Information System Security Consultant

Company: Northwest Software
Location: Falls Church , Virginia, United States
Type: Full-time
Posted: 11.JUN.2019

Summary

Note Candidates must be a US Citizen Candidates need Public Trust Clearance Looking specifically for the following three skillsets in additi...

Description

Note Candidates must be a US Citizen Candidates need Public Trust Clearance Looking specifically for the following three skillsets in addition to the responsibilities below. An ISSO with cloud expertise, the ability to teach is a bonus An ISSO with mobile experience, and cryptocurrencyblock chain experience An ISSO with Supervisory Control and Data Aquistion (SCADA), infrastructure protection, andor engineering experience Job Description Information System Security Consultant (Risk and Compliance) Works closely with Account Security Officer (ASO) and Segment Security Officers (SSO) to ensure operational security measures are implemented. Assesses and mitigates system security risks determines and analyzes security requirements for implementation and testing. Reviews and continuously monitors implemented security controls. Creates and maintains security checklists, templates and other tools to aid in the AA process. Performs security control assessment using NIST 800-53A guidance and as per continuous monitoring requirements. Performs risk analyses to determine and recommends essential safeguards. Proactively mitigates system vulnerabilities and recommends compensating controls. Prepares security authorization packages in accordance with the client contractual requirements. Develops core documents such as System Security Plan, Contingency Plan, Incident Response Plan, Standard Operating Procedures, Plan of Actions and Milestones, Remediation Plans, Configuration Management Plan, etc. Maintains client-specific Plan of Action and Milestones and supports remediation activities. Maintains an inventory of hardware and software for the information system. Develops, tests and trains on Contingency and Incident Response planning. Conducts independent scans of application, network and database and utilizes Managed Security Services Vulnerability Assessment Team (VAT) support as applicable. EXPERIENCE LEVEL 10+ years experience working in a risk management, audit, security or technical delivery role EDUCATION Bachelor or master degree in Computer Science, Computer Studies, Information Security (or equivalent combination of education and experience) CERTIFICATIONS (One or more required) CompTIA Security+ CE, OR Global Information Assurance Certification (GIAC) Security Essentials Certification (GSEC), OR ISC2 Systems Security Certified Practitioner (SSCP), OR Cisco Certified Network Associate (CCNA) Security and CISSP PREFERRED SKILLS - Fluent in English, grammer and communication. KNOWLEDGE AND SKILLS REQUIRED Ability to influence OCISO Delivery system stakeholders in the execution of security and compliance requirements Knowledge of the security countermeasures and overall RMF and NIST compliance Experience as a Security consultant in Risk and Compliance Experience in working with security mgt including information governance and compliance Good understanding of Assurance Practices and Risk Management, hands on experience Experience of security processes and standards, in particular NIST 800-series and RMF Knowledge of security audit and accreditation processes Ability to interpret request for proposal and respond to security and compliance requirements Knowledge of Federal Security, industry and market trends and HPEUSPS offerings Understands HPE and USPS solutions - what they consist of, product roadmaps, IT concepts Understands how cyber security GRC requirements fit within or interface with the sales of other solutions in HPE and HP's partner strategies Understands federal security and regulations impacting security requirements to develop strategies for supporting internal USPS operations Information System Security Works closely with Account Security Officer (ASO) and Segment Security Officers (SSO) to ensure operational security measures are implemented. Assesses and mitigates system security risks determines and analyzes security requirements for implementation and testing. Reviews and continuously monitors implemented security controls. .Please highlight your relevant experience with regards to job description. Risk Management,Audit 10+ years experience working in a risk management, audit, security or technical delivery role.Bachelor or master degree in Computer Science, Computer Studies, Information Security (or equivalent combination of education and experience).Good understanding of Assurance Practices and Risk Management, with hands on experience Experience of security processes and standards, in particular NIST 800-series and Risk Management Framework Cloud,Cryptocurrency Block Chain,SCADA An ISSO with cloud expertise, the ability to teach is a bonus An ISSO with mobile experience, and cryptocurrencyblock chain experience An ISSO with Supervisory Control and Data Aquistion (SCADA), infrastructure protection, andor engineering experience CISSP, CISMCISA or CRISC CISSP, CISMCISA or CRISC a plus

 
Apply Now

Share

Free eBook

Flash-bkgn
Loader2 Processing ...