Job Requirements
Washington, DC
Clearance Unspecified Polygraph not specified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Location: Washington, DC (On-site)
We are seeking an experienced Senior Security Risk Management Subject Matter Expert (SME) to provide technical expertise in security risk management, Assessment and Authorization (A&A), Federal cybersecurity compliance, and continuous monitoring. The successful candidate will support cybersecurity risk management activities across secure cloud, hybrid, and cross-domain environments while ensuring compliance with applicable Federal and Intelligence Community (IC) cybersecurity requirements.
The ideal candidate will possess extensive experience applying risk management principles, implementing security controls, and supporting evolving cybersecurity practices, including the automation of Assessment and Authorization (A&A) and continuous monitoring activities.
Key Responsibilities
Provide subject matter expertise in security risk management and cybersecurity compliance activities.
Support Assessment and Authorization (A&A) efforts in accordance with Federal cybersecurity requirements.
Ensure compliance with the Federal Information Security Modernization Act (FISMA) and applicable Intelligence Community (IC) cybersecurity policies and standards.
Support continuous monitoring activities across enterprise environments.
Provide expertise in Cross Domain Solutions (CDS) security requirements.
Support secure cloud and hybrid engineering initiatives from a security risk management perspective.
Apply NIST Special Publication (SP) 800 Series guidance, CNSSI 1253 security controls, and Risk Management Framework (RMF) principles.
Support emerging cybersecurity risk management practices, including automation of A&A and continuous monitoring activities.
Collaborate with Government stakeholders to develop and implement effective security risk management strategies.
Minimum Qualifications
Minimum 10 years of related cybersecurity and security risk management experience.
At least 2 years of recent experience in each of the following:
Assessment and Authorization (A&A)
Federal Information Security Modernization Act (FISMA) compliance
Intelligence Community (IC) cybersecurity policy and standards
Continuous monitoring
Cross Domain Solutions (CDS)
Secure cloud and hybrid engineering
Demonstrated experience with emerging security risk management practices, including automation of A&A and continuous monitoring.
Experience applying NIST SP 800 Series guidance, CNSSI 1253 security controls, and Risk Management Framework (RMF) principles.
One of the following certifications, in good standing, or comparable demonstrable experience:
Certified Information Security Manager (CISM)
Certified Authorization Professional (CAP)
Governance, Risk, and Compliance (GRC) certification
Preferred Qualifications
Certifications in one or more cloud platforms, including:
Amazon Web Services (AWS)
Microsoft Azure
Microsoft Office 365
Current or prior experience supporting the U.S. Department of Homeland Security (DHS).
Demonstrated experience working within DHS organizations or supporting DHS cybersecurity risk management initiatives is highly preferred.
We are seeking an experienced Senior Security Risk Management Subject Matter Expert (SME) to provide technical expertise in security risk management, Assessment and Authorization (A&A), Federal cybersecurity compliance, and continuous monitoring. The successful candidate will support cybersecurity risk management activities across secure cloud, hybrid, and cross-domain environments while ensuring compliance with applicable Federal and Intelligence Community (IC) cybersecurity requirements.
The ideal candidate will possess extensive experience applying risk management principles, implementing security controls, and supporting evolving cybersecurity practices, including the automation of Assessment and Authorization (A&A) and continuous monitoring activities.
Key Responsibilities
Provide subject matter expertise in security risk management and cybersecurity compliance activities.
Support Assessment and Authorization (A&A) efforts in accordance with Federal cybersecurity requirements.
Ensure compliance with the Federal Information Security Modernization Act (FISMA) and applicable Intelligence Community (IC) cybersecurity policies and standards.
Support continuous monitoring activities across enterprise environments.
Provide expertise in Cross Domain Solutions (CDS) security requirements.
Support secure cloud and hybrid engineering initiatives from a security risk management perspective.
Apply NIST Special Publication (SP) 800 Series guidance, CNSSI 1253 security controls, and Risk Management Framework (RMF) principles.
Support emerging cybersecurity risk management practices, including automation of A&A and continuous monitoring activities.
Collaborate with Government stakeholders to develop and implement effective security risk management strategies.
Minimum Qualifications
Minimum 10 years of related cybersecurity and security risk management experience.
At least 2 years of recent experience in each of the following:
Assessment and Authorization (A&A)
Federal Information Security Modernization Act (FISMA) compliance
Intelligence Community (IC) cybersecurity policy and standards
Continuous monitoring
Cross Domain Solutions (CDS)
Secure cloud and hybrid engineering
Demonstrated experience with emerging security risk management practices, including automation of A&A and continuous monitoring.
Experience applying NIST SP 800 Series guidance, CNSSI 1253 security controls, and Risk Management Framework (RMF) principles.
One of the following certifications, in good standing, or comparable demonstrable experience:
Certified Information Security Manager (CISM)
Certified Authorization Professional (CAP)
Governance, Risk, and Compliance (GRC) certification
Preferred Qualifications
Certifications in one or more cloud platforms, including:
Amazon Web Services (AWS)
Microsoft Azure
Microsoft Office 365
Current or prior experience supporting the U.S. Department of Homeland Security (DHS).
Demonstrated experience working within DHS organizations or supporting DHS cybersecurity risk management initiatives is highly preferred.
group id: RTX199ddb