drjobs Cloud Based Security Control Assessor SCA

Cloud Based Security Control Assessor SCA

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Chantilly, VA - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Company Overview

We are a worldclass team of professionals who deliver next generation technology and products in robotic and autonomous platforms ground soldier and maritime systems in 50 locations worldwide. Much of our work contributes to innovative research in the fields of sensor science signal processing data fusion artificial intelligence (AI) machine learning (ML) and augmented reality (AR).

QinetiQ USs dedicated experts in defense aerospace security and related fields all work together to explore new ways of protecting the American Warfighter Security Forces and Allies. Being a part of QinetiQ US means being central to the safety and security of the world around us. Partnering with our customers we help save lives; reduce risks to society; and maintain the global infrastructure on which we all depend.

Why Join QinetiQ US

If you have the courage to take on a wide variety of complex challenges then you will experience a unique working environment where innovative teams blend different perspectives disciplines and technologies to discover new ways of solving complex problems. In our diverse and inclusive environment you can be authentic feel valued be respected and realize your full potential. QinetiQ US will support you with workplace flexibility a commitment to the health and wellbeing of you and your family and provide opportunities to work with a purpose. We are committed to supporting your success in both your professional and personal lives.

Position Overview

QinetiQ US is looking for a Security Control Assessor with cloudbased experience to support a dynamic DoD client in the Chantilly VA area. Candidates are expected to leverage their past experience and knowledge to help deliver superior support to a rapid prototyping office and should have experience in supporting various cloudbased platforms such as Amazon Web Services Azure Microsoft Google etc.

Responsibilities

  • Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality Integrity and Availability for the information on systems.
  • Ensure security assessments are completed for each IS.
  • Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR.
  • Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO.
  • Assess proposed changes to Information Systems their environment of operation and mission needs that could affect system authorization.
  • Serve as a cybersecurity technical advisor to the CISO and AO under their purview.
  • Be integral to the development of the monitoring strategy. The systemlevel continuous monitoring strategy must conform to all applicable published DoD enterpriselevel or DoD Componentlevel continuous monitoring strategies.
  • Determine and document in the SAR a risk level for every noncompliant security control in the system baseline.
  • Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCAs risk assessment considers threats vulnerabilities and potential impacts as well as existing and planned risk mitigation.
  • Develop a continuous monitoring plan specific to the information system.
  • Other duties as assigned.

Required Qualifications

  • Bachelors degree required
  • 10 years relevant experience
  • DOD 8140 IAM Level II (CAP CASP CISM CISSP GSLC CCISO) one of these certifications is required
  • Top Secret clearance with SCI eligibility is required #qinetiqclearedjob

Preferred Qualifications

  • Strong knowledge of Risk Management Framework (RMF) 80037 and continuous monitoring 800137
  • Expert knowledge and handson experience with FISMA Systems NIST 800series guidelines FIPS Security Assessment & Authorization (SA&A) requirements and processes Continuous Monitoring Framework experience and its tools Plan of Action & Milestones (POA&M) policies and vulnerability/patch management risk management project management proficient with Microsoft products Word Excel PowerPoint.
  • Proficient with vulnerability and scanning tools and wellversed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking and the Microsoft suite of office products
  • Experience in assessing cloudbased security authorizations (FedRamp AWS & Azure) as well as the NIST control responsibilities
  • Strong knowledge of CSAM
  • Expert with documenting and or reviewing security materials such as; system security plans (SSP) Security Assessment Report (SAR) Security Assessment Plan (SAP) and other documents per NIST 800 guidelines.
  • Experience supporting cloudbased security authorizations (FedRamp AWS & Azure)
  • Experience creating Security Assessment Plans Security Assessment Reports and Executivelevel briefings

Company EEO Statement

Accessibility/Accommodation:

If because of a medical condition or disability you need a reasonable accommodation for any part of the employment process please send an email to or callOpt. 4 and let us know the nature of your request and contact information.

QinetiQ US is an Equal Opportunity/Affirmative Action employer. All Qualified Applicants will receive equal consideration for employment without regard to race age color religion creed sex sexual orientation gender identity national origin disability or protected Veteran status.

Employment Type

Unclear

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.