Execute and/or lead advanced security assessments for client information systems
Apply deep technical and compliance expertise to evaluate, advise, and guide clients through FedRAMP, FISMA, and NIST RMF requirements
Lead technical discussions, mentor team members, and support secure cloud architecture and risk mitigation activities
Conduct comprehensive security assessments by analyzing cybersecurity documentation and performing evidence collection, interviews, and testing
Perform system and network vulnerability scanning and analysis using automated and manual techniques
Identify, recommend, and validate vulnerability remediation actions, fix procedures, and mitigation strategies
Prepare clear, accurate, and original reports, attestations, and customer-facing documentation
Work independently or as part of a client delivery team in a fast-paced, deadline-driven, remote environment
Requirements
Bachelor's Degree or 5+ years equivalent experience
3+ years of experience in performing and/or participating in FISMA based security Assessment and Authorization (A&A) activities
Must be a US Citizen and able to obtain an active SECRET Security Clearance
Strong technical background in security engineering, secure architecture, system and network security, authentication protocols, applied cryptography, and application security
Expert knowledge of Cloud Computing, FedRAMP, FISMA, NIST/DoD RMF, and NIST SP 800-series publications
Intermediate experience with testing and assessment tools such as Nessus/ACAS, SCC, DISA STIGs/STIG Viewer, NMAP, and Acunetix
Must hold one other advanced certification such as CISA, CISM, etc. in accordance with the A2LA R311
The candidate must have at least one industry certification from the following list: Cisco Certified Network Associate Security (CCNA Security).