it containsOpen
Company jobsActive postings from Bellese.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Lever.Open
Provider filtered searchThe same provider as a filtered job collection.Open
Department jobsActive postings in Engineering.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyBellese
Sourcee3f02073-cbc6-488c-8328-3836e9ab5c86
ATS providerLever

Description

Bellese is a mission-driven Digital Services Company committed to pioneering innovative technology solutions in civic healthcare. Our dedication lies in making a meaningful impact on public health outcomes. Driven by service design, we strive to know the “Why” to understand the healthcare journey for patients, caregivers, providers, payers, and policymakers. Our goal is to design and build solutions that reduce confusion, provide clarity, support decision making, and streamline the process so that we and our partners can focus on providing better health outcomes by improving patient care and reducing costs and burden. The Team you will be joining: You will be the ISSO for two Teams, QMARS & HQR QMARS Our team is charged with maintaining and improving the software at the Centers for Medicare and Medicaid Services (CMS) that supports the Quality Management and Review Systems (QMARS) program. QMARS online case management system supports the CMS Beneficiary and Family-Centered Care (BFCC) Quality Improvement Organization (QIO) program.  The QIO program is one of the largest federal programs dedicated to improving healthcare quality for Medicare beneficiaries across the country.  Our teams will continuously strive to modernize these systems while improving them in ways that reduce provider burden and minimize costs to CMS.  We do this through HCD and Service design practices, product thinking, and skilled engineering.  At Bellese, we’re relentlessly focused on enabling and empowering providers to focus on improving the quality and safety of patient care. HQR Our team is charged with maintaining and improving the software at the Centers for Medicare and Medicaid Services (CMS) that supports the Hospital Quality Reporting program. Thousands of hospitals across the country depend on these systems to submit quality measure data that reflects the care beneficiaries receive in their facility.  Our teams will continuously strive to modernize these systems, while improving them in ways that reduce provider burden and minimize costs to CMS.  We do this through HCD and Service design practices, product thinking, and skilled engineering.  At Bellese, we’re relentlessly focused on enabling and empowering providers to focus on improving the quality and safety of patient care. The  Information Systems Security Officer (ISSO) is responsible for implementing a value-based approach to security, versus the traditional focus on audits and compliance. The ISSO will work with infrastructure and feature development teams to introduce security early and throughout development processes, taking a proactive and active security analysis approach to identify potential risks and threats, and creating tests and countermeasures in procedures, code, and infrastructure to respond to potential threats. Security Clearance Requirements US Citizenship or Green Card only - we do not offer Sponsorship US Residency for at least the past 3 years Able to meet the requirements to hold a position of Public Trust, including successful completion of a US Government background investigation Disclaimer: Medical or recreational marijuana use is considered illegal at the federal level, regardless of state laws allowing such, and may affect your ability to obtain Public Trust. See article Work that matters, with perks that deliver. Discover how Bellese Technologies invests in you through a benefits suite that makes every day better Remote First, Remote Only Culture Four weeks paid time off yearly (prorated based on start date for the first year) 10 paid floating company holidays Flexible schedule Work from home setup including a Macbook Collaborative, learning environment Medical, dental, and company-paid vision insurance Optional HSA account with some medical plans and a company contribution Company paid basic life and AD&D insurance coverages Company paid short and long term life insurance Optional critical illness and accident insurance 401K plan with 3% safe harbor contribution Wellness resources and virtual care Perks Plus employee discounts You will like it here if You foster a collaborative ethos, driven by the mission to deliver exceptional customer service to clients. You are passionate about Healthcare and changing the healthcare landscape. You’re an out of the box thinker, always striving to know the “why” when it comes to building solutions. You excel in a team-oriented, remote-first environment characterized by mutual respect and open communication. Your adaptability and ability to navigate challenges ensure your success in any situation. What you will be doing: (1) SIA Maintenance (Primary Focus): You will proactively identify system changes in HQR and QMARS and document them in a Security Impact Analysis (SIA) to ensure the ATO remains valid. CFACTS Governance: You will serve as the "Source of Truth" for the system's security posture in CFACTS, managing control implementation statements and evidence. Audit Defense & Evidence Gathering: You will lead the "Audit Season" efforts, gathering screenshots, logs, and process documentation to prove to CMS auditors that controls are "Effective." Risk Advising: You will attend sprint ceremonies for HQR (50%) and QMARS (50%) to advise developers on CMS security standards before they build, preventing "security rework" later. POA&M Life-cycle: You will track security weaknesses from discovery to remediation, ensuring the program meets CMS's strict 30/60/90-day patching windows. Policy Stewardship: You will ensure all program documentation (Contingency Plans, Incident Response Plans) is reviewed and signed off annually per FISMA requirements. Technical Qualifications At least 4 years of experience establishing security controls as outlined in the responsibilities section above. Experience working with two or more from the following: web application development, unix/linux environments, distributed systems, machine learning, developing large scale systems and API services, security software development Experience with one or more infrastructure scripting languages: Terraform, CloudFormation, Ansible, Chef or Puppet, Kubernetes Experience implementing two or more cloud-based solutions: global infrastructure, virtual clouds, virtual computing, serverless computing, load balancing and networking, data storage and data streaming, hadoop, map reduce, secured REST-based API endpoints, security Direct, hands-on experience with CFACTS. (This experience is only available if you hve worked with CMS (Centers for medicare & medicaid) Proven ability to author Security Impact Analyses (SIA), System Security Plans (SSP), and Privacy Impact Assessments (PIA) specifically under NIST 800-53 Rev 5 and CMS ARS 5.0. A&A Lifecycle: Experience taking a system through the Assessment & Authorization (A&A) process to achieve or maintain an ATO (Authority to Operate). Vulnerability Management: Ability to interpret Tenable/Nessus or WebInspect scans to translate technical vulnerabilities into POA&Ms (Plan of Action and Milestones) that developers can understand. Cloud-Native Compliance: Understanding of how to document security controls for AWS-native services

Full job record

Job IDe2abc5933d98d0309a1d20ac9ef030c0a5685755
Org IDa241141c-5d1f-4b7a-8534-921c15c03a6f
Source IDe3f02073-cbc6-488c-8328-3836e9ab5c86
Board IDe3f02073-cbc6-488c-8328-3836e9ab5c86
Providerlever
Provider Job Key77372517-daf6-407b-9e9a-418ace26c299
TitleInformation Systems Security Officer I (ISSO-1)
Normalized Title
Statusdeleted
Activeno
Location TextUnited States
DepartmentEngineering
Team(HQR) Hospital Quality Reporting
Employment TypeFull Time
Workplace Typeremote
Remote Policyremote
CountryUnited States
Region
City
Salary RawUSD 111800-134200 per-year-salary
Salary Min111,800
Salary Max134,200
Salary CurrencyUSD
Salary Periodyear
Source URLhttps://jobs.lever.co/bellese/77372517-daf6-407b-9e9a-418ace26c299
Apply URLhttps://jobs.lever.co/bellese/77372517-daf6-407b-9e9a-418ace26c299/apply
First Seen At2026-05-29 07:06:03Z
Last Seen At2026-06-15 07:57:50Z
Last Checked At2026-06-17 07:58:22Z
Last Changed At2026-06-17 07:58:22Z
Inactive At2026-06-17 07:58:22Z
Source Posted At2026-03-26 16:01:25Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=lever/board=bellese/date=2026-06-15/2026-06-15T07-57-49-850Z-f6db57e5ebe250ff097e8cb5c51b629f7cf26f1aa38de411639d411c8fc91fda.json
Event Fields
{
  "content_hash": "06c392a3a14c632d67c53ff59cec1ff2784eb1ebfe74db567e14c99affe4ef2e",
  "source_hash": "50246c146acb9ffb2543a361d34e78b71e3611a75de0397457899e818df5e2e1",
  "last_changed_at": "2026-06-17T07:58:22.100Z",
  "active_status": "deleted"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "United States",
    "city": null,
    "region": null,
    "country": "United States",
    "is_remote": true,
    "confidence": 0.95
  },
  "salary_max": 134200,
  "salary_min": 111800,
  "inferred_at": "2026-06-15T07:57:50.076Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "United States",
      "city": null,
      "region": null,
      "country": "United States",
      "is_remote": true,
      "confidence": 0.95
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": "year",
  "workplace_type": "remote",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "lists": [
    {
      "text": "Security Clearance Requirements",
      "content": "\n<li>US Citizenship or Green Card only - we do not offer Sponsorship</li>\n<li>US Residency for at least the past 3 years</li>\n<li>Able to meet the requirements to hold a position of Public Trust, including successful completion of a US Government background investigation</li>\n<li>Disclaimer: Medical or recreational marijuana use is considered illegal at the federal level, regardless of state laws allowing such, and may affect your ability to obtain Public Trust. See <a href=\"https://news.clearancejobs.com/2024/03/14/marijuana-use-and-involvement-in-the-new-security-clearance-questionnaire/\">article</a></li>\n"
    },
    {
      "text": "Work that matters, with perks that deliver. Discover how Bellese Technologies invests in you through a benefits suite that makes every day better",
