Systems Analyst - ICR
Job Description
Candidate is to assist the Certification and Accreditation (C&A) Program Manger (PM) with the completion of our client’s Internal Control Reviews (ICR) project for a number of General Support Systems (GSS) and Major Applications (MA). Candidate might be in charge of junior security engineers, as needed, with potential of them being located in the DC and/or Denver, CO area. The candidate is responsible for utilizing guidance provided by our client and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-26 Security
S
elf- Assessment
Guide
for
I
nformati
on
Technolo
gy
Systems, and NIST SP 800-53A,
Guide for Assessing the Security Controls in Federal Information Systems
, as it relates to ICRs. The candidate will be responsible for conducting independent validation and verification tests of selected NIST SP 800-53 controls, and guide junior personnel in the interview process and evaluation of GSS and MA security maturity levels (L1-L5) per NIST SP 800-53a. Performs in a professional position requiring a high level or knowledge in Information System (IS) architecture, IS security, and experience in the C&A process to succeed in the environment.
The candidate will assess and document the security posture of a system through interviews, document validation, and security control testing. Assessment processes and procedures have been outlined. The candidate must be able to follow guidance provided, provide leadership to the team that they will be in charge of, have good speaking, writing, and interviewing skills; be able to work both independently.
Required Qualifications:
·
Expert knowledge and understanding of NIST SP 800 series documentations; specifically, but not limited to: 800-53 Rev 2, -53a Rev 2, -37, -60 and FIPS 199.
·
CISSP or CISA (DIACAP and expert knowledge in 8500 requirements may be acceptable based on experience).
·
Knowledge of Information Technology (IT) and IS including servers, networking, computer security, and LAN/WAN
·
Excellent writing skills, including the ability to summarize technical information and concepts in a clear and easy-to-understand manner, and fluent in English.
·
Strong oral communication skills, including the ability to interact and communicate with all levels of managers and personnel in a professional and tactful manner
·
Proficiency with MS Office products (Work, Excel, etc)
·
U.S. citizen
·
Must be able to pass a background check
Preferable (not required):
·
BA/BS from an accredited university/college (or equivalent military or work experience)
·
Certification and Accreditation Professional (CAP) certificate
·
Knowledge of Federal IT security standards: FISMA and OMB
Travel:
Some required
|