Computer Security Systems Specialist Level III
Computer World Services (CWS)Corporation

Atlanta, Georgia


Job Description

The Computer Security Systems Specialist Level III contractor will assist the OFR in refining and implementing the processes and methodologies to assess internal and external/third-party systems, and provide an accurate accounting and tracking for shortcomings and weaknesses. The weaknesses will be tracked, monitored and reported in Plans of Action and Milestones (POA&Ms). Findings discovered through risk assessments, Security Controls Assessments (SCA) and continuous monitoring activities will be collected, analyzed and used to provide continuous reporting and support informed, risk-based decision making.

In addition to the personnel required to directly perform the subtasks listed in this section, the Contractor may provide Subtask support. Each Subtask support will provide effective implementation of their assigned subtask.

Responsibilities include but are not limited to:
* Serving as the principal liaison between the OFR and supporting personnel for the specific subtask area (e.g., Security Controls Assessors, ISSOs, Continuous Monitoring);
* Ensuring OFR goals are communicated to the task area supporting personnel;
* Providing guidance, support, and supervision to the subtask area supporting personnel;
* Ensuring supporting personnel are properly prioritizing tasks and responsibilities;
* Ensuring proper allocation of tasks among supporting personnel, as applicable;
* Ensuring proper scheduling of tasks among supporting personnel, as applicable;
* Providing the final quality verification/validation of deliverables prior to submission to the OFR; and ensuring compliance with OFR timelines and deadlines for deliverables and associated subtask completion dates.

Key Tasks and Responsibilities

* Using the NIST Risk Management Framework (RMF) to conduct assessments of Information security controls in order to measure the effectiveness of controls and identify control gaps
* Ensure compliance to guidance, standards and regulations such as NIST Special Publications, FIPS, FedRAMP, and other federal regulations and policies
* Preparing Security Impact Assessments, Addendums, Security Authorization Packages and including documentation such as Authorization Official Out-briefs, Security Authorization Recommendations and Security Authorizations Memorandums

* Identify, assess, and prioritize identified risks
* Collect evidence, artifacts, and document findings to support conclusions
* Report on compliance with internal policies, controls, and standards Provide recommendations for remediation of identified deficiencies
* Track and report on Plans of Action and Milestones (POAMs) (i.e., findings/deficiencies to closure)
* Coordinate third-party risk assessments and IT audits
* Manage remediation efforts and report on the status of control deficiencies
* Support security initiatives and global policy adherence and awareness efforts
* Support global information security metrics and reporting program(s)
* Provide security expertise to business units and key stakeholders
* Enforce policy adherence and manage formal policy exception requests
* Provide timely status updates/reporting on assessments and assigned projects



Education & Experience

* A Bachelor degree in Computer Science or a related engineering field with training in information security
* 10+ years' experience in Information Security
* 5+ years' experience building and managing Windows server platforms
* Thorough knowledge of NIST 800 Special Publications, Federal Information Processing
* Standards (FIPS) and other significant federal regulations
* Expertise the NIST Risk Management Framework to generate and maintain SA&A documentation to include System Security Plans, Security Assessments Reports, and Risk Assessments for internal and cloud-based systems (ie., FedRAMP)
* Thorough knowledge of federal laws and directives pertaining to information security
* Experience using security scanners (e.g. Nessus, Nexpose, etc) and remediating vulnerabilities
* Experience in creating and maintaining minimum security configuration baselines for Windows and Linux platforms and applications (i.e., Minimum Benchmarks: CIS, STIGS)
* Experience reviewing system logs for potential intrusions and policy violations.
* Experience using Forescout, Bigfix, and RES a plus

Certifications

  • CISSP
  • CISM

Security Clearance

* Must be able to obtain a Public Trust High
* Must be a US citizen or Lawfully Permanent Resident (LPR)

Other (Travel, Work Environment, DoD 8570 Requirements, Administrative Notes, etc.)

  • D.C. or Remote



Get Hired Faster

Subscribe to job alerts and upload your resume!

*By registering with our site, you agree to our
Terms and Privacy Policy.

More IT jobs


SoftChoice
Seattle, Washington
Posted 42 minutes ago
SoftChoice
La Jolla, California
Posted 42 minutes ago
SoftChoice
San Francisco, California
Posted 42 minutes ago
View IT jobs ยป

Share diversity job

Computer Security Systems Specialist Level III is posted on all sites within our Diversity Job Network.


African American Job Search Logo
Hispanic Inclusion Jobs Logo
Asian Job Search Logo
Women Inclusion Jobs Logo
Diversity Inclusion Jobs Logo
Seniors to Work Logo
Black Inclusion Jobs Logo
Veteran Job Center Logo
LGBT Job Search Logo
Asian Inclusion Jobs Logo
Disabled Job Seekers Logo
Senior Inclusion Jobs Logo
Disability Inclusion Jobs Logo
US Diversity Job Search Logo
LGBTQ Inclusion Jobs Logo
Hispanic Job Exchange Logo