IT Security Governance Officer

Commence

Virginia Beach, VA, United States$120,000 - $170,000ContractPosted 1mo ago

Get more Administrative Assistant openings

A short daily email when similar roles appear in Virginia Beach. No account needed.

At Commence, we’re the start of a new age of data-centric transformation, elevating health outcomes and powering better, more efficient process to program and patient health. We combine quality data-driven solutions that fuel answers, technology that advances performance, and clinical expertise that builds trust to create a more efficient path to quality care.


With human-centered, healthcare-relevant, and value-based solutions, we create new possibilities with data. We provide proof beyond the concept and performance beyond the scope with a focus on efficiencies that transform the lives of those we serve. With a culture driven by purpose, straightforward communication and clinical domain expertise, Commence cuts straight to better care.

Requirements

The IT Security Governance Officer is a Key Personnel position required under a CMS contract, responsible for overseeing the program's compliance with CMS information security requirements. The IT Security Governance Officer serves as the primary point of accountability for the program's information security program, ensuring that all federal and CMS-specific IT security policies are implemented, documented, and enforced across all contract operations.


Requirements

  • Learn, document, and implement Federal and CMS information security controls in compliance with CMS IS2P2, FISMA, FedRAMP, HIPAA, and all applicable CMS security policies and procedures.
  • Disseminate and implement IT policy that aligns with CMS requirements; provide interpretation of current policies in response to inquiries or specific incidents.
  • Oversee the Security Assessment and Authorization (SA&A) process, including development and maintenance of the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and related ATO documentation.
  • Ensure all contractor personnel complete required CMS Information Security Awareness, Privacy, and Records Management training annually; maintain training records per CMS procedures.
  • Manage compliance with CMS encryption standards, FIPS 140 requirements, asset inventory, configuration management, vulnerability scanning, and patch remediation timelines per CMS policy.
  • Serve as primary liaison to CMS on all information security and privacy matters; respond to security incidents within required timeframes and coordinate with the CMS Incident Response Team (IRT) as directed.
  • Oversee Data Use Agreement (DUA) processes and ensure compliance with CMS data access policies through the Enterprise Privacy Policy Engine (EPPE) system.
  • Maintain a complete and current inventory of all IT assets and ensure devices meet CMS and HHS-specific encryption and configuration standards.
  • Support CMS audits, security assessments, and annual performance reviews; allow government access to facilities, systems, and personnel as required.

Qualifications

  • Minimum 5 years of combined work experience, with at least 3 of those years in the healthcare industry supporting either Federal Government agencies or commercial healthcare market in a role such as CIO, Information Technology Manager, Chief Technology Officer, or Network Administrator.
  • Knowledge of the Medicare Fee-for-Service (FFS) program and familiarity with CMS information security requirements, including FISMA, FedRAMP, HIPAA, CMS IS2P2, and the CMS Business Partner System Security Manual (BPSSM).
  • Bachelor's degree in Information Systems, Computer Science, or other related technology field required. Relevant work experience in a related field may be considered in lieu of a bachelor's degree.

Preferred Qualifications

  • Prior IT security governance or CIO-equivalent leadership experience on a CMS contract with demonstrated knowledge of CMS Security Assessment and Authorization (SA&A) processes.
  • Relevant certification such as CISSP, CISM, CISA, or equivalent information security credential.
  • Experience managing FedRAMP authorization packages and working with third-party assessment organizations (3PAOs) for moderate-impact federal systems.
  • Familiarity with CMS esMD, RACDW, IDR, and other CMS-designated data systems used in Medicare medical review operations.

*Commence' headquarters are in Virginia Beach, VA, however we are open to remote candidates in the following states: AZ, AR, CO, DE, FL, GA, IL, IN, KS, KY, MA, MD, MI, MS, MO, MT, NC, NE, NV, NY, OH, OK, PA, SC, TN, TX, VA, DC, WI, and WV*


Work Environment/Physical Demands


The work environment and physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


This is a remote position. While performing the duties of this job, the employee regularly works in a climate-controlled environment. Candidates must be able to sit, read, work on a computer, and watch a computer screen for extended periods of time. Occasionally required to stand, walk, use hands and fingers, kneel or crouch.


Commence is an equal employment opportunity for employer. All personnel processes are merit-based and applied without discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, marital status, age, disability, national or ethnic origin, military and veteran status or any other characteristic protected by applicable law.


Commence.AI is committed to providing equal employment opportunities to all applicants, including individuals with disabilities. If you require reasonable accommodation to participate in the application process due to a disability, please contact Human Resources at (757) 306-4920 or hr@commence.ai. Please note that unless you are requesting an accommodation, all applications must be submitted through our online application system.

The average job posting receives 250 applications.

Stand out by tailoring your resume to this specific role. Our AI resume builder highlights the skills and experience that matter most to this employer.

Frequently asked questions

Who is hiring for IT Security Governance Officer at Commence?+
Commence is actively hiring for this IT Security Governance Officer role. Click "Apply Now" to submit your application directly on Commence's careers page β€” Careeronaut doesn't charge employers or candidates for referrals.
When was this IT Security Governance Officer role posted?+
This listing was first posted on 2026-07-06. We pull the latest copy from the source feed daily, and any role that's taken down gets removed from Careeronaut within seven days so you don't waste time on stale listings.
How should I apply to this IT Security Governance Officer role?+
Start by tailoring your resume to the posting β€” most applicants send generic CVs and the first filter recruiters use is keyword relevance. Careeronaut's AI does this automatically: paste the job description, get a matched resume in under a minute, and download as PDF or DOCX.
Where can I find more Administrative Assistant jobs in Virginia Beach?+
Browse all open administrative assistant roles in Virginia Beach on the listing pages linked below. You can filter by salary, remote-friendly, and posting date.