Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: Top Secret/SCI
Employee Type: Regular
Percentage of Travel Required: None
Type of Travel: None
Position Overview: Reporting directly to the Chief for Cyber Readiness, you will provide audit support that manages NGA's preparation for, execution of, and response to external cyber audits such as Command Cyber Operational Readiness Inspection (CCORI), Command Cyber Readiness Inspection (CCRI), Cybersecurity Service Provider (CSSP), Federal Information Security Management Act (FISMA), and Federal Information Systems Controls Audit Manual (FISCAM) audits. This includes, but is not limited to aggregating documents and artifacts, securing the facilities and infrastructure necessary to house auditors and meetings, developing presentations, briefs, and other products as needed to brief stakeholders on audit readiness status, coordinating audit activities across the NGA enterprise, and conducting routine internal audit assessments to ensure a continuous level of audit readiness. Candidates performing audit support services shall have or obtain within six months of start a certification that is compliant with DoD 8140.01 and DoD 8570.01-M 1040 IAT Level II and CSSP Auditor.
Responsibilities: - Ensure the Cybersecurity Operation Cell (CSOC) is prepared to successfully pass inspections and audits at all times; this includes but is not limited to identifying the audit criteria for CCRI/CCORI, FISMA, FISCAM, and CSSP audits.
- Review regulations, directives, guidance, grading criteria, regulations, and other documents and products as required to identify applicable cybersecurity standards and inspection criteria;
- Perform self-assessments of CSOC services to identify deficiencies, gaps, or other issues and provide remediation recommendations to the Chief of Cyber Readiness.
- Coordinate and collaborate with other Contracts, Government entities, and activities to identify and remediate any findings outside the direct control of TCS staff.
- As required, provide status briefings and reports to the Government on the status of findings and remediation status.
- Regularly attend meetings held both internally and community-wide.
- Develop, update, and maintain, dashboards, charts, documents, reports, and other products as required to accurately depict NGA's audit readiness.
- Provide input to the Weekly CSOC Status Report.
- Coordinate and collaborate with any internal or external stakeholders (government and contractor) as needed or directed by the government in support of this service.
Qualifications: - Considerable experience preparing organizations for CCRI/CCORI, CSSP, and FISMA audits.
- Strong understanding of the NIST Cybersecurity Framework.
- Working knowledge of DOD Cybersecurity Services Evaluator Scoring Metrics (ESM) V.10.
- Working knowledge of DoDIN Inspection Coordination Guides.
- Working knowledge of DoDIN Inspection Pre-Deployment Checklists.
- Working knowledge of the areas of CCORI to include, but not limited to, DCO-IDM effectiveness, Traditional Security STIG checks, Contributing Factors and CND Directive scoring.
- A minimum of 6 years demonstrated experience supporting an IC or DoD agency in an auditor role.
- Strong understanding of cybersecurity compliance policy, governance, programs, processes, and metrics.
- Excellent verbal and writing skills with the ability to write clear and concise assessment reports.
- Demonstrated experience providing briefings to an executive audience.
- IAT Level II certified.
- Willingness to obtain CSSP Auditor certification within 6 months of joining the team.
Desired Qualifications: - ISACA CISA Certified.
- IAT Level III Certified.
Work Environment:
Professional Office Environment: Must be able to sit at a desktop or laptop computer for extended periods of time.
Physical Demands: - While performing the duties of this job, the employee is regularly required to sit, stand, talk, hear, and use hands and fingers to operate a computer and telephone.
- Must be able to communicate regularly via telephone and verbally present information to employees, customers, and outside vendors.
Expected Hours of Work: - 40 hours per week based on the customer's core operating hours.
About RISA: In this time of rapid change, as technologies expand at lightning speed, RISA seeks to remain at the forefront - applying them in unique ways to address our customers' challenges and providing our employees with engaging career opportunities. We seek professionals excited by a challenge and focused on assisting our customers to reach their goals. At RISA, our success comes from the talent and commitment of our employees. As a team, we share the challenges and rewards of providing valuable services to our customers. Come along for the journey and be part of our growth and success.
Benefits: RISA offers a comprehensive benefits package that includes medical, dental, and vision insurance; company-paid disability; life insurance; retirement savings plans: 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.
RISA is an Equal Opportunity Employer.
- Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.