Security Assessment Lead
for sections: About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. Only include sections that have real specific content. No job title heading. No Job ID etc. Remove boilerplate: application deadline, start date subject to change, etc. Also remove EEO, legal, etc. Keep substantive info: company description, location, benefits, responsibilities, required qualifications, preferred qualifications, maybe skills. Need to decide sections.
We have content:
- About the role: description of position: "Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other locations: Warrenton, VA, Atlantic City, NJ, Melbourne, FL, Oklahoma, OK and Leesburg, VA." Also maybe "We are seeking a highly skilled Security Assessment Lead to perform comprehensive assessments..." That's more responsibilities.
We can have About the role: overview.
Responsibilities: list of essential functions/duties.
Requirements: maybe required qualifications? The spec says sections: Requirements, Qualifications, Skills. Could combine required qualifications under Requirements, preferred under Qualifications? Or Skills separate.
We have required qualifications: Bachelor's degree, 10 years experience, at least 2 years recent, at least one certification list, expertise with FAA info sec policies, 5 years management supervisory experience (within required experience timeframe), 2 of those 5 years in lead role.
Preferred qualifications: experience conducting security assessments within federal or regulated environments, strong analytical, communication, technical documentation skills, familiarity with NIST SP 800-53, RMF, STIGs, or similar frameworks.
Skills: maybe we can extract from preferred: strong analytical, communication, technical documentation skills; also maybe expertise with FAA info sec policies; but we can put under Skills.
Benefits: listed.
Pay: not mentioned, so omit.
Schedule: not mentioned, omit.
We must not include sections with placeholder text. So only include About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits.
We need to use for each section heading. Use - for any list of duties/requirements/benefits. Use
for prose.
We must preserve all substantive information, not invent or summarize away detail. So we need to include all details from the posting, but we can format as lists.
We must not repeat job title as heading. Not include Job ID etc.
We must remove boilerplate: application deadline, start date subject to change, EEO, legal, accommodation request, company description beyond maybe about Koniag? The "Our Equal Employment Opportunity Policy" etc must be removed. Also the paragraph about Koniag Government Services (KGS) etc is boilerplate? It's about the company but maybe considered boilerplate? It's describing the company but could be considered part of About the role? The instruction: Remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. The company description about KGS might be considered boilerplate but it's not EEO. It's describing the company; could be kept as part of About the role? However it's somewhat generic. The instruction says preserve ALL substantive information; do NOT invent or summarize away detail. The KGS description is substantive about the company, but maybe it's considered boilerplate? It's not EEO or legal. It's about the company's mission. Might be okay to keep. But we need to decide.
The posting includes: "Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com."
That seems like generic company description, could be considered boilerplate but not explicitly listed to remove. The instruction says remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. This is not those. So we can keep it maybe under About the role.
But we also have earlier: "Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other locations: Warrenton, VA, Atlantic City, NJ, Melbourne, FL, Oklahoma, OK and Leesburg, VA."
We can combine.
Now we need to list responsibilities: The bullet points after "Essential Functions, Responsibilities & Duties may include, but are not limited to:" then list items separated by periods. We'll convert each to
- .
Responsibilities list:
- Conduct assessments of systems and networks within the network environment or enclave to identify deviations from acceptable configurations, enclave policies, and local policies.
- Evaluate the effectiveness of defense‑in‑depth architecture against known vulnerabilities.
- Analyze the security posture of new or existing applications, software, and specialized utility programs and provide actionable recommendations.
- Plan, prepare, and execute system tests to evaluate performance against specifications and security requirements.
- Analyze and report test results, clearly communicating risks, vulnerabilities, and mitigation recommendations.
- Collaborate with technical teams to ensure findings are understood and appropriately addressed.
Now required qualifications: list.
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution.
- Ten (10) years of experience directly related to the responsibilities described in this position.
- At least two (2) years of the relevant experience must be recent (within the last three years).
- At least one of the following risk assessment or cybersecurity certifications: Certified Information Systems Security Professional (CISSP), GIAC Certified Enterprise Defender (GCED), CompTIA Advanced Security Practitioner (CASP), Certified Information Systems Auditor (CISA).
- Expertise with FAA information security policies.
- Five (5) years of management and supervisory experience (within the required experience timeframe), overseeing the successful completion of multiple risk and vulnerability assessments.
- Two (2) of those five (5) years must have been in a lead role.
Preferred qualifications: list.
- Experience conducting security assessments within federal or regulated environments.
- Strong analytical, communication, and technical documentation skills.
- Familiarity with NIST SP 800‑53, RMF, STIGs, or similar cybersecurity frameworks.
Skills: maybe we can extract from preferred: strong analytical, communication, technical documentation skills; also maybe expertise with FAA info sec policies (but that's required). Could also list "analytical, communication, technical documentation" as skills. But we already have them in preferred. Could make Skills section containing those.
