Enter a job title or keyword

IT Security Governance Officer

Commence


Job Location:

Virginia Beach, VA - USA

Monthly Salary: $ 120000 - 170000
Posted: 22 August 2026 (Yesterday)
Application Deadline: 19 November 2026
Vacancies: 1 Vacancy

Job Summary

At Commence were the start of a new age of data-centric transformation elevating health outcomes and powering better more efficient process to program and patient health. We combine quality data-driven solutions that fuel answers technology that advances performance and clinical expertise that builds trust to create a more efficient path to quality care.


With human-centered healthcare-relevant and value-based solutions we create new possibilities with data. We provide proof beyond the concept and performance beyond the scope with a focus on efficiencies that transform the lives of those we serve. With a culture driven by purpose straightforward communication and clinical domain expertise Commence cuts straight to better care.

Requirements

The IT Security Governance Officer is a Key Personnel position required under a CMS contract responsible for overseeing the programs compliance with CMS information security requirements. The IT Security Governance Officer serves as the primary point of accountability for the programs information security program ensuring that all federal and CMS-specific IT security policies are implemented documented and enforced across all contract operations.


Requirements

  • Learn document and implement Federal and CMS information security controls in compliance with CMS IS2P2 FISMA FedRAMP HIPAA and all applicable CMS security policies and procedures.
  • Disseminate and implement IT policy that aligns with CMS requirements; provide interpretation of current policies in response to inquiries or specific incidents.
  • Oversee the Security Assessment and Authorization (SA&A) process including development and maintenance of the System Security Plan (SSP) Plan of Action and Milestones (POA&M) and related ATO documentation.
  • Ensure all contractor personnel complete required CMS Information Security Awareness Privacy and Records Management training annually; maintain training records per CMS procedures.
  • Manage compliance with CMS encryption standards FIPS 140 requirements asset inventory configuration management vulnerability scanning and patch remediation timelines per CMS policy.
  • Serve as primary liaison to CMS on all information security and privacy matters; respond to security incidents within required timeframes and coordinate with the CMS Incident Response Team (IRT) as directed.
  • Oversee Data Use Agreement (DUA) processes and ensure compliance with CMS data access policies through the Enterprise Privacy Policy Engine (EPPE) system.
  • Maintain a complete and current inventory of all IT assets and ensure devices meet CMS and HHS-specific encryption and configuration standards.
  • Support CMS audits security assessments and annual performance reviews; allow government access to facilities systems and personnel as required.

Qualifications

  • Minimum 5 years of combined work experience with at least 3 of those years in the healthcare industry supporting either Federal Government agencies or commercial healthcare market in a role such as CIO Information Technology Manager Chief Technology Officer or Network Administrator.
  • Knowledge of the Medicare programs and familiarity with CMS information security requirements including FISMA FedRAMP HIPAA CMS IS2P2 and the CMS Business Partner System Security Manual (BPSSM).
  • Bachelors degree in Information Systems Computer Science or other related technology field required. Relevant work experience in a related field may be considered in lieu of a bachelors degree.

Preferred Qualifications

  • Prior IT security governance or CIO-equivalent leadership experience on a CMS contract with demonstrated knowledge of CMS Security Assessment and Authorization (SA&A) processes.
  • Relevant certification such as CISSP CISM CISA or equivalent information security credential.
  • Experience managing FedRAMP authorization packages and working with third-party assessment organizations (3PAOs) for moderate-impact federal systems.
  • Familiarity with CMS esMD RACDW IDR and other CMS-designated data systems used in Medicare medical review operations.

*Commence headquarters are in Virginia Beach VA however we are open to remote candidates in the following states: AZ AR CO DE FL GA IL IN KS KY MA MD MI MS MO MT NC NE NV NY OH OK PA SC TN TX VA DC WI and WV*


Work Environment/Physical Demands


The work environment and physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


This is a remote position. While performing the duties of this job the employee regularly works in a climate-controlled environment. Candidates must be able to sit read work on a computer and watch a computer screen for extended periods of time. Occasionally required to stand walk use hands and fingers kneel or crouch.


Commence is an equal employment opportunity for employer. All personnel processes are merit-based and applied without discrimination on the basis of race color religion sex sexual orientation gender identity marital status age disability national or ethnic origin military and veteran status or any other characteristic protected by applicable law.


is committed to providing equal employment opportunities to all applicants including individuals with disabilities. If you require reasonable accommodation to participate in the application process due to a disability please contact Human Resources at or . Please note that unless you are requesting an accommodation all applications must be submitted through our online application system.

Salary Description
$120000 - $170000

Required Experience:

Unclear Seniority


About Company

Company Logo

Commence delivers data transformation and clinical expertise that improve care access, reduce burn, and modernize healthcare systems.

View Profile View Profile