Overview
Skills
Job Details
Requirement:
System Security & Privacy Plan (SSPP) Developer
Remote
12+ Months
Work Description
System Security & Privacy Plan (SSPP) Developer
Objective: Author And Maintain Security Documentation in Alignment with Federal Regulatory Frameworks to Ensure Compliance and Support Audit Readiness.
Roles & Responsibilities:
- Develop, write, and maintain System Security & Privacy Plans (SSPPs), Privacy Impact Assessments (PIAs), SSPP attachments and supporting A&A documentation.
- Ensure Alignment with NIST SP 800-37, 800-53, 800-171, 800-172, FedRAMP, and FISMA Standards.
- Collaborate with CWT Risk, GRC, and Government SMES to Extract System-Specific and Control-Related Information.
- Translate Technical Configurations and Architectural Diagrams into Narrative Form for Policy Documents.
- Lead Gap Assessments and Compliance Validation Exercises; Document and Recommend Mitigation Plans.
- Track Revisions and Maintain Version Control for All Security Artifacts.
- Support CWT in the preparation and submission of A&A Packages to applicable federal bodies.
Specifications
All work will align with industry-standard cybersecurity frameworks, particularly:
NIST SP 800-37, SP 800-53, SP 800-171, SP 800-172
FedRAMP, FISMA, And Applicable U.S. Federal Security Requirements
All documentation must be professionally written, compliance-aligned, and audit-ready.
Deliverables must meet accessibility and formatting requirements as per CWT s Internal Policy (E.G., Editable Source Formats, PDF exports, Change Log/Versioning).
All resources must comply with CWT s Confidentiality, Non-disclosure, and access control protocols while interfacing with its systems.
Documentation
The following documentation will be created, maintained, and version-controlled throughout the engagement:
System Security & Privacy Plans (SSPPS) Detailed Plans for Each In-Scope System in Accordance with NIST And FedRAMP. Update the System Security & Privacy Plans (SSPPs) and all associated attachments. Privacy Impact Assessments (PIAS) Completed PIAS tied to SSPPS as per applicable compliance standards.
Deliverables / Work Product
Complete System Security & Privacy Plans (SSPS) And Corresponding Privacy Impact Assessments (PIAS). Updated System Security & Privacy Plans (SSPPs) and all associated attachments.