Information Security Compliance Specialist

Tria Federal

$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Very familiar with DHS practices and regulations.
  • 3-5 years of experience in Cybersecurity, specifically with DHS A&A Assessments.
  • Possess a DHS Public Trust clearance.
  • Proficient in CSAM and NIST Risk Management Framework (RMF).
  • Knowledgeable of the DHS Security Authorization Process.
  • Experience in assessing and managing cybersecurity risks with stakeholders.
  • Understanding of system Authority to Operate (ATO) processes and maintenance.

Responsibilities

  • Conduct independent evaluations of security controls across technical, operational, and management domains.
  • Review and analyze system documentation related to security and management plans.
  • Analyze and interpret results from vulnerability and compliance scans.
  • Identify vulnerabilities, compliance issues, and design gaps.
  • Create detailed Security Assessment Reports highlighting risks and ATO requirements.
  • Manage Plan of Action and Milestones (POA&Ms) activities from creation to closure.
  • Coordinate efforts with system owners, engineers, and risk officers during the authorization process.

Benefits

  • Potential for remote work with onsite requirements 1-2 times per week.
  • Opportunities for professional development in a governmental cybersecurity environment.
  • Engagement in significant projects impacting national security.
  • Experience working with high-caliber team members in the field of cybersecurity.
Full Job Description
Job Description:

The Information Systems Compliance Specialist will conduct Security Assessment and Authorization (A&A) support for USSS IT systems. This candidate must have the ability to work onsite at customer HQ 1-2 times per week in Washington, DC.

Requirements:
  • Very familiar with DHS.
  • 3-5 years Cybersecurity experience, especially conducting DHS A&A Assessments.
  • DHS Public Trust clearance.
  • Working knowledge and experience with CSAM and the NIST RMF.
  • Working knowledge and experience with the DHS Security Authorization Process.
  • Experience working with system stakeholders to assess and manage system cybersecurity risk.
  • Knowledge of the process to obtain a system ATO and requirements to maintain the ATO.
  • Ability to synthesize complex IT system information and communicate system status and requirements in written products and verbal presentations.
  • Ability to assess and identify clear, concise, and effective security control implementation statements.
  • Ability to work independently and within given timelines.
  • Ability to report onsite at customer HQ as required.

Qualifications:
  • CISSP, CISM
  • 3-5 Years of IT Security Control Assessment experience
  • DHS A&A Experience
  • Bachelor's degree
  • Security+ Certification

Responsibilities:
  • Conduct independent tests and evaluations of technical, operational, and management security controls.
  • Review system documentation to include security plans, Configuration Management Plans, Contingency Plans, Account Management Plans, etc.
  • Ability to analyze and interpret vulnerability and compliance scans.
  • Identify security weaknesses, design gaps, and compliance deviations.
  • Author comprehensive Security Assessment Reports (SARs) with clear risk findings and ATO deliverables.
  • Perform Plan of Action and Milestones (POA&Ms) management activities including creation, management and closures
  • Coordinate with system owners, engineers, and risk officers during authorization processes


Similar Jobs

More Jobs at Tria Federal

More Information Technology Jobs

Find similar Information Security Compliance Specialist jobs: