CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.
Roles/Responsibilities:
The Security Engineer will project work by leading security governance, compliance, and risk management activities, with a strong focus on System Security & Privacy Plans (SSP/SSPP). This role bridges technical security operations and regulatory compliance, ensuring audit readiness, effective vulnerability remediation, and secure delivery of public-facing services across complex, multi-platform environments.
- Lead end to end System Security & Privacy Plan (SSP/SSPP) development, maintenance, and updates for enterprise systems
- Drive remediation activities through POA&M management, ensuring timely closure of compliance gaps
- Translate penetration testing and vulnerability findings into actionable remediation work items (EPICs/user stories)
- Coordinate with application, infrastructure, and security teams to validate remediation through re-testing and evidence
- Oversee risk-based vulnerability management, including prioritization and SLA-driven remediation
- Provide governance oversight for endpoint protection, web application security, and cloud security controls
- Produce assessor ready documentation, including configurations, monitoring evidence, approvals, and incident traceability
- Support continuous audit readiness and reduce repeat findings through disciplined governance and documentation practices
Mandatory Skills:
- 12 Years of experience: deep focus on: Governance, Risk, and Compliance (GRC), Enterprise Security and Security Architecture, Vulnerability Management and Penetration Testing , Cloud Security and hybrid environments
- 10 Years of proven experience owning SSP development end to end
- 10 Years of hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks
- 10 Years- strong expertise in: Control implementation documentation, Audit evidence collection and validation, POA&M creation, tracking, and remediation management
- 8 years of experience on ability to translate technical security issues into compliance aligned remediation actions
- 8 years of experience in strong stakeholder management skills across security, infrastructure, and application teams
- 8 years of experience: Excellent written and verbal communication skills, particularly for executive stakeholders
- 8 years of experience: Knowledge of NIST 800 53, NIST RMF, and privacy controls
- 8 years of experience: Knowledge of Secure SDLC and DevSecOps practices
Desirable Skills:
- 5 years of experience operating in multi-vendor, multi-platform environments
- 5 years of experience: Demonstrated ability to reduce repeat audit findings and improve compliance maturity
- 5 years of experience on mentoring or guiding teams on security governance best practices
- 1years of experience on supporting HHSC systems, including SSP development and compliance