Data Automation Engineer
3 days ago
Baltimore
Job Description Data Automation Engineer Location: Baltimore, MD (Hybrid) Work Type: Hybrid - 3 days onsite Clearance: Public Trust (MBI) or ability to obtain Job Description We are seeking a Data Automation Engineer to support the CMS Governance, Risk, Authorization, and Compliance for the Enterprise (GRACE) program. This role sits at the intersection of cybersecurity governance and data engineering, responsible for designing, building, and maintaining the automated data pipelines, integration layers, and visualization capabilities that power CMS’s real-time risk and compliance posture. The ideal candidate will build and optimize ETL workflows that ingest security data from sources including Wiz, CDM feeds, vulnerability scanners, and GRC platforms such as CFACTS (Archer IRM) and route that data into Snowflake’s Security Data Lake (SDL) architecture for analysis and reporting. This person will develop translation middleware and API integrations to convert compliance artifacts into NIST OSCAL formats, enabling machine-readable, standardized data exchange across the enterprise. They will design and maintain Tableau dashboards that give CMS leadership, system owners, and risk managers near real-time visibility into security metrics, vulnerability status, ongoing authorization health, and compliance posture. This role requires someone who understands that the data they are moving and presenting drives risk decisions for systems protecting the health data of over 100 million Americans—and who can translate between the language of data engineering and the language of cybersecurity governance. Responsibilities Data Pipeline Development and Integration • Design, build, and maintain automated ETL/ELT pipelines that ingest security and compliance data from multiple sources including Wiz, CDM, CFACTS (Archer IRM), vulnerability scanners, and endpoint detection tools into Snowflake’s Security Data Lake (SDL)., • Develop and maintain translation middleware and API gateways that extract SSP, SAR, and POA&M data from CFACTS, convert it into NIST OSCAL format (JSON, XML, or YAML), and map it to SDL schema requirements., • Integrate CFACTS with SDL’s Snowflake architecture to facilitate automated ingestion, curation, and analysis of OSCAL-based artifacts, enabling structured payloads to flow into SDL reporting pipelines., • Build and maintain API interoperability layers between GRC tools, security platforms, and CMS data repositories to support real-time data exchange and automated assessment workflows., • Support integration with new or transitioning GRC tools (e.g., Xacta or other CMS-approved platforms) ensuring continuity of data flows and minimal disruption to operations., • Design and develop Tableau dashboards integrated with SDL and CFACTS that provide near real-time visibility into security metrics, vulnerability status, ongoing authorization (OA) health, and enterprise compliance posture., • Build dynamic risk scoring visualizations that incorporate EPSS, KEV, and threat intelligence data to present prioritized vulnerability views for risk managers and system owners., • Develop role-based reporting views that serve different stakeholder needs—from executive risk summaries to detailed technical drill-downs for engineers and ISSOs., • Create and maintain OA and compliance monitoring dashboards supporting daily refresh cycles with 99% or greater adherence targets., • Automate the generation of RMF artifacts using OSCAL workflows, reducing manual effort in producing and maintaining compliance documentation such as SSPs, contingency plans, and incident response plans., • Build and maintain OSCAL validation tooling that programmatically checks compliance artifacts against NIST OSCAL schemas, flags formatting or content errors, and ensures artifacts remain current as controls are updated or inherited across systems., • Develop reusable OSCAL component definitions and control baselines that enable systems to inherit security controls from shared services, reducing duplication in artifact development and supporting CMS’s modular control framework approach., • Implement automated compliance and risk monitoring tools that identify compliance gaps, track remediation efforts, verify implementation, and generate reports for stakeholders at all levels., • Support dynamic risk scoring framework deployment by building the data infrastructure that feeds quantitative and semi-quantitative risk models used in CMS’s risk acceptance and prioritization processes., • Develop automated alert mechanisms for critical compliance and security issues based on threshold triggers within the SDL environment., • Work alongside GRC analysts, ISSOs, risk managers, and system owners to translate compliance and risk management requirements into technical data solutions., • Contribute to the continuous improvement program by identifying opportunities to enhance data pipeline reliability, reduce latency in reporting, and expand automation coverage., • Support the lessons learned repository and Jira-based tracking of process improvements with version-controlled documentation of data architecture changes., • Assist in evaluating emerging GRC technologies and data analytics methodologies, piloting promising innovations, and scaling successful approaches across the enterprise. Required Qualifications • Bachelor’s degree in Computer Science, Data Engineering, Information Systems, Cybersecurity, or a related field (or equivalent professional experience)., • 5+ years of experience in data engineering, data integration, or automation engineering roles., • Demonstrated experience building and maintaining ETL/ELT pipelines using Snowflake, AWS, or similar cloud data platforms., • Proficiency with SQL and at least one scripting/programming language (Python, JavaScript, or similar) for data transformation and API development., • Hands-on experience designing and developing dashboards and data visualizations in Tableau or equivalent enterprise BI tools., • Experience working with APIs, middleware, and data integration patterns (REST, JSON, XML, YAML)., • Familiarity with structured compliance data formats and the ability to develop automated workflows that generate, transform, and validate standardized security documentation (experience with NIST OSCAL is preferred but not required)., • Working knowledge of cybersecurity governance, risk, and compliance (GRC) concepts including the Risk Management Framework (RMF), Authority to Operate (ATO), and ongoing authorization (OA) processes., • Familiarity with NIST standards (SP 800-53, SP 800-37) and federal compliance requirements (FISMA, HIPAA, FedRAMP)., • Understanding of GRC tool ecosystems such as Archer/CFACTS, Xacta, or similar platforms and how compliance data flows between them., • Experience with vulnerability management data sources and risk scoring frameworks (CVE, EPSS, KEV, CVSS)., • Ability to obtain and maintain a Public Trust (MBI) clearance., • U.S. citizenship or permanent residency required. Desired Qualifications • Direct experience supporting CMS, HHS, or other federal health agency IT security programs., • Experience with NIST OSCAL (Open Security Controls Assessment Language) including developing tooling or pipelines that programmatically generate, validate, or transform OSCAL-formatted SSPs, SARs, POA&Ms, and component definitions., • Experience with Wiz, CrowdStrike, Tenable, or other cloud security and vulnerability management platforms., • Familiarity with CDM (Continuous Diagnostics and Mitigation) program data feeds and HWAM reporting., • Hands-on experience with Snowflake (SDL architecture, schema design, data pipelines, Snowpipe, Streams/Tasks)., • Experience building automated OSCAL compliance pipelines that convert legacy or GRC-tool-native artifacts into machine-readable OSCAL formats and feed them into data lake or reporting architectures., • Knowledge of FedRAMP authorization processes and SaaS governance frameworks., • Relevant certifications such as Snowflake SnowPro, AWS Certified Data Engineer, Tableau Desktop Specialist, CompTIA Security+, CISSP, CISA, or CGRC., • Experience with Jira, Confluence, or similar tools for Agile project tracking and documentation. Compensation and Benefits Salary Range: $120,000 - $170,000 (Compensation is determined by various factors, including but not limited to location, work experience, skills, education, certifications, seniority, and business needs. This range may be modified in the future.) Benefits: Gridiron offers a comprehensive benefits package including medical, dental, vision insurance, HSA, FSA, 401(k), disability & ADD insurance, life and pet insurance to eligible employees. Full-time and part-time employees working at least 30 hours per week on a regular basis are eligible to participate in Gridiron’s benefits programs. Gridiron IT Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status or disability status. Gridiron IT is a Women Owned Small Business (WOSB) headquartered in the Washington, D.C. area that supports our clients' missions throughout the United States. Gridiron IT specializes in providing comprehensive IT services tailored to meet the needs of federal agencies. Our capabilities include IT Infrastructure & Cloud Services, Cyber Security, Software Integration & Development, Data Solution & AI, and Enterprise Applications. These capabilities are backed by Gridiron IT's experienced workforce and our commitment to ensuring we meet and exceed our clients' expectations. Company DescriptionGRIDIRON IT is a Small Business specializing in IT talent search and placement. From executive search to cleared IT professionals, Gridiron IT provides top talent to government agencies, federal contractors, and commercial clients. Building on more than 20 years of recruiting excellence and solid relationships throughout the field, Gridiron IT is a trusted IT staffing resource in the National Capital Area and across the country. We work closely with our clients and consultants to understand their unique needs and make placements that make sense.GRIDIRON IT is a Small Business specializing in IT talent search and placement. From executive search to cleared IT professionals, Gridiron IT provides top talent to government agencies, federal contractors, and commercial clients. Building on more than 20 years of recruiting excellence and solid relationships throughout the field, Gridiron IT is a trusted IT staffing resource in the National Capital Area and across the country. We work closely with our clients and consultants to understand their unique needs and make placements that make sense.