Bachelor's degree and 8+ years of experience in Information Systems Security Engineering., Experience with SaaS applications and cloud environments (AWS, Microsoft Azure)., Previous experience as an Information Systems Security Engineer supporting customers directly., At least one certification required, such as CISSP or GSLC..
Key responsibilities:
Manage multiple Assessment and Authorization (A&A) systems and projects simultaneously.
Document security control implementations and gather artifacts for Risk Management Framework (RMF) compliance.
Collaborate with systems owners and project managers to create various A&A related documents.
Coordinate with contractor and customer personnel to navigate the A&A process and achieve necessary authorizations.
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
Navitas Partners LLC is a diversity led business, headquartered in NJ, as a dynamic IT professional services and workforce solutions company. We believe creating the best solutions in human resource services means always going above and beyond - and people are our most important asset. Our “DNA”
invokes core values of knowing, trusting and serving our relationships. The better we know our clients and candidates, the better our relationship, and the better we match the needs and exceed expectations. We want our client’s experience with us to reflect a transparent, professional and driven relationship.
At Navitas Partners we strive for Excellence in People, and grow with you to become a true extension of your HR specific business requirements, while remaining sensitive to your price & business needs.
Certified Diversity Employer: SBE • WOSB • WBE • MBE • NMSDC
NAICS: 541511, 541512, 541513, 541519, 54164, 518210, 811212, 561320
https://form.jotform.com/223145471243247
Job title: Information Systems Security Engineering Duration: 12 months
Location: Remote
Summary:
• Possess multi-tasking skills, be able to handle multiple A&A systems / projects simultaneously, as well as being a good communicator / facilitator. Comfortable communicating at all levels from developer / engineer to senior contractor / customer staff.
• Knowledge of complex network environments involving shared networks and multiple security enclaves
• Possess the ability to bridge the technical implementation (i.e. engineering talk) into commonly understood security verbiage. Often this is a skillset and is not an actual language, frequent translation or a basic understand needs to be conveyed by the ISSE when speaking with others or when communicating in writing in order to ensure it's easy to understand at all levels.
• Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for the various Assessment and Authorization (A&A) efforts
• Document and obtain a general understanding of the architecture being developed or that was developed for each project in order to write the Systems Security Plans (SSP) / CONOPS
• Gather the information by working with various systems owners, project managers, and engineering team members in order to write various additional A&A related documents such as Contingency Plan (CP), General User Guide (GUG), Privileged User Guide (PUG), Standard Operating Procedures (SOP's), etc.
• Document the Plans of Actions and Milestones (POA&Ms) implementation responses or mitigations, as well as provide all required artifacts (i.e. evidence gathering from the system owners, PMs, and engineering teams)
• Coordinating with various contractor and customer personnel to obtain the A&A content, as well as working with various customer security organizations to navigate the customer's A&A process to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), and Authority to Operate (ATO) for each of the primary and secondary assigned systems
• Provide appropriate support for ATO'ed systems that are in continuous monitoring
• Education, Experience & Skills
8+ years' experience and a bachelor's degree minimum required
Previous ISSE experience directly supporting the customer
SaaS applications along with Public, private and/or hybrid Cloud experience is a must (AWS, Microsoft Azure, etc.)
• Certifications: At least 1 is required
CISSP or GSLC certifications
Required profile
Experience
Level of experience:Senior (5-10 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.