5-7 years of hands-on experience in risk and vulnerability assessments.
In-depth knowledge of Federal Cybersecurity regulations and guidelines (NIST, FISMA).
Experience in developing and maintaining information assurance documentation.
Ability to incorporate security requirements into system design throughout the lifecycle.
CISSP or equivalent certification (e.g., Security+).
Secret Clearance required.
Responsibilities
Enhance cybersecurity assessment operations through SOP development.
Analyze vulnerabilities and recommend remediation tactics.
Review and recommend improvements on technical documentation like security plans and test procedures.
Develop and document effective security evaluation test plans.
Research and develop relevant information security policies and guidelines.
Lead or participate in technical exchange meetings, documenting outcomes.
Conduct hands-on security testing and assess risk based on analytical results.
Benefits
Collaborative work environment promoting teamwork.
Opportunities for professional growth and development.
Participation in technical exchange meetings to enhance knowledge.
Engagement in high-impact federal cybersecurity initiatives.
Full Job Description
Key Responsibilities:
Provide enhancement capabilities and SOPs to cybersecurity assessment operations for execution and implementation.
Provide analysis of vulnerabilities.
Review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.).
Develop and document security evaluation test plans and procedures.
Assist in researching, evaluating, and developing relevant Information security policies and guidance.
Actively participate in or lead technical exchange meetings, documenting actions items and results of these events.
Brief leadership, as needed, on the status of action items and/or results of activities.
Conduct hands-on security testing, analyze test results, document risk, and recommend countermeasures.
Coordinate with other program organizations conducting security testing.
Assess and calculate risk-based on threats, vulnerabilities, and shortfalls uncovered in testing.
Identify mitigation countermeasures to identify threats, vulnerabilities, and shortfalls.
Provide oversight of the design, development and implementation of security-related support systems.
Qualifications:
Technical Proficiency: Hands-on experience conducting comprehensive risk and vulnerability assessments. Extensive knowledge of Federal Cybersecurity regulations, policies and guidelines (e.g., NIST, FISMA and associated guidelines). Experience developing and maintaining system and enterprise level information assurance documentation. Ability to support security engineering activities and ensure security requirement are incorporated into system design, architecture and configuration baselines throughout the systems lifecycle.
Compliance: Ensure compliance with Federal cybersecurity regulations, including NIST, FISMA, and associated guidance. Ensure artifacts, assessments, and system configurations remain aligned with NIST SP 800-53 controls, FedRAMP baselines, Federal agency policy and directives.
Certifications: CISSP or equivalent Cybersecurity certification (e.g., Security+).
Preferred Expertise:
Demonstrated success supporting Federal contracts.
Strong background coordinating with stakeholders (e.g., system owners, ISSOs, architecture teams, and cybersecurity leadership) to validate system requirements, address information assurance concerns, and resolve compliance or security issues.
Strong analytical, written, and verbal communication skills, with the ability to translate technical risks and content into terms suitable for executive and government stakeholders.
Ability to work collaboratively with others and contribute to a team environment.
Education & Experience:
Education: Bachelor's degree in Information Technology, Business Management or a related field.
Experience: Minimum of 8 years of cybersecurity experience.