Leads the identification, communication, and distribution of cybersecurity risks and actionable mitigations/remediations at the tactical and strategic levels across the Agency IT environment, working closely with the VAT, SOC, CTI, SCAs, ISSMs, ISSOs, and system owners.
- reviews change requests, prioritizes vulnerability remediation, and identifies common security-gap patterns using frameworks such as MITRE ATT&CK.
- develops Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos (CRRMs) and supports Component Cyber Acquisition Risk Management (C-CARM) through the Acquisition Lifecycle Framework.
- Identify tactical risks by working with operational teams (VAT, SOC, CTI) to build a full picture of tactical cyber risk; review and recommend approval/denial of tactical change requests.
- Support prioritization of vulnerability remediation and identification of common security-gap patterns using frameworks such as MITRE ATT&CK.
- Identify strategic risks by working with SCAs, ISSMs, ISSOs, and system owners; support Component Cyber Acquisition Risk Management (C-CARM) through templates/guidance tied to Acquisition Decision Events.
- Develop and review Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos (CRRMs).
- Conduct Risk Assessments gathering data on incidents, vulnerabilities, POA&Ms, KEVs, loss-magnitude metrics, threat actors, and TTPs.
- Support development of an organizational risk tolerance level and information system risk profiles aligned to the NIST Cybersecurity Framework.
- Maintain a near-real-time holistic risk management dashboard and CSD risk register for senior management visibility.
- Provide briefings to senior management on the Agency's cyber risk posture; support Cybersecurity Supply Chain Risk Management (C-SCRM) documentation.
Minimum Qualifications- Bachelor's Degree in Information Assurance, Computer Science, or related field.
- Minimum 7 years of professional experience in information assurance, cybersecurity, risk management, or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, 5 years of such experience
- One of the following: CompTIA Security+; ISC2 CISSP; ISACA CISM; ISACA CRISC; GIAC GCED; CompTIA CEH
- Candidates must be US citizens (no dual citizens) with the ability to pass a federal background investigation in order to gain access to sensitive information.
Other Job Specific Skills- Demonstrated knowledge/experience with: Risk Assessments; NIST SP 800-37 RMF; NIST Cybersecurity Framework; NIST SP 800-53 security controls; managing POA&Ms; reviewing vulnerability scan results; using the Enterprise Logging System for audit-log review; reviewing OS/application/database security baseline configuration; performing security impact analysis on change requests; writing security policy; and understanding of M-22-09 / Zero Trust Architecture pillars
Compensation RangesCompensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.