
Sr. Federal Security Governance Analyst
Maximus · United States
- Hybrid
- Full-time
- $122,000 / year
- United States
Tailored resume — keyword-matched to this role.
Hiring manager — we find who's hiring.
Intro email — drafted to reach them directly.
Job highlights
- Analyze security risks for federal and DoD clients.
- Establish and advise on security requirements.
- Ensure alignment with NIST, RMF, FedRAMP.
- Collaborate with ISSOs and business teams.
- Translate federal security needs into solutions.
About the role
Senior Federal Security Governance Analyst
Maximus is seeking a seasoned Security Governance/Risk professional to support and strengthen enterprise security governance for Federal and DoD customers. This role is responsible for performing complex risk analyses, establishing and advising on Information Assurance and security requirements, and ensuring alignment with Federal frameworks such as NIST, RMF, FedRAMP, and DoD requirements. The successful candidate will collaborate closely with enterprise and project ISSOs, customers, and business teams, translating Federal security requirements into practical, business-aligned solutions. Demonstrated experience supporting Federal government and DoD environments is essential for success in this role.
Essential Duties and Responsibilities:
- Perform complex risk analyses and risk assessment.
- Establish and satisfy Information Assurance (IA) and security requirements based upon the analysis of user, policy, regulatory, and resource demands.
- Support customers in the development and implementation of doctrine and policies.
- Advise information system owners on client/project security policies and requirements for systems.
- Keep abreast of emerging security technologies and make appropriate recommendations regarding the enhancement of the security posture of systems and their implementation.
- Collaborate with the Enterprise (Shared Services) ISSO to ensure proper alignment of organizational governance with Federal and DoD customers.
- Collaborate with project ISSO’s (existing contracts) and Business Development and Capture Teams to ensure proper alignment of organizational governance with existing and prospective Federal and DoD customers.
- Assist the Enterprise (Shared Services) ISSO with application of security policies to shared services supporting Federal and DoD customers.
- Recommend enhancements that align governance with Federal and DoD customers.
- Support the enhancement and on-going management of governance activities from a Federal perspective, including vendor assessments, annual enterprise risk assessments, enterprise risk registers, security awareness and training, and maintenance of a GRC.
Minimum Requirements:
- Bachelor's Degree in related field.
- 5-7 years of relevant professional experience required.
- Equivalent combination of education and experience considered in lieu of degree.
Additional Minimum Requirements:
- 7+ years of security governance development and management for a corporate organization supporting Federal and DoD customers.
- Experience supporting security governance for organizations using FedRAMP CSO’s as it pertains to system-specific and hybrid controls.
- RMF and A&A experience desired.
- Demonstrated experience in cybersecurity governance programs in highly regulated federal environments, including implementation and oversight of NIST-based security controls.
- Strong understanding of Federal requirements to include but not limited to applicable Executive Orders, FISMA, FIPS, CMMC, NIST 800-171, NIST 800-53, NIST 800-60, and NIST 800-65.
- Experience with Federal and DoD GRC tools (e.g., CFACTS, CSAM, eMASS).
- Experience mapping and cross-walking policies, standards, and procedures to multiple security frameworks.
- Exercise judgment in selecting methods, techniques, and evaluation criteria for obtaining results.
- Network with key contacts outside own area of expertise.
- Develop solutions to a variety of complex problems.
- Work requires considerable judgment and initiative.
- Ability to communicate Federal language (NIST verbiage) in understandable business terms.
- Excellent interpersonal skills, presentation skills, and oral / written communication skills.
- Strong customer service abilities required.
- Ability to work collaboratively with a broad range of staff.
- Skilled in Microsoft Office software including Word, Excel, and PowerPoint; Smartsheet; and Lucid.
- Ability to perform comfortably in a fast-paced, deadline-oriented work environment.
- Ability to execute many complex tasks simultaneously and work as a team member as well as independently.
Preferred Qualifications:
- Bachelor’s degree in cybersecurity, computer science, information assurance, or related field.
- Certifications like CISSP, CISM, CISA, or GRC / audit or risk certifications desired.
Key skills/competency:
- Security Governance
- Risk Analysis
- Information Assurance
- Federal Frameworks
- NIST
- RMF
- FedRAMP
- DoD Requirements
- Cybersecurity Governance
- GRC Tools
Skills & topics
- Security Governance
- Risk Analysis
- Information Assurance
- Federal Security
- DoD Security
- NIST
- RMF
- FedRAMP
- Cybersecurity
- GRC
How to get hired
- Tailor your resume: Highlight your 7+ years of federal and DoD security governance experience, NIST, RMF, and FedRAMP expertise.
- Craft a compelling cover letter: Emphasize your ability to translate complex federal security requirements into practical business solutions.
- Prepare for interviews: Be ready to discuss your experience with federal frameworks, risk analysis, and GRC tools.
- Showcase your communication skills: Demonstrate your ability to articulate technical concepts in business terms.
Technical preparation
Master NIST RMF and FedRAMP documentation.,Familiarize with GRC tools like CFACTS, CSAM.,Understand DoD and federal cybersecurity mandates.,Practice risk assessment methodologies.
Behavioral questions
Describe a complex risk analysis you performed.,How do you translate technical security terms?,Give an example of policy development support.,How do you handle competing priorities?
Frequently asked questions
- What specific federal security frameworks are most important for the Senior Federal Security Governance Analyst role at Maximus?
- For the Senior Federal Security Governance Analyst position at Maximus, a strong understanding and experience with NIST, RMF, FedRAMP, FISMA, FIPS, CMMC, NIST 800-171, NIST 800-53, NIST 800-60, and NIST 800-65 are crucial. Experience with DoD requirements is also essential.
- What type of security clearance is typically required for this role at Maximus?
- The job requisition mentions clearance eligibility is required, but specific details are not provided in the general description. Candidates should refer to the additional information section of the job requisition for this opening to determine the exact clearance eligibility needed for the Senior Federal Security Governance Analyst role.
- Does Maximus offer opportunities for professional development for a Senior Federal Security Governance Analyst?
- While not explicitly stated for this role, Maximus typically values continuous learning and professional growth. Preferred qualifications include certifications like CISSP, CISM, CISA, or GRC/audit/risk certifications, suggesting an environment that supports and encourages such development.
- What are the key GRC tools used by Maximus for federal and DoD clients in this Senior Federal Security Governance Analyst position?
- The role requires experience with Federal and DoD GRC tools. Specific examples mentioned include CFACTS, CSAM, and eMASS, indicating these are likely the primary platforms used for governance, risk, and compliance activities.
- How does Maximus ensure alignment of organizational governance with Federal and DoD customers for this role?
- The Senior Federal Security Governance Analyst collaborates closely with both the Enterprise (Shared Services) ISSO and project ISSOs to ensure proper alignment. This includes working with Business Development and Capture Teams to align governance with existing and prospective customers, and applying security policies to shared services.
- What is the expected educational background for a Senior Federal Security Governance Analyst at Maximus?
- A Bachelor's Degree in a related field (such as cybersecurity, computer science, or information assurance) is generally required. However, an equivalent combination of education and relevant professional experience may be considered in lieu of a degree.