      "content": "\n<li>Remote First, Remote Only Culture</li>\n<li>Four weeks paid time off yearly (prorated based on start date for the first year)</li>\n<li>10 paid floating<strong>&nbsp;</strong>company holidays</li>\n<li>Flexible schedule</li>\n<li>Work from home setup including a Macbook&nbsp;</li>\n<li>Collaborative, learning environment</li>\n<li>Medical, dental, and company-paid vision insurance</li>\n<li>Optional HSA account with some medical plans and a company contribution</li>\n<li>Company paid basic life and AD&amp;D insurance coverages</li>\n<li>Company paid short and long term life insurance</li>\n<li>Optional critical illness and accident insurance</li>\n<li>401K plan with 3% safe harbor contribution</li>\n<li>Wellness resources and virtual care</li>\n<li>Perks Plus employee discounts</li>\n"
    },
    {
      "text": "You will like it here if ",
      "content": "\n<li>You foster a collaborative ethos, driven by the mission to deliver exceptional customer service to clients. You are passionate about Healthcare and changing the healthcare landscape. You’re an out of the box thinker, always striving to know the “why” when it comes to building solutions. You excel in a team-oriented, remote-first environment characterized by mutual respect and open communication. Your adaptability and ability to navigate challenges ensure your success in any situation.</li>\n"
    },
    {
      "text": "What you will be doing:",
      "content": "<div>\n\n<li>(1) SIA Maintenance (Primary Focus): You will proactively identify system changes in HQR and QMARS and document them in a Security Impact Analysis (SIA) to ensure the ATO remains valid.</li>\n<li>CFACTS Governance: You will serve as the \"Source of Truth\" for the system's security posture in CFACTS, managing control implementation statements and evidence.</li>\n<li>Audit Defense &amp; Evidence Gathering: You will lead the \"Audit Season\" efforts, gathering screenshots, logs, and process documentation to prove to CMS auditors that controls are \"Effective.\"</li>\n<li>Risk Advising: You will attend sprint ceremonies for HQR (50%) and QMARS (50%) to advise developers on CMS security standards before they build, preventing \"security rework\" later.</li>\n<li>POA&amp;M Life-cycle: You will track security weaknesses from discovery to remediation, ensuring the program meets CMS's strict 30/60/90-day patching windows.</li>\n<li>Policy Stewardship: You will ensure all program documentation (Contingency Plans, Incident Response Plans) is reviewed and signed off annually per FISMA requirements.</li>\n\n</div>"
    },
    {
      "text": "Technical Qualifications",
      "content": "<div>\n\n<li>At least 4 years of experience establishing security controls as outlined in the responsibilities section above.</li>\n<li>Experience working with two or more from the following:&nbsp;web application development, unix/linux environments, distributed systems, machine learning, developing large scale systems and API services, security software development</li>\n<li>Experience with one or more infrastructure scripting languages: Terraform, CloudFormation, Ansible, Chef or Puppet, Kubernetes</li>\n<li>Experience implementing two or more cloud-based solutions:&nbsp;global infrastructure, virtual clouds, virtual computing, serverless computing, load balancing and networking, data storage and data streaming, hadoop, map reduce, secured REST-based API endpoints, security</li>\n<li><strong>Direct, hands-on experience with CFACTS. </strong>(This experience is only available if you hve worked with CMS (Centers for medicare &amp; medicaid)</li>\n<li>Proven ability to author Security Impact Analyses (SIA), System Security Plans (SSP), and Privacy Impact Assessments (PIA) specifically under NIST 800-53 Rev 5 and CMS ARS 5.0.</li>\n<li>A&amp;A Lifecycle: Experience taking a system through the Assessment &amp; Authorization (A&amp;A) process to achieve or maintain an ATO (Authority to Operate).</li>\n<li>Vulnerability Management: Ability to interpret Tenable/Nessus or WebInspect scans to translate technical vulnerabilities into POA&amp;Ms (Plan of Action and Milestones) that developers can understand.</li>\n<li>Cloud-Native Compliance: Understanding of how to document security controls for AWS-native services&nbsp;</li>\n\n</div>"
    }
  ],
  "country": "US",
  "createdAt": 1774540885903,
  "updatedAt": null,
  "categories": {
    "team": "(HQR) Hospital Quality Reporting",
    "location": "United States",
    "commitment": "Full Time",
    "department": "Engineering",
    "allLocations": [
      "United States"
    ]
  },
  "salaryRange": {
    "max": 134200,
    "min": 111800,
    "currency": "USD",
    "interval": "per-year-salary"
  },
  "workplaceType": "remote"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/e2abc5933d98d0309a1d20ac9ef030c0a5685755?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/a241141c-5d1f-4b7a-8534-921c15c03a6fJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/e3f02073-cbc6-488c-8328-3836e9ab5c86JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/e2abc5933d98d0309a1d20ac9ef030c0a5685755/eventsJSON