Security Assessor with Security Clearance

Bethesda, Maryland

Marathon TS Inc
Job Expired - Click here to search for similar jobs
Security Assessor Fully Remote / Prefer DC Metro Area Marathon TS has an immediate need for a Security Assessor specializing in the FedRAMP risk management framework to join our team in support of our Commercial Cybersecurity Practice, remote location available. Candidates must be US Citizens and eligible for a clearance to be considered for this position. Ideal candidates for this position are leaders in the FedRAMP/NIST Assessment space who bring deep knowledge of client engagement and development, and practice management, using your strong experience with FedRAMP and NIST risk management framework you will support and lead teams to perform assessments for cloud computing technologies in meeting federal compliance. As a an Assessor on the team, you will be responsible for supporting client engagements, assigning work, reviewing team contributions, and assuring quality reports are provided. Responsibilities include: Review of CSP documentation and provide recommendations Able to fill role as Penetration Tester Work with CSP and track progress of tasks/assignments Provide first level review of Associate work papers Provide system security consultation within cloud-based and on-premise environments in accordance with NIST, OMB, and other security regulatory frameworks Assist in developing all system security and compliance documentation (ex. SSP, ISCP, IRP, FIPS-199, CMP, diagrams, policies and procedures) Prepare, review, and/or update, and maintain IT security supporting artifacts Assist in developing all system assessment documentation (ex. SAP, SAR, RET, SRTM) Provide clients security and compliance guidance Identify problems, issues, challenges within client systems and conduct research to develop technical and conceptual solutions Perform responsibilities of Associate when Associate is not available Build a customer-focused relationship with client(s). Collaborate across multiple internal teams to ensure successful delivery of results based on scope of work. Establish standards and procedures to minimize risks. Minimum Requirements: Bachelor's degree (4-yr college or university) or equivalent combination of education and experience 2-5 years of experience in either auditing or consulting FedRAMP and NIST experience (in order of preference): FedRAMP, NIST SP 800-53, RMF, FISMA, NIST SP 800-171 /CMMC Strong written and verbal communication skills including the ability to explain technical matters to non-technical audiences. Broad based IT background with a technical understanding of networks, protocols, security configurations, cryptography, identity and access management, and the systems development life cycle. Excellent communication skills, both written and verbal with strong presentation skills. Ability to interact with clients and represent the company in a professional manner. Ability to successfully manage multiple tasks. Serve as a mentor to Associate Security Consultants and Security Consultants on best practices. Team player able to work well with others in a collaborative manner and is a self-starter who can work with minimum supervision. Work to continually build and improve solid and well-rounded practices and processes Certification Requirements: One of the following: Cisco Certified Network Associate Security (CCNA Security) Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops) Cybersecurity Analyst (CySA) GIAC Certified Incident Handler (GCIH) GIAC Systems and Network Auditor (GSNA) GIAC Certified Intrusion Analyst (GCIA) Certified Information Systems Auditor (CISA) Certified Information System Security Professional or Associate (CISSP or Associate) Certified Secure Software Lifecycle Professional (CSSLP) Certified Information Systems Security Officer (CISSO) CyberSec First Responder (CFR) CompTIA Advanced Security Practitioner Continuing Education (CASP) Continuing Education (CE) CompTIA Cloud (Cloud) Global Industrial Cyber Security Professional (GICSP) Securing Cisco Networks with Threat Detection Analysis (SCYBER) Marathon TS is committed to the development of a creative, diverse and inclusive work environment. In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Marathon TS will be based on merit, qualifications, and abilities. Marathon TS does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age or any other characteristic protected by law (referred to as "protected status ").
Date Posted: 01 May 2024
Job Expired - Click here to search for similar jobs