The Security Modernization Specialist Mid evaluates the Agency's current enterprise architecture, tools, and processes against CISA's Zero Trust Maturity Model, then updates the Agency's ZTA Implementation Plan and drafts/updates the OIT Zero Trust Optimization Roadmap across all ZT focus areas - Identity, Devices, Networks, Applications & Workloads, Data, Visibility & Analytics, Automation & Orchestration, and Governance. It supports the Zero Trust Architecture Implementation & Optimization Integrated Project Team (IPT), builds consensus across working groups, and tracks ZTA risks, issues, and metrics through to resolution. The position also maintains BI dashboards and technical/executive-facing documentation that communicate the Agency's ZTA maturity progress by pillar.
- Serve as Zero Trust SME and strategic consultant to Government leadership; assist in incorporating ZT concepts per M-22-09, CISA's Zero Trust Maturity Model, NIST SP 800-207, DoD's ZT Reference Architecture, and EO 14028.
- Evaluate the Agency's Enterprise Architecture, tools, configurations, and SOPs from a ZTA lens; identify further-adoption opportunities.
- Identify technology/capability gaps; evaluate products and make tool/technology recommendations to mature ZTA capability levels.
- Update the Agency's ZTA Implementation Plan and draft/update the OIT Zero Trust Optimization Roadmap across all ZT focus areas (Identity, Devices, Networks, Applications & Workloads, Data, Visibility & Analytics, Automation & Orchestration, Governance).
- Draft and maintain the Agency's Security Modernization Strategy and support the ZTA Implementation & Optimization IPT, working groups, and consensus-building.
- Prioritize modernization initiatives and track ZTA risks/issues/blockers; develop and track Security Modernization metrics.
- Maintain the SecMod/ZT JIRA project board and an enterprise Integrated Master Schedule/Gantt chart; develop single-pane-of-glass BI dashboards tracking ZTA maturity per pillar.
- Develop technical documentation, non-technical executive summaries, and briefing materials supporting security modernization efforts.
Minimum Qualifications- Minimum 5 years of professional experience in information assurance, cybersecurity, risk management, or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, 3 years of such experience.
- One of the following (per PWS Section B - Security Modernization): ISC2 CISSP; ISACA CISM; ISACA CRISC; GIAC GCED; CompTIA CEH.
Other Job Specific Skills- Demonstrated knowledge/experience with:
- M-22-09; Zero Trust Architecture pillars;
- CISA Zero Trust Maturity Model;
- NIST Zero Trust Architectural Model;
- DoD Zero Trust Reference Architecture;
- Risk Assessments;
- NIST SP 800-37 RMF;
- NIST Cybersecurity Framework;
- NIST SP 800-53 controls;
- POA&M management;
- System design/configuration security impact analysis; and security policy writing.
Compensation RangesCompensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.