Job Requirements
Remote
Public Trust Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
seeks a career and customer-oriented Information to join our team supporting a federal agency's Safeguards and Risk Management (SRM) mission. This is a fully position and only expected to be in the office in case of emergency or if requested/required by government.
- Categorizes systems (FIPS 199) in coordination with system owners, accounting for high-volume PII/NPI data aggregation risks inherent to organizational data.
- Build the control package: apply NIST SP 800-53 controls, develop the SSP, draft implementation statements, and collect evidence validating secure data ingestion and processing.
- Guide system owners on writing and resolving implementation statements.
- Drive controls to secure status and see them through testing, with emphasis on data integrity, encryption-in-transit (TLS), and Identity & Access Management (IAM).
- Partner closely with the Security Assessment Provider/SCA to ensure quality of artifacts and evidence to enable the assessment.
- Advise system owners on control prioritization, ensuring alignment with both NIST frameworks and financial regulatory data protection standards (e.g., FFIEC expectations).
- Support RMF & A&A: Cyber Risk Framework (CRF) input, Change Request Reviews, POA&M tracking, SA&A Project List, and SOPs/A&A artifacts on a best-effort basis.
- Hands-on experience with NIST RMF (800-30, 800-37, 800-53, and 800-53A) - practical implementation, not just familiarity.
- Demonstrated experience building control packages and drafting implementation statements.
- Experience in creating or supporting Security Assessment Plans and Security Assessment Reports.
- Experience with Q-Compliance (or the ability to ramp quickly).
- Experience interpreting data from vulnerability scanning tools (e.g., Tenable, Qualys) to identify risks in databases and file-processing pipelines.
- Understanding network architectures, including SaaS, IaaS, or PaaS environments; experience securing modern, cloud-native web platforms preferred.
- Technical background sufficient to collaborate with system owners on design documentation.
- SME-level knowledge of NIST SP 800-137 (ISCM).
- 1+ years of technical experience with Python, Java, or PHP - sufficient to read, interpret, and understand code to independently verify control implementation and evaluate technical alternate solutions for complex NIST requirements.
- 1+ year of experience with a GRC tool (such as CSAM).
- Experience with Q-Compliance and/or Q-Audit.
- Experience with API testing (REST APIs), JSON payload security, and/or scripting and automation.
- Relevant industry certifications (e.g., CISA, CAP, CISSP, Security+).
- Must be a U.S. Citizen with the ability to obtain and maintain a Public Trust clearance prior to starting this position.
- Must be able to remain in a stationary position 50% and constantly operate a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.
group id: RTX14564a