DataLock Consulting Group · 2 months ago
Security Assessor
DataLock Consulting Group is a technology company seeking a Security Assessor to conduct security control assessments and audits of information systems. The role involves verifying security controls, documenting assessments, and ensuring compliance with established frameworks.
ComplianceConsultingCyber SecurityInformation TechnologySecurityTraining
Responsibilities
Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs)
Develop associated schedules and resource plans to complete the assessments
Perform quality control on the assessment and associated deliverables
Participate as an individual contributor for complex system assessments
Develop practical and risk-based approaches for security control implementation and vulnerability remediation
Work closely with ISSOs (contractors and Government) and the technical team and ensure all appropriate A&A supporting documentation is provided prior to conducting the assessment
Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization
Conduct Security Assessment Kickoff briefings and SAR briefings
Review cyber/system/network security body of evidence and documentation for accuracy and completeness
Conduct security controls assessment of applicable security controls and privacy controls; assess implemented security controls and provide assurance that they are operating as intended
Analyze security control findings for information systems and applications to convey weaknesses
Document security assessment results accurately; read, understand, and convey vulnerabilities found during the assessments
Create security assessment results and document recommendations in a SAR for remediations and security control measures
Perform audits of each system and provide an authorization recommendation based on determination of risk to the customer
Audits will include unprivileged and privileged scans against each applicable system
Audits will include unprivileged and privileged database scans against each applicable database management system (DBMS)
Conduct Post Assessment Meetings with the customer
Provide Plan of Action and Milestones (POA&M) support to ensure mitigations are completed or the teams are working to mitigate all vulnerabilities in a timely fashion and within customer policy timelines
Develop and maintain a schedule for conducting reoccurring Continuous Monitoring and/or ongoing CDM efforts once the initial assessments are complete
Perform continuous monitoring to ensure implemented security controls remain functional throughout the lifecycle of the information system
Qualification
Required
1+ years of experience performing security testing and/or security control assessments
1+ years of experience with developing and documenting the SAPs, and SARs
1+ years of experience utilizing NIST 800-53 and 800-53A
Knowledge of the NIST Cybersecurity Framework, Risk Management Framework, FIPS, and other NIST A&A publications
Experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan
Knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions
Knowledge and skills to perform and document the assessment
Understanding of tools such as Nessus, Web Inspect, Db Protect and Splunk
Familiar with the cloud environments (services/security) and FedRAMP A&A process
Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally
Effective technical writing and documentation processing skills
BS/BA degree in Information Technology or related cyber/cyber-security field
Must possess one of the following certifications: Cisco Certified Network Associate Security (CCNA Security), Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops), Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Systems and Network Auditor (GSNA), GIAC Certified Intrusion Analyst (GCIA), Certified Information Systems Auditor (CISA), Certified Information System Security Professional or Associate (CISSP or Associate), Certified Secure Software Lifecycle Professional (CSSLP), Certified Information Systems Security Officer (CISSO), CyberSec First Responder (CFR), CompTIA Advanced Security Practitioner Continuing Education (CASP+) Continuing Education (CE), CompTIA Cloud+ (Cloud+), Global Industrial Cyber Security Professional (GICSP), Securing Cisco® Networks with Threat Detection Analysis (SCYBER), All professional certifications and CPE credits must be up to date
Preferred
BCR Cyber Technical Proficiency Testing Activity (highly preferred)