REQUIRED SKILLS/ABILITIES
- Using automated tools, identify the presence and use of any unapproved technology components in the common operating environment to ensure compliance with the client's enterprise architecture and applicable reference models.
- Work closely with the client's Audit Team to identify areas for process improvement.
- Understand and incorporate lessons learned from internal and external audits across the enterprise's portfolio of IT systems by working closely with the client1s Audit Team.
- Validate results of control testing conducted by Information System Security Officers (ISSO) in support of annual self- assessment requirements for IT systems within the required testing frequencies as part of the Continuous Monitoring Program.
- Review artifacts submitted as evidence of control testing results as a part of the self-assessment testing conducted by the ISSOs to validate reported test results.
- Review, validate, and track false positives in scan results reported by the ISSOs to provide assurance that IT system operation meets specified security control implementation requirements as specified in the NIST SPB00-53 and supporting DHS guidance.
- Review documentation submitted in support of requesting a waiver for compliance with specified security requirements per the NIST SP 800-53, and provide recommendations to the client for approval and acceptance of associated risk.
- Review and assess system changes to determine the level of independent security assessment required in support of the Security Impact Analysis process for the enterprise portfolio of systems.
- Coordinate with the SCA team on testing of common controls, the client's RMIC Group for A-123 and external assessments, as well as the schedule for testing applications due to major changes.
- Perform quality assurance reviews of security documentation as needed to ensure content meets the intended requirements and is suitable to determine the security posture and associated risk of an IT system.
CERTIFICATION REQUIREMENTS
- CISA, CISM, and/ or CISSP preferred, but not required.
Equal Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.