AnaVation is seeking a Sr. Security Specialist (ISSO/Risk Assessor duties) for our mission critical customer in Washington, DC. You will work as part of a fantastic team providing security expertise on high priority projects. Daily duties include, but are not limited to: · Integral team member for agencyâs risk assessment program that will be performing internal audits and building streamlined assessment processes. · Having in-depth security knowledge, is highly technical, and experienced in managing the security of a systemâs accreditation boundary. · Focusing on the enterprise governance and risk of exposure across a multi-cloud and on-premise environment that will include multiple vendors, customers and XaaS products. · Evaluating agencyâs current system infrastructure and recommending changes to improve its security posture. · Providing customer support for security compliance and audit liaison activities. Focus is on improving the security posture of the agencyâs Forensic and Investigative Labs. · Developing, maintaining, and assessing Security Assessment & Authorization (SA&A) packages resulting in an Authority To Operate (ATO) for IT systems. · Creating and maintaining SSPs and supporting documentation in accordance with agency guidelines and directives. This includes writing implementation statements, creating supporting documentation (e.g., Contingency Plans, Incident Response Plans, Account Management Plans, etc.), performing self-assessments, and/or assessing your peerâs assessment, while working with system stakeholders. · Develop, coordinate, test, and train personnel on Incident Response Plans and Contingency Plans. · Ensuring that information systems are accredited, maintain their ATO, and are being continuously monitored. · Performing risk assessments for agency systems/applications, to include cloud-based systems. · Performing security control assessments to include collecting supporting artifacts/evidence and interviewing system owner/owner representatives. · Maintaining and tracking system POA&Ms. · Reviewing and analyzing vulnerability scan data and providing recommendations on remediation. · Taking ownership on various projects. · Improving on processes and procedures and making recommendations to improve the security posture of the agency's IT systems and applications. This position is on-site in Washington, DC.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed
Number of Employees
51-100 employees