HimalayasHimalayas logo
BelleseBE

Information Systems Security Officer I (ISSO-1)

Bellese Technologies is a digital service company that designs and builds human-centered technology solutions to improve the U.S. healthcare system for government and commercial clients.

Bellese

Employee count: 51-200

Salary: 112k-134k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Bellese is a mission-driven Digital Services Company committed to pioneering innovative technology solutions in civic healthcare. Our dedication lies in making a meaningful impact on public health outcomes.
Driven by service design, we strive to know the “Why” to understand the healthcare journey for patients, caregivers, providers, payers, and policymakers. Our goal is to design and build solutions that reduce confusion, provide clarity, support decision making, and streamline the process so that we and our partners can focus on providing better health outcomes by improving patient care and reducing costs and burden.

The Team you will be joining:

You will be the ISSO for two Teams, QMARS & HQR

QMARS

Our team is charged with maintaining and improving the software at the Centers for Medicare and Medicaid Services (CMS) that supports the Quality Management and Review Systems (QMARS) program. QMARS online case management system supports the CMS Beneficiary and Family-Centered Care (BFCC) Quality Improvement Organization (QIO) program. The QIO program is one of the largest federal programs dedicated to improving healthcare quality for Medicare beneficiaries across the country. Our teams will continuously strive to modernize these systems while improving them in ways that reduce provider burden and minimize costs to CMS. We do this through HCD and Service design practices, product thinking, and skilled engineering. At Bellese, we’re relentlessly focused on enabling and empowering providers to focus on improving the quality and safety of patient care.

HQR

Our team is charged with maintaining and improving the software at the Centers for Medicare and Medicaid Services (CMS) that supports the Hospital Quality Reporting program. Thousands of hospitals across the country depend on these systems to submit quality measure data that reflects the care beneficiaries receive in their facility. Our teams will continuously strive to modernize these systems, while improving them in ways that reduce provider burden and minimize costs to CMS. We do this through HCD and Service design practices, product thinking, and skilled engineering. At Bellese, we’re relentlessly focused on enabling and empowering providers to focus on improving the quality and safety of patient care.

The Information Systems Security Officer (ISSO) is responsible for implementing a value-based approach to security, versus the traditional focus on audits and compliance. The ISSO will work with infrastructure and feature development teams to introduce security early and throughout development processes, taking a proactive and active security analysis approach to identify potential risks and threats, and creating tests and countermeasures in procedures, code, and infrastructure to respond to potential threats.

Security Clearance Requirements

  • US Citizenship or documented proof of eligibility to work in the US without Sponsorship
  • US Residency for at least the past 3 years
  • Able to meet the requirements to hold a position of Public Trust, including successful completion of a US Government background investigation
  • Disclaimer: Medical or recreational marijuana use is considered illegal at the federal level, regardless of state laws allowing such, and may affect your ability to obtain Public Trust. See article

Work that matters, with perks that deliver. Discover how Bellese Technologies invests in you through a benefits suite that makes every day better

  • Remote First, Remote Only Culture
  • Four weeks paid time off yearly (prorated based on start date for the first year)
  • 10 paid floatingcompany holidays
  • Flexible schedule
  • Work from home setup including a Macbook
  • Collaborative, learning environment
  • Medical, dental, and company-paid vision insurance
  • Optional HSA account with some medical plans and a company contribution
  • Company paid basic life and AD&D insurance coverages
  • Company paid short and long term life insurance
  • Optional critical illness and accident insurance
  • 401K plan with 3% safe harbor contribution
  • Wellness resources and virtual care
  • Perks Plus employee discounts

You will like it here if

  • You foster a collaborative ethos, driven by the mission to deliver exceptional customer service to clients. You are passionate about Healthcare and changing the healthcare landscape. You’re an out of the box thinker, always striving to know the “why” when it comes to building solutions. You excel in a team-oriented, remote-first environment characterized by mutual respect and open communication. Your adaptability and ability to navigate challenges ensure your success in any situation.

