Please Note:
- This is 100% OnSite position.
- Selected candidate must be willing to work onsite in Woodlawn MD 5 days a week.
Position Description:
- The Subject Matter Expert (SME) will provide technical guidance for assessing the management operational assurance and technical security controls implemented on an information system via security testing and evaluation methods.
- The SME will provide guidance on improvement of policies and procedures to support the federal clients business processes for security assessment of Organizations.
- Provide technical advisory functions to staff.
- Provide administrative support for pre and postassessment activities.
- Provide continued modernization support for the Technical System Security Requirements (TSSR) and Security Evaluation Questionnaire (SEQ)
- Determine security controls effectiveness to ensure controls are implemented correctly operating as intended and meeting requirements.
- Provide Cloud technical assistance/data privacy technical assistance.
- Provide technical assistance with ensuring suite of controls are implemented and operating as intended.
Key Required Skills:
- Strong business documentation and technical writing skills;
- Must know NIST 80053 revision 5;
- How to assess cybersecurity control based on NIST 80053a R5;
- Strong experience working in Excel
Requirements
Basic Qualifications:
- Bachelors Degree and 3 years of relevant experience or masters degree and 1 year of relevant experience or 7years of relevant experience in lieu of a degree.
- 2 years of security control assessment experience
- Strong business documentation and technical writing skills.
- Must have strong experience working in Excel
- Must be able to obtain and maintain a Public Trust. Contract requirement.
Required Skills:
- Must possess a relevant cybersecurity certification (e.g. Security CISSP CISM or CAP)
- Experience with interpreting and applying federal laws OMB directives and clientspecific policies to security and compliance efforts.
- Experience with interpreting and assessing security controls using NIST SP 80053A Rev. 4 NIST SP 80053 Rev. 5 NIST SP 80037 Rev. 1 NIST SP 80030 Rev. 1 NIST SP 80039 and FIPS publications.
Desired Skills:
- Experience supporting Risk Management Framework (RMF) activities in accordance with NIST guidelines.
- Experience coordinating with the federal agency and partner agencies understanding and leveraging existing agreements.
- Experience producing and maintaining business and technical documentation related to the Risk Management Framework.
CyberSecurity, Security+, CISSP, CISM, CAP, NIST 800, RMF