Steampunk logo
SteampunkPosted 3 weeks ago

Cyber Risk Management Specialist

On-siteMcLean, Virginia, United States

Full TimeMedium

Job Summary

Integrate security into DevOps throughout the software development life cycle and identify vulnerabilities to create effective risk-based solutions. Develop tactical automation strategies to optimize IT infrastructure while implementing NIST SP 800-53 controls for cloud environments. Lead project teams in accrediting cloud products by applying FedRAMP regulations and supporting external audits, ATO processes, and continuous monitoring activities. Manage Plan of Action & Milestones for remediation tracking and coordinate with system owners and third-party assessment organizations. Ensure ongoing compliance through monthly deliverables, vulnerability scanning, penetration testing, and annual security assessments.

Required Qualifications

  • Ability to obtain a U.S. government Security Clearance
  • Master's Degree and 6 year of cyber and FISMA experience
  • Bachelor's Degree and 8 years of cyber and FISMA experience
  • No degree and 12 years of experience, 10 of which must be in cyber and FISMA
  • Possesses at least one professional certification: CISSP, CASP, CISA, CISM or GSLC
  • A solid grasp on confidentiality, integrity, and availability (CIA) security concepts
  • The ability to be flexible and adaptive to a fast-paced, fluid business environment

Desired Qualifications

  • Experience in FISMA, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security
  • Experience in Information Security processes to include RMF, FedRAMP, Compliance, Continuous Monitoring, and Annual Assessments
  • Certifications in one or more of the following: CISSP, CRICS, CCSP, CAP/CGRC
  • Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform and Infrastructure
  • Experience conducting assessments in a 3PAO, C3PAO, or risk auditing organization
  • Experience supporting systems in Agile environments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce