Risk Assessor

rose international

Richmond (VA)

On-site

USD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

rose international is hiring an IT Risk Assessor in Richmond, VA. The candidate will support compliance with state and federal standards, conduct assessments on various systems, and analyze security controls.

The ideal candidate should have at least 2 years of experience in IT risk assessments, strong analytical and communication skills, and familiarity with security technologies. Core responsibilities include detailed evaluations and providing executive summaries for each assessment performed.

Qualifications

  • 2+ years of experience conducting IT risk assessments.
  • Experience creating technical documentation and reports.
  • Experience working independently with minimal supervision.

Responsibilities

  • Assist with meeting security and compliance requirements per state and federal standards.
  • Review information system security controls and evaluate their efficacy in mitigating associated risk.
  • Provide an executive summary of the assessment for each evaluated system.

Skills

Analyzing system security controls implementation
Effective written and verbal communication
Attention to detail
Knowledge of SEC501 security standard
Familiarity with technologies (Java, .NET, SQL, etc.)

Tools

Vulnerability scanning tools
Intrusion Detection/Prevention System
Firewalls and network security technologies

Job description

The qualified candidate will join a team that is responsible for the assessment of information systems that are supported by multiple operating systems, databases, and software development technologies.

TAX seeks an experienced risk assessor in Richmond, VA. The candidate will assist agency personnel in performing risk assessments in accordance with Commonwealth and Agency procedures as well as identify opportunities for improvement. The underlying information infrastructure includes Linux, UNIX, and Windows operating systems; Oracle and Microsoft SQL Server databases, and multiple software development languages that include PowerBuilder, Java, .NET, etc. to name a few.

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls and evaluate their efficacy in mitigating associated risk. The risk assessor will work closely with system owners, data owners, and system administrators to conduct interviews and review technical information. The assessor will provide an executive summary of the assessment along with a completed VITA Risk Assessment Template for each system evaluated.

An information system security risk assessment should also be performed in compliance with SEC501.09 and SEC520.00 using the risk assessment template: (http://vita.virginia.gov/uploadedFiles/VITA_Main_Public/Library/PSGs/Word_versions/Risk_Assessment_Template.xlsx).

Systems Assessed
  • Appeals and Rulings
  • FACSYS
  • Fraud Identity Theft
  • TAXi (SharePoint)
  • Teleplan
  • eFile
  • Keylight
  • Remit
  • Report Manager
Responsibilities
  • Assist with meeting security and compliance requirements per state and federal standards.
  • Review information system security controls and evaluate their efficacy in mitigating associated risk.
  • Work closely with system owners, data owners, and system administrators to conduct interviews and review technical information.
  • Provide an executive summary of the assessment along with a completed VITA Risk Assessment Template for each system evaluated.
  • Ensure assessments are performed in compliance with SEC501.09 and SEC520.00.
Qualifications
  • 2+ years of experience conducting IT risk assessments.
  • Strong knowledge of analyzing system security controls implementation and efficacy.
  • Experience working as a member of a core team and independently with minimal supervision.
  • Strong attention to detail and effective written and verbal communication skills.
  • Experience creating technical documentation and reports.
  • Knowledge of SEC501 security standard.
  • Knowledge of IRS Pub 1075 and CIS benchmarks.
  • Familiarity with technologies such as Java, .NET, Windows, Linux, UNIX, MS SQL, and Oracle.
Core Tools and Technologies
  • Vulnerability scanning and analysis.
  • Intrusion Detection/Prevention System (IPS/IDS).
  • Security Event Logging.
  • Firewalls and other network security technologies.
Physical Requirements
  • Ability to lift no more than 50 lbs.
EEO and Equal Opportunity

All your information will be kept confidential according to EEO guidelines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Strategic IT Risk Assessor – Security & Compliance
Strategic IT Risk Assessor – Security & Compliance

rose international • Richmond (VA)

On-site
USD 70,000 - 90,000
IT Auditor - Remote
IT Auditor - Remote

PEOPLECORP AMERICA • Austin (TX)

Remote
USD 80,000 - 110,000
Risk Assessment Specialist
Risk Assessment Specialist

Ampcus, Inc • Richmond (VA)

On-site
USD 85,000 - 120,000
TPRM Assessor/Cybersecurity Risk Auditor
TPRM Assessor/Cybersecurity Risk Auditor

Ampcus Inc • Chantilly (VA)

On-site
USD 85,000 - 115,000
Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
1.20. IT Security Analyst
1.20. IT Security Analyst

Focused HR Solutions • Richmond (VA)

On-site
USD 80,000 - 120,000
IT Security Analyst / Assessor
IT Security Analyst / Assessor

NXTKEY CORPORATION • Washington

On-site
USD 90,000 - 120,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
IT Auditor
IT Auditor

ASCENDING • United States

Hybrid
USD 80,000 - 110,000
Security Control Assessor
Security Control Assessor

Apex Systems • Alexandria (VA)

On-site
USD 90,000 - 120,000
401K program
HSA
ESPP (Employee Stock Purchase Program)
+1