Salary
💰 $120,000 - $140,000 per year
Tech Stack
CloudCyber Security
About the role
- Participate in the assessment of low, moderate, and high impact information systems to include Cloud service offerings.
- Complete comprehensive test plans for identified security controls following NIST 800-53a, Federal Risk and Authorization Management Program (FedRAMP) guidance, and/or agency-specific guidance.
- Produce complete, accurate, and timely findings reports using client defined templates.
- Review and analyze needed updates to existing set of security documents (e.g., system boundaries, privacy impact assessments (PIAs), system security plans (SSP), risk assessments (RA), memoranda of understanding, interconnection security agreements, contingency plans (CP), etc.)
- Maintain currency on latest security vulnerabilities and options for mitigation.
- Develop risk mitigations and recommendations for identified security assessment findings.
- Review system categorization and associated controls. Maintain currency in federal cybersecurity policy, e.g., Office of Management and Budget (OMB) Memorandum, NIST Special Publications, and FedRAMP.
Requirements
- 10+ years experience with NIST RMF.
- Proficiency in all steps in the RMF framework, expert in NIST special publications such as 800-53 & 800-17.
- Bachelor's degree or equivalent experience.
- At least one of the following certifications: CAP, GIAC, GSLC, CISM, CRISC, CISSP, or CASP.
- Must be a US Citizen.
- Must be able to obtain and maintain a Public Trust Clearance (the investigation will involve a credit, fingerprint, and law enforcement agency check).