But we need to avoid duplication? The instruction: Preserve ALL substantive information; do NOT invent or summarize away detail. If we put skills in both Preferred and Skills, that's duplication. Better to put skills under Skills section and not repeat in Preferred? But Preferred includes those skills; we could keep them there and not have a separate Skills section. However we need to decide sections: we have Required Qualifications (maybe as Requirements), Preferred Qualifications (maybe as Qualifications), and Skills (maybe from Preferred). But to avoid duplication, we could treat Required Qualifications as Requirements, Preferred Qualifications as Qualifications, and Skills could be omitted if not distinct. But the instruction says prefer a few substantive sections over many thin ones. So we could combine Preferred Qualifications and Skills into one Qualifications section, or keep Skills separate if we have distinct skills not covered elsewhere. The Preferred includes "Strong analytical, communication, and technical documentation skills." That's skills. Also "Experience conducting security assessments within federal or regulated environments." That's experience, could be qualification. "Familiarity with NIST SP 800‑53, RMF, STIGs, or similar cybersecurity frameworks." That's also skill/knowledge.
We could have a Qualifications section that includes both required and preferred? But the spec separates Requirements and Qualifications. Usually Requirements = mandatory, Qualifications = preferred. So we can put required under Requirements, preferred under Qualifications. Skills could be part of Qualifications (maybe we don't need separate Skills). But the instruction says use headings for Skills if we have content. We could decide not to include Skills heading if we don't have distinct skills beyond what's in Qualifications. However we have skills mentioned; we could put them under Qualifications as part of the list.
Thus sections: About the role, Responsibilities, Requirements, Qualifications, Benefits.
We need to include Benefits section with list.
Benefits list: medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.
We'll make
- each.
Now About the role: we need prose
. Include the description: Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other locations: Warrenton, VA, Atlantic City, NJ, Melbourne, FL, Oklahoma, OK and Leesburg, VA. Also maybe include the statement "We are seeking a highly skilled Security Assessment Lead to perform comprehensive assessments of systems and networks, evaluate security architectures, and provide actionable insights to strengthen the organization’s cybersecurity posture. The ideal candidate will have deep experience analyzing systems, executing security tests, and assessing compliance against established policies, configurations, and requirements." That's more about role/responsibilities but could be in About the role. However we already have Responsibilities section; we could keep that sentence in About the role as overview. It's not duplicated elsewhere. Let's include it.
Thus About the role paragraph: combine both.
Now we must not include any boilerplate like EEO, legal, accommodation request, company description about KGS (the long paragraph). Should we remove that? It's not EEO/legal but it's generic company description. The instruction says remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. It does not explicitly say to remove generic company description. However it might be considered boilerplate but not listed. Safer to keep? The instruction says preserve ALL substantive information; do NOT invent or summarize away detail. The KGS paragraph is substantive about the company. So we should keep it. But where to put? Could be part of About the role as additional description. However it's quite long and maybe not directly about the role. But it's still substantive. We'll include it in About the role after the initial description.
Thus About the role will have multiple paragraphs? We can use multiple
tags.
Now we must not include any duplicated lines. Ensure we don't repeat same info.
Now output HTML fragment only.
Let's craft:
About the role
Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other locations: Warrenton, VA, Atlantic City, NJ, Melbourne, FL, Oklahoma, OK and Leesburg, VA.
We are seeking a highly skilled Security Assessment Lead to perform comprehensive assessments of systems and networks, evaluate security architectures, and provide actionable insights to strengthen the organization’s cybersecurity posture. The ideal candidate will have deep experience analyzing systems, executing security tests,
- for any list of duties/requirements/benefits. Use
for prose. We must preserve all substantive information, not invent or summarize away detail. So we need to include all details from the posting, but we can format as lists. We must not repeat job title as heading. Not include Job ID etc. We must remove boilerplate: application deadline, start date subject to change, EEO, legal, accommodation request, company description beyond maybe about Koniag? The "Our Equal Employment Opportunity Policy" etc must be removed. Also the paragraph about Koniag Government Services (KGS) etc is boilerplate? It's about the company but maybe considered boilerplate? It's describing the company but could be considered part of About the role? The instruction: Remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. The company description about KGS might be considered boilerplate but it's not EEO. It's describing the company; could be kept as part of About the role? However it's somewhat generic. The instruction says preserve ALL substantive information; do NOT invent or summarize away detail. The KGS description is substantive about the company, but maybe it's considered boilerplate? It's not EEO or legal. It's about the company's mission. Might be okay to keep. But we need to decide. The posting includes: "Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com." That seems like generic company description, could be considered boilerplate but not explicitly listed to remove. The instruction says remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. This is not those. So we can keep it maybe under About the role. But we also have earlier: "Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other locations: Warrenton, VA, Atlantic City, NJ, Melbourne, FL, Oklahoma, OK and Leesburg, VA." We can combine. Now we need to list responsibilities: The bullet points after "Essential Functions, Responsibilities & Duties may include, but are not limited to:" then list items separated by periods. We'll convert each to
- .
Responsibilities list:
- Conduct assessments of systems and networks within the network environment or enclave to identify deviations from acceptable configurations, enclave policies, and local policies.
- Evaluate the effectiveness of defense‑in‑depth architecture against known vulnerabilities.
