Yesterday
Secret
Unspecified
Unspecified
Security
Washington, DC (On-Site/Office)
Location : Washington, DC Hybrid
Contract To Hire
Job Description
Responsibilities:
Required Qualifications:
Desired Qualifications:
Contract To Hire
Job Description
Responsibilities:
- Execute assessment support according to plans and guidance provided by more senior members of staff.
- Review Rules of Engagement, Security Assessment Plans and Security Assessment Reports
- Apply risk-based approaches for security control implementation and vulnerability remediation under the guidance of more senior members of staff.
- Work closely with Government Security Program Stakeholders such as CISO, ISSOs, ISSMs, and SCAs to quality control and quality assurance team members to ensure and improve quality of assessment deliverables.
- Local travel within the DMV area to conduct security assessments.
- Assist with other tasks as assigned.
- Advocated best practices to customers on behalf of Client Cyber Solutions. Contribute to practice development by participating in thought leadership, conferences, and assisting with white paper research and development.
Required Qualifications:
- Requires 4 days on-site support in Washington, DC
- Active Top-Secret clearance required.
- This position requires a badge and or clearance that will require an extensive background, credit, and drug screening requirement.
- 3+ years' experience in cybersecurity programs and experience performing security testing and/or security control assessments.
- Must have experience with RMF in an Assessor role.
- Familiarity with FISMA and NIST SP 800-53 and 800-53A
- Ideally, familiarity with Linux, Windows, Unix, legacy systems and cloud
- Proactive about professional development and willing to obtain security certifications.
- Great communication and interpersonal skills.
- Must be able to occasionally travel to customer locations and perform on site assessments when needed.
Desired Qualifications:
- Experience with Archer GRC, XACTA, and eMass tools
- Bachelor's Degree in a technology discipline
- General knowledge of system administration and networking principles
- Active cybersecurity certification such as Security+, CEH, CISM, CAP, or CISSP
group id: cxjudgpa