Security Assessor

Emploi pas sur LinkedIn

🕒 il y a 8 mois

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟢 Junior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

SDLC

Splunk

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of DataLock Consulting Group

DataLock Consulting Group

11 - 50 employés

Fondée en 2013

💼 Conseil

🎖️ Défense

📦 Logistique

Consulting • Defense • Logistics

DataLock Consulting Group est une entreprise de conseil en cybersécurité qui se spécialise dans le développement de programmes de sécurité, la conformité, ainsi que dans l'architecture et l'ingénierie de la sécurité. Leur approche consiste à intégrer la cybersécurité dans les fondations des réseaux et des systèmes plutôt que de la traiter comme une simple réflexion après coup. Ils desservent divers secteurs, y compris le gouvernement, la finance, l'aérospatiale et la santé, offrant des services tels que la gestion des risques, les évaluations de sécurité et la sécurité du cloud.

Description

• Conduct security control assessments of the security and privacy controls implemented by an information system to determine the overall effectiveness of the controls • Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). • Perform quality control on the assessment and associated deliverables. • Participate as an individual contributor for complex system assessments. • Develop practical and risk-based approaches for security control implementation and vulnerability remediation. • Work closely with ISSOs (contractors and Government) and the technical team and ensure all appropriate A&A supporting documentation is provided prior to conducting the assessment. • Conduct Security Assessment Kickoff briefings and SAR briefings. • Analyze security control findings for information systems and applications to convey weaknesses. • Document security assessment results accurately; read, understand, and convey vulnerabilities found during the assessments. • Perform audits of each system and provide an authorization recommendation based on determination of risk to the customer.

🎯 Exigences

• 1+ years of experience performing security testing and/or security control assessments. • 1+ years of experience with developing and documenting the SAPs, and SARs. • 1+ years of experience utilizing NIST 800-53 and 800-53A. • Knowledge of the NIST Cybersecurity Framework, Risk Management Framework, FIPS, and other NIST A&A publications. • Experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan. • Knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions. • Knowledge and skills to perform and document the assessment. • Understanding of tools such as Nessus, Web Inspect, Db Protect and Splunk. • Familiar with the cloud environments (services/security) and FedRAMP A&A process. • Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally. • Effective technical writing and documentation processing skills.

🏖️ Avantages

• Remote Job • Competitive salary • Professional development opportunities

Postuler Maintenant

Emplois Similaires

🕒 il y a 9 mois

Trapp Technology

51 - 200

🔒 Cybersecurity

🤝 B2B

🏢 Entreprise

Cybersecurity Technician I specializing in SIEM operations for proactive alert investigation and incident response assistance. Investigating alerts and correlating events to determine potential security breaches.

🇺🇸 États-Unis – Télétravail

💵 $17 - $25 / heure

⏰ Temps Plein

🟢 Junior

🟡 Intermédiaire

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🚫👨‍🎓 Aucun diplôme requis

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security