The Information Security Risk Specialist will assist technical leaders in discovering cyber risks, understanding applicable policies, and developing a mitigation plan. The role involves assessing the threat landscape, guiding clients through the Risk Management Framework (RMF) and Authority to Operate (ATO) process, and translating security concepts into actionable plans.
Requirements
- 2+ years of experience with program control and governance, system security lifecycle management, authorization, POA&Ms, vulnerability remediation, privacy, Information Systems Security Engineer (ISSE) support, and threat modeling
- 2+ years of experience preparing system accreditation documentation required by the Navy or DoD and assessing system vulnerability using approved DoD tools
- 2+ years of experience guiding a client through the entire Risk Management Framework (RMF) and Authority to Operate (ATO) process
- Knowledge of policy management support, change management, cybersecurity engineering, requirements, and cybersecurity tools development
- Knowledge of cybersecurity monitoring standards and enterprise security requirements or standards such as FIPS, NIST, Executive Orders, Notices, and Memoranda
- Top Secret clearance
- HS diploma or GED
- Industry certification such as CISSP or CompTIA Security+ Certification
Benefits
- Health benefits
- Life insurance
- Disability benefits
- Financial benefits
- Retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Dependent care
- Recognition awards