Place of Performance: Remote
Citizenship: US Citizen (MUST)
Security Clearance: Must be eligible to possess MBI (IRS Background Investigation) clearance. Active IRS MBI clearance is preferred.
Role Summary:
Senior hands-on technical lead for security assessment execution and for developing and validating the SCSEMs and automated evaluation files that drive every review. Distinct from the Computer & Information Systems Manager: this role is the deep technical author/assessor rather than the team manager.
Key Responsibilities:
- Develop, update, and validate SCSEMs and automated evaluation files (Nessus audit / SCAP XCCDF), mapping to CIS Benchmarks, DISA STIGs, and applicable NIST controls.
- Validate that automated checks accurately reflect required configurations and correctly evaluate both binary and non-binary conditions.
- Lead hands-on system configuration checks and automated/manual compliance scanning during reviews.
- Perform corrective actions and ad hoc fixes for identified issues, including logic errors in automated evaluation files.
- Maintain configuration instructions and supporting documentation; ensure alignment between SCSEMs and automated files.
Core Experience (Required):
- Demonstrated experience identifying and applying information-security/cybersecurity requirements and ensuring they are addressed through development, implementation, and configuration.
- Demonstrated experience implementing security controls, configuration changes, software/hardware updates, and vulnerability management within government organizations.
- Hands-on experience securing configurations and authoring or tailoring SCSEM/STIG/CIS/Nessus content (preferred).
Minimum Education: High School Diploma or higher.
Certifications / Licenses (minimum of ONE of the following):
- CCNA Security CySA+/CSA+ GICSP GSEC Security+ CE CND SSCP CASP+ CE CCNP Security CISA CISSP (or Associate) GCED GCIH CCSP CAP CISM GSLC CCISO HCISPP CEH GSNA CFR PenTest+
In lieu of a certification, graduation from a minimum 2-year IT/Cybersecurity program at an accredited college or university may be substituted.
Preferred: Prior FTI/Safeguards review experience; demonstrated SCSEM/STIG/CIS/Nessus authoring.