Solicitation
Governance, Risk and Compliance Consultant
GCTOF-24-03
Department of the Air Force, FA2218 Afimsc A37R. Other Computer Related Services.
Response deadline
June 28, 2024 at 1:00 PM EDT
Closed 811 days ago. Posted May 28, 2024, first published April 30, 2024. Scheduled to archive June 28, 2024.
Description
As published on SAM.gov.
The contractor acts as a Governance, Risk, and Compliance (GRC) Consultant for AFIMSC under a non-personal service contract. The contractor's responsibilities include:
1. Ensuring the Chaplain Corps Accounting Section (CCAC) achieves and maintains an Authorization to Operate (ATO) for its current and future cloud-based accounting systems. This involves consistent progress in attaining ATO and avoiding lapses.
2. Conducting detailed assessments of the organization's GRC posture, focusing on cybersecurity controls, policies, and procedures in compliance with various DoD, Air Force, and local policies.
3. Evaluating and ensuring compliance with designated accounting software and network requirements, identifying weaknesses, and coordinating migrations to cloud-based services with appropriate security measures like FEDRAMP.
4. Developing and recommending strategies to address compliance gaps, vulnerabilities, and risks in alignment with DoD and Air Force standards, and providing action plans to address identified issues.
5. Offering guidance and expertise on interpreting and applying relevant standards and frameworks, ensuring alignment with organizational objectives, and providing advice on governance practices for improved performance.
6. Collaborating with cross-functional teams to design, implement, and maintain effective risk management processes and controls, ensuring seamless integration into daily operations and alignment with the organization’s strategic goals.
7. Assisting in the documentation and maintenance of security controls, policies, and procedures, updating these as necessary to reflect changes in regulations or emerging threats, and maintaining records for audit purposes.
8. Regularly conducting reviews and audits to assess compliance with established frameworks, identify areas for improvement, and monitor the effectiveness of risk management controls.
9. Providing training and knowledge transfer sessions on GRC principles, compliance requirements, and risk management best practices to internal stakeholders.
10. Maintaining relevant certifications and proficiency with tools like eMASS and ITIPS, demonstrating experience with the Risk Management Framework and NIST publications related to security and privacy controls, and guidance on applying these frameworks to federal information systems.
Publications
Every notice SAM.gov issued under this solicitation number, oldest first. Each is a separate record on SAM.
April 30, 2024
Solicitation
Due June 28, 2024 at 1:00 PM EDT. SAM.gov, notice 514222472cf5411283af091da0feb7f2
May 8, 2024
Solicitation
Due June 28, 2024 at 1:00 PM EDT. SAM.gov, notice 2092445a1a3d48f2a22c67921e3fa7d1
May 8, 2024
Solicitation
Due June 28, 2024 at 1:00 PM EDT. SAM.gov, notice d865d942dd9146298651942da06afa2f
May 28, 2024
Solicitation
Due June 28, 2024 at 1:00 PM EDT. SAM.gov, notice 9499f1c7f3e249a180d215178bb4a8c8
Points of contact
- Ana Mendez-GarnerAFIMSC.HC.ResourceManagement@us.af.mil2109698190
- Portmann WernerAFIMSC.HC.ResourceManagement@us.af.mil2109695776