Cyber & A&A Security Specialist - Hybrid Remote
ATTAINX INC
Mableton, GA, United States
4 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.jofdav.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$98,000.0
Working hours
Regular working hours
Job source
Tech stack
Cyber Security
Information Systems
Federal Information Processing Standards (FIPS)
Information Systems Security Architecture Professional
ArcSight SIEM Tool
SARS Software Products
Tenable Nessus
Vulnerability Analysis
Job description
- Conduct full lifecycle Security Control Assessments and Authorization (A&A) activities for NWS FIPS 199 Low, Moderate, High, HVA, and hybrid systems in accordance with the NIST Risk Management Framework (RMF), NWS policy, NOAA, and DOC directives
- Validate information System Security Plans (SSPs), FIPS 200, control implementations, and supporting policies and procedures for accuracy, completeness, and NIST SP 800-53 compliance.
- Execute security control test procedures through documentation review, technical validation, and interviews with system stakeholders to determine control implementation status and effectiveness
- Collect, analyze, and document evidentiary artifacts (screenshots, test logs, interview notes) to validate control implementation and effectiveness.
- Utilize CSAM to retrieve POAMs, artifacts, and other pertinent documentation to assist with the A&A process and ensure accuracy of the A&A documentation uploaded in the tool
- Analyze and interpret vulnerability and configuration compliance scan results from tools like Tenable Nessus to identify control gaps, assess risk, and validate remediation actions.
- Develop and maintain pre-assessment and assessment deliverables, including Security Assessment Plans (SAPs), Security Control Assessment (SCA) workbooks, and kickoff deck briefings
- Document assessment results and risk determinations in Security Assessment Reports (SARs), Vulnerability Assessment Reports (VARs), and Authorization to Operate (ATO) briefing deck.
Requirements
- Knowledge of DOC, NOAA, and NWS IT security policies and implementation standards or those of similar sized organizations AND comprehensive understanding of NIST guidance to include, but not limited to, NIST Special Publications and Federal Information Processing Standards.
- At least 5 years of recent experience (within the last 6 years) in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools.
- At least 5 years of recent experience (within the last 6 years) with enterprise architecture methodologies, concepts, procedures, principles, and tools.
- At least 5 years of recent experience (within the last 6 years) in contingency planning and backup and recovery best practices and application of NIST guidance in this area.
- At least 5 years of recent experience (within the last 6 years) in using technical testing tools (Tenable Security Center, ArcSight, IBM Big Fix, etc.).
- At least 5 years of performing assessments of Federal Information Systems using the Risk Management Framework.
- Ability to work in a cohesive team-oriented environment.
- Possess at least one of the following Certifications or be able to Obtain within six (6) months of hire:
- Certified Information Systems Security Professional (CISSP).
- Certified Information Systems Auditor (CISA).
- GIAC Certified Incident Handler (GCIH).
- GIAC Systems and Network Auditor (GSNA).
- Electronic Commerce Council Certified Ethical Hacker (CEH).
- ISC2 Certified in Governance, Risk and Compliance (CGRC).
- Security Certified Network Professional (SCNP).
- Security Certified Network Architect (SCNA)., * Bachelor’s Degree (or higher) in a related field
- Knowledge of assessing and securing cloud-hosted systems in accordance with federal security requirements
- Self-starter, highly motivated individual who adapts to a dynamic work environment
- Strong attention to detail with an ability to operate effectively across multiple priorities., Cyber Security, Information Security, A&A
Benefits & conditions
- Paid vacation
- Medical, dental, and vision coverage
- Matching 401(k) plan
- Tuition/training reimbursement
- Long & Short-Term Disability, $98,000.00
About the company
AttainX Inc. is CMMI Level 3, ISO 9001:2015 certified QMS, and a Gold Level SAFe Partner. For over 14 years, AttainX has delivered innovative IT and cloud-based solutions for a broad portfolio of federal clients, including USDA, NOAA, DOE, DHS, and DIA.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.jofdav.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
DC
Daniel Cranney
The Overflow: Security and Privacy
6 months ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago