Seeking an experienced
Lead Consultant with strong technical expertise and the leadership skills necessary to develop the assessment strategy manage the technical risk assessment team and ensure consistent high-quality execution across all counties.
The DHHS Privacy & Security Office is launching a large-scale cybersecurity initiative involving technical security risk assessments and penetration testing across 100 counties. This initiative covers county IT infrastructure including servers desktops networks firewalls user access provisioning MFA VPNs security hardening procedures vulnerability management and patch management processes. The Technical Security Risk Assessment & Penetration Testing Lead Consultant will be responsible for designing and conducting technical security assessments performing penetration testing activities creating standardized methodologies and templates and managing the assessment team s assignments and project timelines. The consultant will also provide clear non-technical communication of complex security topics to business leaders CMS and stakeholders.
Required/Desired Skills
| Skill | Required /Desired | Amount | of Experience |
|---|
| Experience in cybersecurity risk assessments and penetration testing. | Required | 7 | Years |
| Lead and perform technical security risk assessments on county IT environments (servers desktops networks firewalls IAM MFA VPNs patching pro | Required | 5 | Years |
| Conduct internal/external penetration testing vulnerability identification and exploit validation | Required | 7 | Years |
| Develop a repeatable assessment methodology templates testing procedures and reporting formats for use across 100 counties. | Required | 5 | Years |
| Manage and coordinate assessment team workloads assignments schedules and deliverables. | Required | 7 | Years |
| Create and maintain project plans timelines and progress reports. | Required | 7 | Years |
| Familiarity with NIST CIS Controls ISO 27001 and related frameworks. | Required | 3 | Years |
Questions
| No. | Question |
|---|
| Question1 | Absences greater than two weeks MUST be approved by CAI management in advance and contact information must be provided to CAI so that the resource can be reached during his or her absence. The Client has the right to dismiss the resource if he or she does not return to work by the agreed upon date. Do you agree to this requirement |
| Question2 | What is your candidates email address |
| Question3 | How soon can your candidate start if selected for this opportunity |
| Question4 | Candidates submitted above the hourly Vendor Rate of $140 may not be considered for this assignment. Do you agree to this requirement |
| Question5 | Have you thoroughly validated and attest to the accuracy of the credentials listed throughout your candidate s VectorVMS profile and resume pursuant to Section 5.2.5 of ITS-009440 |
Seeking an experienced Lead Consultant with strong technical expertise and the leadership skills necessary to develop the assessment strategy manage the technical risk assessment team and ensure consistent high-quality execution across all counties.The DHHS Privacy & Security Office is launching a l...
Seeking an experienced
Lead Consultant with strong technical expertise and the leadership skills necessary to develop the assessment strategy manage the technical risk assessment team and ensure consistent high-quality execution across all counties.
The DHHS Privacy & Security Office is launching a large-scale cybersecurity initiative involving technical security risk assessments and penetration testing across 100 counties. This initiative covers county IT infrastructure including servers desktops networks firewalls user access provisioning MFA VPNs security hardening procedures vulnerability management and patch management processes. The Technical Security Risk Assessment & Penetration Testing Lead Consultant will be responsible for designing and conducting technical security assessments performing penetration testing activities creating standardized methodologies and templates and managing the assessment team s assignments and project timelines. The consultant will also provide clear non-technical communication of complex security topics to business leaders CMS and stakeholders.
Required/Desired Skills
| Skill | Required /Desired | Amount | of Experience |
|---|
| Experience in cybersecurity risk assessments and penetration testing. | Required | 7 | Years |
| Lead and perform technical security risk assessments on county IT environments (servers desktops networks firewalls IAM MFA VPNs patching pro | Required | 5 | Years |
| Conduct internal/external penetration testing vulnerability identification and exploit validation | Required | 7 | Years |
| Develop a repeatable assessment methodology templates testing procedures and reporting formats for use across 100 counties. | Required | 5 | Years |
| Manage and coordinate assessment team workloads assignments schedules and deliverables. | Required | 7 | Years |
| Create and maintain project plans timelines and progress reports. | Required | 7 | Years |
| Familiarity with NIST CIS Controls ISO 27001 and related frameworks. | Required | 3 | Years |
Questions
| No. | Question |
|---|
| Question1 | Absences greater than two weeks MUST be approved by CAI management in advance and contact information must be provided to CAI so that the resource can be reached during his or her absence. The Client has the right to dismiss the resource if he or she does not return to work by the agreed upon date. Do you agree to this requirement |
| Question2 | What is your candidates email address |
| Question3 | How soon can your candidate start if selected for this opportunity |
| Question4 | Candidates submitted above the hourly Vendor Rate of $140 may not be considered for this assignment. Do you agree to this requirement |
| Question5 | Have you thoroughly validated and attest to the accuracy of the credentials listed throughout your candidate s VectorVMS profile and resume pursuant to Section 5.2.5 of ITS-009440 |
View more
View less