What you will be doing:

  • (1) SIA Maintenance (Primary Focus): You will proactively identify system changes in HQR and QMARS and document them in a Security Impact Analysis (SIA) to ensure the ATO remains valid.
  • CFACTS Governance: You will serve as the "Source of Truth" for the system's security posture in CFACTS, managing control implementation statements and evidence.
  • Audit Defense & Evidence Gathering: You will lead the "Audit Season" efforts, gathering screenshots, logs, and process documentation to prove to CMS auditors that controls are "Effective."
  • Risk Advising: You will attend sprint ceremonies for HQR (50%) and QMARS (50%) to advise developers on CMS security standards before they build, preventing "security rework" later.
  • POA&M Life-cycle: You will track security weaknesses from discovery to remediation, ensuring the program meets CMS's strict 30/60/90-day patching windows.
  • Policy Stewardship: You will ensure all program documentation (Contingency Plans, Incident Response Plans) is reviewed and signed off annually per FISMA requirements.

Technical Qualifications

  • At least 4 years of experience establishing security controls as outlined in the responsibilities section above.
  • Experience working with two or more from the following: web application development, unix/linux environments, distributed systems, machine learning, developing large scale systems and API services, security software development
  • Experience with one or more infrastructure scripting languages: Terraform, CloudFormation, Ansible, Chef or Puppet, Kubernetes
  • Experience implementing two or more cloud-based solutions: global infrastructure, virtual clouds, virtual computing, serverless computing, load balancing and networking, data storage and data streaming, hadoop, map reduce, secured REST-based API endpoints, security
  • Direct, hands-on experience with CFACTS. (This experience is only available if you hve worked with CMS (Centers for medicare & medicaid)
  • Proven ability to author Security Impact Analyses (SIA), System Security Plans (SSP), and Privacy Impact Assessments (PIA) specifically under NIST 800-53 Rev 5 and CMS ARS 5.0.
  • A&A Lifecycle: Experience taking a system through the Assessment & Authorization (A&A) process to achieve or maintain an ATO (Authority to Operate).
  • Vulnerability Management: Ability to interpret Tenable/Nessus or WebInspect scans to translate technical vulnerabilities into POA&Ms (Plan of Action and Milestones) that developers can understand.
  • Cloud-Native Compliance: Understanding of how to document security controls for AWS-native services
The Salary range for ISSO-1 is 111,800-$134,200
U.S. citizen or legal right to work in the United States without sponsorship

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 112k-134k USD

Experience

4 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About Bellese

Learn more about Bellese and their company culture.

View company profile

Bellese Technologies is a user-driven service design and civic technology company with a profound focus on enhancing the healthcare journey for all stakeholders. Founded in 2009, the company partners with government agencies, particularly in the health and human services sectors, to modernize legacy systems and create impactful digital services. Bellese is committed to a human-centered design approach, moving away from traditional policy-driven design to ensure that the end-users—patients, caregivers, providers, and policymakers—are at the forefront of every solution. This philosophy is driven by the recognition of systemic challenges in the U.S. healthcare system, such as rising costs and the need for greater price transparency and access to health outcome data. The company's core mission is to reduce confusion, provide clarity, and support informed decision-making through the digital products it builds. By doing so, Bellese aims to streamline processes, allowing the focus to remain on patient care, improving health outcomes, and reducing administrative burdens and costs.

The expertise of Bellese Technologies lies not only in designing innovative solutions from the ground up but also in the intricate process of transforming existing, complex systems with modern technology. This requires meticulous planning, robust user research, and a service design methodology that allows for incremental, non-disruptive changes to operational systems. Success in this domain involves interpreting policy and implementing services that meet legislative requirements while simultaneously addressing the real-world needs of users. Bellese fosters a culture of collaboration, experimentation, and continuous feedback, working closely with all stakeholder groups to ensure alignment and drive service improvement. This approach has enabled the company to successfully modernize multiple enterprise healthcare information systems, demonstrating a proven ability to navigate the complexities of civic technology and deliver solutions that contribute to a more efficient, transparent, and patient-centric healthcare ecosystem. Their work is guided by the principle that technology, when thoughtfully applied, can significantly improve the engagement of citizens with the government agencies that serve them.

Employee benefits

Learn about the employee benefits and perks provided at Bellese.

View benefits

Home office budget

Work from home setup including a Macbook.

Disability Insurance

Company-paid short-term and long-term disability coverage.

Flexible Hours

Work-life balance is essential. We offer flexible hours to accommodate.

Retirement benefits

Invest in your future with a 401K plan and a safe harbor contribution from Bellese.

View Bellese's employee benefits
Claim this profileBellese logoBE

Bellese

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

17 remote jobs at Bellese

Explore the variety of open remote roles at Bellese, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Bellese

Remote companies like Bellese

Find your next opportunity by exploring profiles of companies that are similar to Bellese. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan