Security Controls Assessor - Senior
SMS Data Products Group, Inc. · Springfield, VA · 3 wk ago
Information TechnologyFull-time
About the role
SMS is seeking a Senior Security Controls Assessor and Validator to join our team supporting the United States Coast Guard in Alexandria, VA. The successful candidate will evaluate, test, and validate the effectiveness of security controls with a strong emphasis on applying the Risk Management Framework (RMF) and will lead a team of assessors.
Since 1976, SMS has specialized in modernizing legacy IT and sustaining complex enterprise environments for federal agencies. We invest in our employees by providing training, tools, and support to keep critical missions operational, improve performance, and reduce risk.
Responsibilities
- Serve as senior member and representative of assigned team for meetings and lead internal resources to meet established milestones and targeted completion dates.
- Provide guidance, coaching, and training to employees of the assigned team.
- Assist in Security Assessment & Authorization Coordination Plan and conduct security authorization reviews of federal systems.
- Manage and review Accreditation Packages.
- Support USCG system accreditation and Ongoing Assessment and Ongoing Authorization processes for assigned systems.
- Provide SME knowledge of Risk Management Framework (RMF) policy and application, NIST Security Controls, and Control Implementation methodologies for the A&A process.
- Review and provide guidance on System Security Plan, Security Assessment Report (SAR), and Plans of Action and Milestones (POA&M) and other security documentation.
- Support POA&M remediation activities and review POA&M closure documentation.
- Assess and develop authorization packages for technical solutions, collaborating with internal expertise and analyzing the technical solution.
- Collaborate and communicate with parties within and outside the organization, including customers and vendors.
- Support Privacy Compliance Activities, including review of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN).
- Facilitate and monitor information assurance (IA) processes for new projects, including development of security authorization packages and tracking progress for all Security Control implementations and POA&Ms.
- Support and/or develop all Security Authorization artifacts and documentation and assemble Authorization packages.
- Administer and adhere to the Risk Management Plan.
- Coordinate closely with Quality Assurance Specialists to identify and mitigate risk to meet established quality standards.
Requirements
- Minimum of an active DoD Secret clearance required.
- University Degree (BA/BS) or equivalent experience and minimum 5 years of related work experience.
- CSSP-AU certification: CEH, CySA+, CISA, PenTest+, GSNA, or CFR (within 60 days of hire).
- DOD 8750 IAT III certifications: CASP+ CE, CCNP Security, CISA, CISSP (or associate), GCED, GCIH, or CCSP.
- Relevant DOD, DHS, or .gov Cyber Security Information Assurance experience with hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations.
- Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes.
- Experience with continuous monitoring/ongoing authorization.
- Intimate understanding of NIST RMF implementation guidance.
- In-depth understanding of NIST Security Controls and Control Implementation methodologies.
- Experience assessing security controls based on cybersecurity principles (e.g., NIST SP 800-53, Cybersecurity Framework).
- Demonstrated understanding of critical documentation required in Security Authorization (SA) Packages.
- Ability to understand and support Privacy Compliance Activities, including development of PIA, PTA, and SORN.
- Experience managing client relationships, including determining client needs, managing expectations, and delivering quality results.
- Experience analyzing strategic guidance for issues requiring clarification or additional guidance.
- Understanding of basic cyber concepts and their organizational impact.
- Experience as a senior or lead team member, including coaching, reviewing work products, tracking deadlines, reporting, and facilitating onboarding/offboarding.
- Experience with administrative planning activities, including preparation of functional and specific support plans and managing correspondence.
- Understanding of Cloud Services delivery models and their influence on the Assessment and Authorization process.
Qualifications (Desired)
- Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A).
- Hands-on experience with eMASS or similar application.