This role involves applying fundamental cybersecurity principles and concepts to tasks and projects. The position requires assessing and implementing NIST Cybersecurity Framework (CSF) guidelines, standards, and best practices for cyber security and risk management to strengthen an organization's security posture. Responsibilities include reviewing disaster recovery capabilities (backups), Endpoint Detection and Response (EDR), Web Application Firewall (WAF), application whitelisting, and host-based firewalls to provide continuous monitoring of end-user devices for cyber threats. The role demands an understanding of Governance Risk and Compliance (GRC) requirements, standards, and guidelines governing security within the Federal Government (e.g., NIST publications, FISMA, and OMB memoranda), and aligning IT with business objectives to effectively manage risk. The position will apply NIST Risk Management Framework (RMF), NIST SP 800-53 controls, Assessment and Authorization processes, POA&M management, and System Security Plan, FedRAMP, and SOC 2. It also involves performing cybersecurity risk management, research and development, and leading practices. The role requires gathering and organizing technical information about an organization's mission goals and needs, existing security products, and ongoing programs in cybersecurity. Developing strategies, roadmaps, assessments, and policies is key. The position will perform password auditing, network and web vulnerability scanning, virus management, and intrusion detection. Monitoring change management documentation to identify potential impacts to security testing is also a responsibility. The role includes authoring risk narratives to communicate key risks to government CISO and security auditors, supporting risk audits and assessments, and providing recommendations for application design. Collaboration with solution architects for security requirements on network architecture is expected.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior