Employment Type : Full-Time
Sr. Security Control Assessor
Consultant Full-Time
APPLY
Perform Security Assessments (SAs). Although the primary emphasis for this task is for the contractor to complete System
Security Authorization (SSA) activities, this task will provide a vehicle to perform any type of related assessment and reporting needed by FSA that is not identified by other awarded tasks. Other related assessments include but are not limited to Ongoing Security Authorization (OSA) assessments, Private Collection Agency (PCA) security authorizations,
Self-Assessments, Security Impact Analysis (SIA), System Retirement/Data Disposal Assessments, Partial SSA assessments, and special interest security assessments deemed necessary by FSA Management. These SA activities will
requirement preparation services which will include security architecture, security engineering and continuous monitoring planning.
Scanning, Penetration Testing & Analysis Support. Contractor shall provide support for Red Team Services, as well as Vulnerability Scanning and Analysis, Web Application Surveillance and Penetration Testing Tools to perform the services
as part of the Security Assessment (Task 1) requirements in SSA, OSA and SIA activities.
DUTIES AND RESPONSIBILITIES:
provide feedback on performance/deliverables.
compliance with the NIST SP 800-53 Rev. 4, NIST 800-37 Rev.1, and agency-
specific requirements.
support system security configurations and implementation.
perform the security assessment activities. Responsible for assisting in the
presentation of the vulnerability findings to the client.
as Nessus, HP WebInspect, QualysGuard, AppDetective, and Burp Suite.
which the candidate is responsible for leading. Develop Project Schedules, Security Assessment Plans(SAPs), Security Assessment Reports (SARs), Plan of Action and Milestone (POA&M)
Reports, and Executive-Level briefings.
REQUIRED SKILLS:
Technology and/or Cybersecurity.
NIST SP 800-53 Rev. 4, NIST SP 800-53A Rev. 4, and NIST 800-37 Rev.1.
(e.g. network firewalls, WAFs, VPNs, etc.) and the current state of Information
Security, and be able to interpret the requirements of relevant governing
bodies (NIST, OMB, GAO, etc).
QualysGuard, Nessus).
configuration checklists (e.g., DISA STIGs, CIS Benchmarks).
within in the Continental US.
DESIRED SKILLS:
Cybersecurity related field preferred, however not required).
assessments using tools such as Nessus, HP WebInspect, AppDetective, BurpSuite,
and QualysGuard.
Continuous Diagnostics and Mitigation (CDM) program and requirements. Cloud security certification (e.g. CCSK, AWS).
Experience working in CSAM.
ESSENTIAL FUNCTIONS:
Physical Requirements:
Work Environment:
degree of teamwork and cooperation with other members of the staff as well as
individuals across the Company and Customers.
Equipment & Machines:
Printers, Telephone, and other miscellaneous office equipment.
Attendance:
workweek, normally Monday through Friday. However, times and days may vary
depending on business requirements. Needs to be available to work overtime
during critical peaks and be available to meet last minute requests for
overtime should the situation occur.
Other Essential Functions:
impose a safety risk/hazard to the employee or others. Must put forward a
professional behavior that enhances productivity and promotes teamwork and cooperation. Must be able to interface with individuals at
all levels of the organization both verbally and in writing. Must be
well-organized with the ability to coordinate and prioritize.
Sr. Security Control Assessor
Consultant Full-Time
APPLY
Perform Security Assessments (SAs). Although the primary emphasis for this task is for the contractor to complete System
Security Authorization (SSA) activities, this task will provide a vehicle to perform any type of related assessment and reporting needed by FSA that is not identified by other awarded tasks. Other related assessments include but are not limited to Ongoing Security Authorization (OSA) assessments, Private Collection Agency (PCA) security authorizations,
Self-Assessments, Security Impact Analysis (SIA), System Retirement/Data Disposal Assessments, Partial SSA assessments, and special interest security assessments deemed necessary by FSA Management. These SA activities will
requirement preparation services which will include security architecture, security engineering and continuous monitoring planning.
Scanning, Penetration Testing & Analysis Support. Contractor shall provide support for Red Team Services, as well as Vulnerability Scanning and Analysis, Web Application Surveillance and Penetration Testing Tools to perform the services
as part of the Security Assessment (Task 1) requirements in SSA, OSA and SIA activities.
DUTIES AND RESPONSIBILITIES:
provide feedback on performance/deliverables.
compliance with the NIST SP 800-53 Rev. 4, NIST 800-37 Rev.1, and agency-
specific requirements.
support system security configurations and implementation.
perform the security assessment activities. Responsible for assisting in the
presentation of the vulnerability findings to the client.
as Nessus, HP WebInspect, QualysGuard, AppDetective, and Burp Suite.
which the candidate is responsible for leading. Develop Project Schedules, Security Assessment Plans(SAPs), Security Assessment Reports (SARs), Plan of Action and Milestone (POA&M)
Reports, and Executive-Level briefings.
REQUIRED SKILLS:
Technology and/or Cybersecurity.
NIST SP 800-53 Rev. 4, NIST SP 800-53A Rev. 4, and NIST 800-37 Rev.1.
(e.g. network firewalls, WAFs, VPNs, etc.) and the current state of Information
Security, and be able to interpret the requirements of relevant governing
bodies (NIST, OMB, GAO, etc).
QualysGuard, Nessus).
configuration checklists (e.g., DISA STIGs, CIS Benchmarks).
within in the Continental US.
DESIRED SKILLS:
Cybersecurity related field preferred, however not required).
assessments using tools such as Nessus, HP WebInspect, AppDetective, BurpSuite,
and QualysGuard.
Continuous Diagnostics and Mitigation (CDM) program and requirements. Cloud security certification (e.g. CCSK, AWS).
Experience working in CSAM.
ESSENTIAL FUNCTIONS:
Physical Requirements:
Work Environment:
degree of teamwork and cooperation with other members of the staff as well as
individuals across the Company and Customers.
Equipment & Machines:
Printers, Telephone, and other miscellaneous office equipment.
Attendance:
workweek, normally Monday through Friday. However, times and days may vary
depending on business requirements. Needs to be available to work overtime
during critical peaks and be available to meet last minute requests for
overtime should the situation occur.
Other Essential Functions:
impose a safety risk/hazard to the employee or others. Must put forward a
professional behavior that enhances productivity and promotes teamwork and cooperation. Must be able to interface with individuals at
all levels of the organization both verbally and in writing. Must be
well-organized with the ability to coordinate and prioritize.
Enlightened, Inc. is an Equal Opportunity and Affirmative Action employer. All qualified candidates will receive consideration for employment without regard to race, ethnicity, gender, veteran status, or on the basis of disability or any other federal, state or local protected class.
XJ6