Selected candidate must be willing to work on-site in Woodlawn MD 5 days a week.
Selected candidate must be able to obtain and maintain a public trust clearance.
KEY REQUIRED SKILLS:
Working knowledge of NIST SPfraud prevention identity verification risk analysis cybersecurity financial crime or a related field.
POSITION DESCRIPTION:
Analyze documents and conduct intake and elicitation sessions with project teams.
Decompose applications or services into the analytical components required for impact assessment.
Conduct initial impact assessments and document the chain of reasoning supporting each determination.
Document each application or services impact assessment assurance level selections and any tailoring decisions.
Re-engage with project teams when service scope user populations transaction types or threat conditions change in ways that affect prior risk and determination.
Produce analytical written products risk assessments impact assessments security plan sections control assessment reports or equivalent.
Applying a normative framework (NIST SPor equivalent) to a specific service and producing a written analysis that shows the judgments made at each step.
Requirements
SKILL REQUIREMENTS:
BASIC QUALIFICATIONS:
Bachelors or higher degree in Computer Science Information Systems Cybersecurity Mathematics Statistics Philosophy Law Economics or a related analytical discipline.
Working knowledge of NIST SPespecially the base volume and the NIST Risk Management Framework (SP 800-37).
REQUIRED SKILLS:
Experience in fraud prevention identity verification risk analysis cybersecurity financial crime or a related field.
Direct experience conducting digital identity risk assessments under NIST SP 800-63 (Revision 3 or 4) for production online services
Experience following the below steps:
Analytical decomposition: Reliably breaks complex systems into the components required for the analysis.
Rubric application: Applies a written rating rubric to a specific case by identifying the rubric row that matches the case and recording the corresponding rating. Does not substitute personal judgment for the rubric where the rubric is determinative.
Categorical reasoning: Can determine whether an impact category applies to a given situation before rating its severity.
Source-and-direction tracking: Distinguishes information the system holds about a user from information the user provided to the system.
Elicitation: Obtains required information from stakeholders particularly when the information initially received is incomplete or conflicting.
Written precision: Produces clear analytical prose. Reasoning is traceable. Conclusions are tied to evidence.
Critical thinking: Evaluates information and arguments for soundness identifies unstated assumptions and distinguishes claims that are supported from those that are not.
Self-direction: Manages a queue of assessments without daily supervision and surfaces blockers early.
DESIRED SKILLS:
Professional certifications: CISSP CISA CIPP/G or equivalent would be a plus.
Strong attention to detail and organizational skills.
Proficiency with Microsoft Excel and standard business applications.
Ability to manage multiple priorities in a fast-paced environment while maintaining accuracy.
Required Skills:
Experience in fraud prevention identity verification risk analysis cybersecurity financial crime or a related field. Direct experience conducting digital identity risk assessments under NIST SP 800-63 (Revision 3 or 4) for production online services Experience following the below steps: Analytical decomposition: Reliably breaks complex systems into the components required for the analysis. Rubric application: Applies a written rating rubric to a specific case by identifying the rubric row that matches the case and recording the corresponding rating. Does not substitute personal judgment for the rubric where the rubric is determinative. Categorical reasoning: Can determine whether an impact category applies to a given situation before rating its severity. Source-and-direction tracking: Distinguishes information the system holds about a user from information the user provided to the system. Elicitation: Obtains required information from stakeholders particularly when the information initially received is incomplete or conflicting. Written precision: Produces clear analytical prose. Reasoning is traceable. Conclusions are tied to evidence. Critical thinking: Evaluates information and arguments for soundness identifies unstated assumptions and distinguishes claims that are supported from those that are not. Self-direction: Manages a queue of assessments without daily supervision and surfaces blockers early.
Required Education:
Bachelors or higher degree in Computer Science Information Systems Cybersecurity Mathematics Statistics Philosophy Law Economics or a related analytical knowledge of NIST SPespecially the base volume and the NIST Risk Management Framework (SP 800-37).
PLEASE NOTE: It is a 100% Onsite position.Selected candidate must be willing to work on-site in Woodlawn MD 5 days a week.Selected candidate must be able to obtain and maintain a public trust clearance.KEY REQUIRED SKILLS:Working knowledge of NIST SPfraud prevention identity verification risk analys...
PLEASE NOTE:
It is a 100% Onsite position.
Selected candidate must be willing to work on-site in Woodlawn MD 5 days a week.
Selected candidate must be able to obtain and maintain a public trust clearance.
KEY REQUIRED SKILLS:
Working knowledge of NIST SPfraud prevention identity verification risk analysis cybersecurity financial crime or a related field.
POSITION DESCRIPTION:
Analyze documents and conduct intake and elicitation sessions with project teams.
Decompose applications or services into the analytical components required for impact assessment.
Conduct initial impact assessments and document the chain of reasoning supporting each determination.
Document each application or services impact assessment assurance level selections and any tailoring decisions.
Re-engage with project teams when service scope user populations transaction types or threat conditions change in ways that affect prior risk and determination.
Produce analytical written products risk assessments impact assessments security plan sections control assessment reports or equivalent.
Applying a normative framework (NIST SPor equivalent) to a specific service and producing a written analysis that shows the judgments made at each step.
Requirements
SKILL REQUIREMENTS:
BASIC QUALIFICATIONS:
Bachelors or higher degree in Computer Science Information Systems Cybersecurity Mathematics Statistics Philosophy Law Economics or a related analytical discipline.
Working knowledge of NIST SPespecially the base volume and the NIST Risk Management Framework (SP 800-37).
REQUIRED SKILLS:
Experience in fraud prevention identity verification risk analysis cybersecurity financial crime or a related field.
Direct experience conducting digital identity risk assessments under NIST SP 800-63 (Revision 3 or 4) for production online services
Experience following the below steps:
Analytical decomposition: Reliably breaks complex systems into the components required for the analysis.
Rubric application: Applies a written rating rubric to a specific case by identifying the rubric row that matches the case and recording the corresponding rating. Does not substitute personal judgment for the rubric where the rubric is determinative.
Categorical reasoning: Can determine whether an impact category applies to a given situation before rating its severity.
Source-and-direction tracking: Distinguishes information the system holds about a user from information the user provided to the system.
Elicitation: Obtains required information from stakeholders particularly when the information initially received is incomplete or conflicting.
Written precision: Produces clear analytical prose. Reasoning is traceable. Conclusions are tied to evidence.
Critical thinking: Evaluates information and arguments for soundness identifies unstated assumptions and distinguishes claims that are supported from those that are not.
Self-direction: Manages a queue of assessments without daily supervision and surfaces blockers early.
DESIRED SKILLS:
Professional certifications: CISSP CISA CIPP/G or equivalent would be a plus.
Strong attention to detail and organizational skills.
Proficiency with Microsoft Excel and standard business applications.
Ability to manage multiple priorities in a fast-paced environment while maintaining accuracy.
Required Skills:
Experience in fraud prevention identity verification risk analysis cybersecurity financial crime or a related field. Direct experience conducting digital identity risk assessments under NIST SP 800-63 (Revision 3 or 4) for production online services Experience following the below steps: Analytical decomposition: Reliably breaks complex systems into the components required for the analysis. Rubric application: Applies a written rating rubric to a specific case by identifying the rubric row that matches the case and recording the corresponding rating. Does not substitute personal judgment for the rubric where the rubric is determinative. Categorical reasoning: Can determine whether an impact category applies to a given situation before rating its severity. Source-and-direction tracking: Distinguishes information the system holds about a user from information the user provided to the system. Elicitation: Obtains required information from stakeholders particularly when the information initially received is incomplete or conflicting. Written precision: Produces clear analytical prose. Reasoning is traceable. Conclusions are tied to evidence. Critical thinking: Evaluates information and arguments for soundness identifies unstated assumptions and distinguishes claims that are supported from those that are not. Self-direction: Manages a queue of assessments without daily supervision and surfaces blockers early.
Required Education:
Bachelors or higher degree in Computer Science Information Systems Cybersecurity Mathematics Statistics Philosophy Law Economics or a related analytical knowledge of NIST SPespecially the base volume and the NIST Risk Management Framework (SP 800-37).