Crest Security Assurance ยท 9 hours ago
SME Information Security Analyst with Security Clearance
Maximize your interview chances
Security
No H1BSecurity Clearance Required
Insider Connection @Crest Security Assurance
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Responsible for leading the RMF assessment, authorization, and monitoring steps for systems following NIST and ICD 503 standards and best practices
Maintain ongoing knowledge of Federal policies and practices related to cyber security
Perform Continuous monitoring to facilitate ongoing awareness of threats, vulnerabilities, and information security to support risk management decisions
Activities include vulnerability analysis and management, POA&M management, security impact reviews of change requests, annual assessments and reporting for Information Security Vulnerability Management (ISVM)
Provide continued access to security-related information allowing the Government to make more effective and timely risk management decisions, including ongoing security authorization decisions
Experience with supporting CONMON efforts for Cloud Systems and CI/CD Pipelines
Monitor the evolving RMF guidance and adapt vulnerability management processes and procedures as necessary to maintain compliance in accordance with the FISMA and the evolution of the FISMA scorecard
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
10+ years of proven experience performing security controls
Active clearance up to TS/SCI security clearance
Possess excellent verbal and written communication skills
Strong architecture, network and infrastructure security, or next gen security expertise (agile/hybrid agile, cloud)
Extensive experience working with various security methodologies and processes, compliance controls related to cloud security, performing assessments in cloud computing environment
Extensive experience providing analysis and trending of vulnerability data from a large number of heterogeneous devices
Must possess expert knowledge in risk and vulnerability management
Preferred
Knowledge, skills, abilities, and experience with common assessment & authorization (A&A) application platforms (e.g. eMASS, CSAM, Xacta is preferred)