Strong working knowledge of IT Security requirements, technical security countermeasures, risk management processes, contingency planning, and secure data communications
Conduct full cycle Security Assessments & Authorizations (SA&A)
Test network, system, application and NIST controls from administrative and technical perspectives
Analyze vulnerability scans, interpret risks, and employ manual checks to validate vulnerability data
Assist customers in understanding risk and provide risk mitigation recommendations
Create Security Assessment Plans, Reports, and POA&Ms
Conduct documentation reviews, inspections, and interviews with personnel to collect evidence of compliance
Determine compliance based on responses and analysis of supporting evidence
Requirements
At least 5 years experience
Bachelor's Degree or 4 years of specialized experience
Strong security assessor background
Must understand the Risk Management Framework (RMF) process
Experience conducting full cycle Security Assessments & Authorizations (SA&A)
Experience testing network, system, application and NIST control testing from administrative and technical perspectives
Experience analyzing vulnerability scans, interpreting risks, and performing manual validation of vulnerability data
Ability to create Security Assessment Plans, Reports, and POA&Ms