Technical Manager

DataLock Consulting Group

Poland

On-site

PLN 100,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Health insurance
Professional development opportunities

Job summary

A leading consulting firm in Poland seeks a Managing Partner to oversee security control assessments. The role involves conducting audits of security controls and evaluating systems for effectiveness. Candidates should have extensive experience with NIST frameworks and possess strong project management skills. A bachelor’s degree in IT or related field is required, along with relevant certifications. This is a pivotal role ensuring client security standards are met. Excellent communication and technical writing skills are essential.

Qualifications

  • 8 years of experience in security programs.
  • 5 years of experience in auditing and/or assessment.
  • Extensive experience with NIST 800-53 and 800-53A.

Responsibilities

  • Assist in developing a Security Control Assessment strategy.
  • Conduct Security Assessment Kickoff briefings and SAR briefings.
  • Analyze security control findings and document results.

Skills

Security control assessment
NIST Cybersecurity Framework
Auditing
Risk Assessment
Technical writing
Project management

Education

BS/BA degree in Information Technology
Master’s degree in relevant field

Tools

Nessus
Splunk
Web Inspect
Db Protect

Job description

Managing Partner

To be determined prior to time of absence.

SUMMARY

The Technical Manager/Lead Security Assessor will conduct security control assessments of the security and privacy controls implemented by an information system to determine the overall effectiveness of the controls and the vulnerability state of components, applications and databases residing within the system boundary. Following the NIST Cybersecurity Framework, Risk Management Framework and using NIST 800-53A, verifies the security status of existing information systems with an Authority to Operate (ATO) by performing appropriate assessments on any new system developed or deployed by the customer, and conducts audits of security controls to ensure continuous monitoring of systems assigned. Assesses systems that have previously been assessed and received an ATO and systems that have not yet been assessed and do not have an ATO.

RESPONSIBILITIES
  • Assist in developing a Security Control Assessment (SCA) strategy for the organization; to include an overall assessment process flow or swim‑lane diagram which documents the steps required to conduct assessment activities and interact with all necessary parties.
  • Integrate SCA functions with overall continuous monitoring and Continuous Diagnostic and Mitigation (CDM).
  • Serve as a technical manager and assigns tasks to the security assessment lead; develop associated schedules and resource plans to complete the assessments.
  • Identify and document the appropriate security assessment level of effort and project management information to include tasks, reviews (including compliance reviews), resources, due dates, and milestones for the system being tested.
  • Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs).
  • Work closely with ISSOs (contractors and Government) and the technical team and ensure all appropriate A&A supporting documentation is provided prior to conducting the assessment.
  • Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization.
  • Conduct Security Assessment Kickoff briefings and SAR briefings.
  • Review cyber/system/network security body of evidence and documentation for accuracy and completeness.
  • Conduct security controls assessment of applicable security controls and privacy controls; assess implemented security controls and provide assurance that they are operating as intended.
  • Analyze security control findings for information systems and applications to convey weaknesses.
  • Document security assessment results accurately; read, understand, and convey vulnerabilities found during the assessments.
  • Create security assessment results and document recommendations in a SAR for remediations and security control measures.
  • Perform audits of each system and provide an authorization recommendation based on determination of risk to the customer.
  • Audits will include unprivileged and privileged scans against each applicable system.
  • Audits will include unprivileged and privileged database scans against each applicable database management system (DBMS).
  • Perform quality control on the assessment and associated deliverables.
  • Conduct Post Assessment Meetings with the customer.
  • Provide Plan of Action and Milestones (POA&M) support to ensure mitigations are completed or the teams are working to mitigate all vulnerabilities in a timely fashion and within customer policy timelines.
  • Develop and maintain a schedule for conducting reoccurring Continuous Monitoring and ongoing CDM efforts once the initial assessments are complete.
  • Perform continuous monitoring to ensure implemented security controls remain functional throughout the lifecycle of the information system.
MINIMUM EXPERIENCE AND SKILLS
  • 8 years of experience in security programs (master’s degree substitutes for 5 years).
  • 5 years of experience in auditing and/or assessment.
  • Extensive experience with developing and documenting the ROEs, SAPs, and SARs.
  • Extensive experience and expert knowledge of the NIST Cybersecurity Framework, Risk Management Framework, FIPS, and other NIST A&A publications.
  • Extensive experience utilizing NIST 800-53 and 800-53A.
  • Strong experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan.
  • Strong knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions.
  • Expert knowledge and skills to perform and document the assessment.
  • Significant experience with tools such as Nessus, Web Inspect, Db Protect and Splunk.
  • Strong technical background with Windows, Unix, legacy systems, databases, web servers/application, cloud and virtualization environments.
  • Familiar with the cloud environments (services/security) and FedRAMP A&A process.
  • Strong project management, time management, and work sequencing skills.
  • Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally.
  • Effective technical writing and documentation processing skills.
MINIMUM EDUCATION
  • BS/BA degree in Information Technology or related cyber/cyber‑security field with 8+ years of experience.
  • Or Master’s degree with 3+ years of experience.
  • Or equivalent experience.
CERTIFICATIONS
  • Must possess an ISC2 Certified Information System Security Professional (CISSP) certification.
  • Must possess one of the following certifications:
  • CompTIA Advanced Security Practitioner (CASP+ CE)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Security Leadership (GSLC)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Cloud Security Professional (CCSP)
  • CISSP-Information Systems Security Architecture Professional (CISSP-ISSAP)
  • CISSP-Information Systems Security Engineering Professional (CISSP-ISSEP)
  • CISSP-Information Systems Security Management Professional (CISSP-ISSMP)
  • Certified Chief Information Security Officer (CCISO)
  • BCR Cyber Technical Proficiency Testing Activity
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessor
Security Assessor

DataLock Consulting Group • Poland

Remote
PLN 210,000 - 296,000
Security Penetration Tester
Security Penetration Tester

DataLock Consulting Group • Poland

Remote
PLN 252,000 - 380,000
Information Security Engineer
Information Security Engineer

YDU JC Air Cond & Ref Inc.- Dubai • Warszawa

On-site
PLN 160,000 - 220,000
Cybersecurity Quality Assurance Analyst Independent Verification and Validation (IV&V)
Cybersecurity Quality Assurance Analyst Independent Verification and Validation (IV&V)

DataLock Consulting Group • Poland

Remote
PLN 120,000 - 150,000
Senior GRC Engineer
Senior GRC Engineer

DataLock Consulting Group • Poland

Remote
PLN 294,000 - 380,000
Competitive compensation
Comprehensive benefits package
Commitment to work-life balance
Security Engineer with IRS MBI Clearance
Security Engineer with IRS MBI Clearance

3M Consultancy • Poland

Remote
PLN 210,000 - 296,000
Cybersecurity Architect
Cybersecurity Architect

Vector Synergy • Warszawa

On-site
PLN 100,000 - 130,000
Cybersecurity Vulnerability Analyst
Cybersecurity Vulnerability Analyst

ARHS • Warszawa

On-site
PLN 180,000 - 260,000
Cybersecurity Risk Manager (EU Security Environment)
Cybersecurity Risk Manager (EU Security Environment)

Aricoma • Warszawa

On-site
PLN 180,000 - 320,000
Senior Analyst – Attack Surface Management
Senior Analyst – Attack Surface Management

Jobtailor • Kraków

On-site
PLN 180,000 - 250,000