- Analyze the security posture of new or existing applications, software, and specialized utility programs and provide actionable recommendations.
- Plan, prepare, and execute system tests to evaluate performance against specifications and security requirements.
- Analyze and report test results, clearly communicating risks, vulnerabilities, and mitigation recommendations.
- Collaborate with technical teams to ensure findings are understood and appropriately addressed.
Now required qualifications: list.
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution.
- Ten (10) years of experience directly related to the responsibilities described in this position.
- At least two (2) years of the relevant experience must be recent (within the last three years).
- At least one of the following risk assessment or cybersecurity certifications: Certified Information Systems Security Professional (CISSP), GIAC Certified Enterprise Defender (GCED), CompTIA Advanced Security Practitioner (CASP), Certified Information Systems Auditor (CISA).
- Expertise with FAA information security policies.
- Five (5) years of management and supervisory experience (within the required experience timeframe), overseeing the successful completion of multiple risk and vulnerability assessments.
- Two (2) of those five (5) years must have been in a lead role.
Preferred qualifications: list.
- Experience conducting security assessments within federal or regulated environments.
- Strong analytical, communication, and technical documentation skills.
- Familiarity with NIST SP 800‑53, RMF, STIGs, or similar cybersecurity frameworks.
Skills: maybe we can extract from preferred: strong analytical, communication, technical documentation skills; also maybe expertise with FAA info sec policies (but that's required). Could also list "analytical, communication, technical documentation" as skills. But we already have them in preferred. Could make Skills section containing those.
But we need to avoid duplication? The instruction: Preserve ALL substantive information; do NOT invent or summarize away detail. If we put skills in both Preferred and Skills, that's duplication. Better to put skills under Skills section and not repeat in Preferred? But Preferred includes those skills; we could keep them there and not have a separate Skills section. However we need to decide sections: we have Required Qualifications (maybe as Requirements), Preferred Qualifications (maybe as Qualifications), and Skills (maybe from Preferred). But to avoid duplication, we could treat Required Qualifications as Requirements, Preferred Qualifications as Qualifications, and Skills could be omitted if not distinct. But the instruction says prefer a few substantive sections over many thin ones. So we could combine Preferred Qualifications and Skills into one Qualifications section, or keep Skills separate if we have distinct skills not covered elsewhere. The Preferred includes "Strong analytical, communication, and technical documentation skills." That's skills. Also "Experience conducting security assessments within federal or regulated environments." That's experience, could be qualification. "Familiarity with NIST SP 800‑53, RMF, STIGs, or similar cybersecurity frameworks." That's also skill/knowledge.
We could have a Qualifications section that includes both required and preferred? But the spec separates Requirements and Qualifications. Usually Requirements = mandatory, Qualifications = preferred. So we can put required under Requirements, preferred under Qualifications. Skills could be part of Qualifications (maybe we don't need separate Skills). But the instruction says use headings for Skills if we have content. We could decide not to include Skills heading if we don't have distinct skills beyond what's in Qualifications. However we have skills mentioned; we could put them under Qualifications as part of the list.
Thus sections: About the role, Responsibilities, Requirements, Qualifications, Benefits.
We need to include Benefits section with list.
Benefits list: medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.
We'll make
- each.
Now About the role: we need prose
. Include the description: Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other locations: Warrenton, VA, Atlantic City, NJ, Melbourne, FL, Oklahoma, OK and Leesburg, VA. Also maybe include the statement "We are seeking a highly skilled Security Assessment Lead to perform comprehensive assessments of systems and networks, evaluate security architectures, and provide actionable insights to strengthen the organization’s cybersecurity posture. The ideal candidate will have deep experience analyzing systems, executing security tests, and assessing compliance against established policies, configurations, and requirements." That's more about role/responsibilities but could be in About the role. However we already have Responsibilities section; we could keep that sentence in About the role as overview. It's not duplicated elsewhere. Let's include it. Thus About the role paragraph: combine both. Now we must not include any boilerplate like EEO, legal, accommodation request, company description about KGS (the long paragraph). Should we remove that? It's not EEO/legal but it's generic company description. The instruction says remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. It does not explicitly say to remove generic company description. However it might be considered boilerplate but not listed. Safer to keep? The instruction says preserve ALL substantive information; do NOT invent or summarize away detail. The KGS paragraph is substantive about the company. So we should keep it. But where to put? Could be part of About the role as additional description. However it's quite long and maybe not directly about the role. But it's still substantive. We'll include it in About the role after the initial description. Thus About the role will have multiple paragraphs? We can use multiple
tags. Now we must not include any duplicated lines. Ensure we don't repeat same info. Now output HTML fragment only. Let's craft:
About the role
Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at other locations: Warrenton, VA, Atlantic City, NJ, Melbourne, FL, Oklahoma, OK and Leesburg, VA.
We are seeking a highly skilled Security Assessment Lead to perform comprehensive assessments of systems and networks, evaluate security architectures, and provide actionable insights to strengthen the organization’s cybersecurity posture. The ideal candidate will have deep experience analyzing systems, executing security tests,
- each.
Now About the role: we need prose