Job Description: The Information Systems Compliance Specialist will conduct Security Assessment and Authorization (A&A) support for USSS IT systems. This candidate must have the ability to work onsite at customer HQ 1-2 times per week in Washington, DC.
Requirements: - Very familiar with DHS.
- 3-5 years Cybersecurity experience, especially conducting DHS A&A Assessments.
- DHS Public Trust clearance.
- Working knowledge and experience with CSAM and the NIST RMF.
- Working knowledge and experience with the DHS Security Authorization Process.
- Experience working with system stakeholders to assess and manage system cybersecurity risk.
- Knowledge of the process to obtain a system ATO and requirements to maintain the ATO.
- Ability to synthesize complex IT system information and communicate system status and requirements in written products and verbal presentations.
- Ability to assess and identify clear, concise, and effective security control implementation statements.
- Ability to work independently and within given timelines.
- Ability to report onsite at customer HQ as required.
Qualifications: - CISSP, CISM
- 3-5 Years of IT Security Control Assessment experience
- DHS A&A Experience
- Bachelor's degree
- Security+ Certification
Responsibilities: - Conduct independent tests and evaluations of technical, operational, and management security controls.
- Review system documentation to include security plans, Configuration Management Plans, Contingency Plans, Account Management Plans, etc.
- Ability to analyze and interpret vulnerability and compliance scans.
- Identify security weaknesses, design gaps, and compliance deviations.
- Author comprehensive Security Assessment Reports (SARs) with clear risk findings and ATO deliverables.
- Perform Plan of Action and Milestones (POA&Ms) management activities including creation, management and closures
- Coordinate with system owners, engineers, and risk officers during authorization processes