Cyber Remediation & POA&M Coordinator (R-00188)
True Zero Technologies
Apply to this job
True Zero is seeking a Cyber Remediation & POA&M Coordinator to support enterprise vulnerability remediation and Risk Management Framework (RMF) activities for the National Institutes of Health (NIH). This position serves as the operational link between vulnerability management, system owners, ISSOs, security engineering, and executive leadership to ensure cybersecurity findings are prioritized, tracked, and remediated in accordance with Federal requirements and organizational risk priorities.
The ideal candidate understands that effective vulnerability management extends beyond identifying weaknesses. Success in this role requires coordinating remediation efforts across multiple stakeholders, maintaining accurate Plans of Action and Milestones (POA&Ms), validating corrective actions, and providing leadership with timely visibility into remediation progress and residual risk.
Job Responsibilities
- Coordinate enterprise remediation activities for vulnerabilities identified through continuous monitoring, vulnerability scanning, penetration testing, audits, and security assessments.
- Develop, maintain, and manage POA&Ms in accordance with Federal, HHS, and NIH requirements.
- Partner with ISSOs, system owners, security engineers, and technical teams to establish remediation plans, milestones, and completion timelines.
- Monitor remediation progress, validate supporting evidence, and ensure corrective actions are accurately documented.
- Coordinate risk acceptance requests, compensating controls, waivers, and remediation exceptions through established governance processes.
- Track remediation performance against established service level objectives and communicate overdue or high priority items to program leadership.
- Support RMF authorization activities by ensuring vulnerabilities and POA&M items are accurately reflected within authorization documentation.
- Collaborate with vulnerability management and threat intelligence personnel to reprioritize remediation activities based on exploitability, Known Exploited Vulnerabilities (KEVs), operational impact, and emerging threats.
- Develop recurring remediation status reports, executive summaries, and operational metrics for Government leadership.
- Support internal and external cybersecurity assessments by coordinating remediation responses and tracking corrective actions through closure.
- Recommend process improvements that enhance remediation efficiency, reporting accuracy, and enterprise risk reduction.
Job Qualifications
- Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, or a related discipline.
- Three or more years of experience supporting vulnerability management, RMF, cybersecurity governance, or compliance programs.
- Experience developing and managing Plans of Action and Milestones (POA&Ms).
- Working knowledge of the NIST Risk Management Framework (RMF), FISMA, and NIST SP 800-53.
- Experience coordinating remediation activities across multiple technical teams and business stakeholders.
- Strong organizational skills with the ability to manage multiple concurrent remediation efforts.
- Excellent written and verbal communication skills, including experience preparing reports for technical and executive audiences.
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience with enterprise GRC platforms such as JCAM, eMASS, ServiceNow, Archer, or similar governance tools.
- Experience supporting vulnerability management programs and Continuous Diagnostics and Mitigation (CDM) initiatives.
- Familiarity with CISA Known Exploited Vulnerabilities (KEV) guidance, Binding Operational Directives, and Federal remediation requirements.
- Experience supporting audit remediation, authorization package development, and continuous monitoring programs.
- Certified in Governance, Risk and Compliance (CGRC)
- CISSP
- Security+
- CAP
- CISM
- Project Management Professional (PMP)
One or more of the following is preferred:
Summary
Coordinate vulnerability remediation, develop POA&Ms, support cybersecurity assessments, and ensure compliance.
Job title
Cyber Remediation & POA&M Coordinator
Experience level
3+ years
Minimum experience
3+ years exp
Industry
government and cybersecurity
Location requirements
100% remote, no on-site requirement
Salary
Not specified
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Unknown location