Unfortunately, this job posting is expired. Please click here to view related job postings.
Company

Solutions By Design IISee more

addressAddress20588, MD
type Form of workFull-Time
CategoryInformation Technology

Job description

Job Description

SBD is seeking a Security Control Assessor (SCA) to join our team supporting our federal client. This position is involved in all steps of the Risk Management Framework (RMF) as outlined in the NIST SP 800-37, Risk Management Framework for Information Systems, with a primary focus on executing all security control assessments for the organization.

This position is hybrid, requiring at least 2 days/week onsite at our customer's location in Camp Springs, MD.

Responsibilities Include:

  • Ensuring a timely, thorough, and effective security assessment, ensuring risks are clearly stated and appropriately rated.
  • Prepare the necessary security assessment artifacts and reports, documenting the results associated with the assessment, and conduct close out briefings for the respective system's stakeholders.
  • Provide peer reviews of teammate's assessment deliverables as needed.
  • Risk assessments
  • FedRAMP assessments
  • Review and input into enterprise security policy and governance, and security architecture and configuration of enterprise resources.

Required Experience and Qualifications:

  • Bachelor's Degree and 3 to 6+ years of related experience.
  • Must have and maintain at least one certification such as CISSP, CISM, CISA, CAP, CEH, or equivalent.
  • Extensive experience with the NIST RMF and independently leading security control assessments from start to finish using the NIST Framework.
  • Experience in several of the following areas is required:
    • Understanding of IT security practices and procedures.
    • Knowledge of current security tools available.
    • Different communication protocols.
    • Encryption techniques/tools.
    • Secure system architecture.
    • System engineering.
    • System administration.
    • Configuration management.
    • Agile application development experience.
  • Must be fully cloud proficient (AWS, Azure, Google).
  • Experienced performing FedRAMP assessments and assessments of systems hosted in the cloud.
  • Experience creating, reviewing, and updating/editing security artifacts (i.e., Security Plans, Contingency Plan, Contingency Plan Test, e- Authentication workbook, FIPS 199 workbook, etc.)
  • Proficient at interpreting scan results from various vulnerability and compliance tools such as MicroFocus Fortify SCA and WebInspect, Tenable Nessus and TIO, Prisma Cloud, SonarQube.
  • Must be capable of providing corrective actions for weaknesses discovered during the assessment.
  • Must have experience with SIEM tools and performing audit log reviews.
  • Experience creating and validating remediation of POA&Ms.
  • Technical writing ability is required.
  • Must be a US Citizen able to obtain an agency-specific suitability clearance prior to starting.
  • Must reside within a commutable distance to our client's location in Camp Springs, MD in order to work onsite at least 2 days/week.
  • Must be able to pass a comprehensive background check.
  • Must be fully vaccinated for COVID-19, unless a medical exemption or religious accommodation is approved. Individuals are considered fully vaccinated two weeks after their last dose of their vaccine. Confirmation of vaccine is required.

Desired Experience and Qualifications:

  • Knowledge of container platforms (EKS, OpenShift, Docker) and microservice architecture.
  • Development or programming experience.
  • Familiarity with Nipper, Burp Suite Pro, Kali Linux, SolarWinds, Telos IACS, SPLUNK.
  • Penetration Testing experience.


Job Posted by ApplicantPro
Refer code: 2168609. Solutions By Design II - The previous day - 2023-01-26 15:15

Solutions By Design II

20588, MD
Popular Security Control Assessor jobs in top cities
Jobs feed

Cybersecurity Specialists

Amnet

Colorado, United States

$70.5K - $89.2K a year

Cybersecurity Operations Specialist - Tier 3

Northramp, Llc

Washington, DC

$70.1K - $88.7K a year

Cybersecurity Compliance Specialist

Attainx Inc

Arlington, VA

$112K - $142K a year

Cybersecurity Specialist

Black Diamond Consulting Corporation

Washington, DC

$116K - $146K a year

Cybersecurity Sales Specialist (Remote / Atlanta)

Corus Group, Llc

Atlanta, GA

$64.8K - $82K a year

Junior IT Analyst (REMOTE)

Jefferson Consulting Group

Remote

$62.8K - $79.5K a year

Cybersecurity Specialist - Digital Forensics

Abbvie

Illinois, United States

$97K - $123K a year

Information Security Specialist

National Wildlife Federation

Reston, VA

$110,000 - $115,000 a year

IT Cybersecurity Specialist (INFOSEC)

Us Naval Air Systems Command

Orlando, FL

$82,830 - $128,043 a year

Cybersecurity Management Specialist

Caelum Research Corporation

Aberdeen, MD

$50 - $80 an hour

Share jobs with friends

Security Controls Assessor/Assessment and Authorization Specialist (SCA A&A)

Leidos

$122,200 - $220,900 a year

Suitland, MD

just now - seen