Nava is seeking a Senior Program Manager (ISSO) to lead system security, risk management, and infrastructure oversight in support of the Centers for Medicare & Medicaid Services (CMS). In this role, you'll lead Risk Management Framework (RMF) activities, maintain the system's Authorization to Operate (ATO), oversee security controls and risk assessments, support continuous monitoring and incident response, and serve as a trusted advisor to CMS stakeholders on the program's overall security and privacy posture. The ideal candidate will have a bachelor's degree and at least seven years of relevant experience, with a strong background in the Risk Management Framework (RMF), Authorization to Operate (ATO) management, cybersecurity, and federal compliance. Experience leading security assessments, managing POA&Ms, and implementing federal security controls in an operational environment is essential. While Nava and CMS provide onboarding through the ISSO Handbook and ISSO Boot Camp, candidates should bring established experience managing RMF activities and supporting federal information security programs. Although no specific certification is required under the contract, credentials such as CISSP, CISM, or CompTIA Security+ are highly desirable. This is an opportunity to take on a highly visible leadership role supporting one of CMS's mission-critical systems. You'll work closely with engineering teams, program leadership, and federal stakeholders to strengthen the program's security posture while helping deliver secure, reliable digital services that support millions of Americans.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior