Information Security Specialist

Novul Solutions
Arlington, United States
2 months ago
Apply on dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Databases Software Vulnerability Management SARS Software Products Vulnerability Analysis

Job description

We are seeking an experienced Information Security Specialist to support DoD CIO cybersecurity and risk management initiatives. This role focuses on conducting threat and risk assessments of enterprise systems, infrastructure, applications, and databases to evaluate security controls, identify vulnerabilities, and assess overall cybersecurity risk., * Conduct threat, vulnerability, and risk assessments across enterprise environments.

  • Evaluate security control effectiveness and identify security gaps.
  • Perform security planning, risk analysis, and risk management activities.
  • Develop assessment reports, risk documentation, and mitigation recommendations.
  • Support cybersecurity compliance, authorization, and governance efforts.
  • Coordinate with technical teams, system owners, and leadership stakeholders.
  • Track findings, remediation activities, and risk acceptance decisions.
  • Ensure support aligns with contractual requirements and SLAs.

Requirements

  • Master’s degree with 12 years of experience; Bachelor’s degree with 14 years; or 18 years of experience without a degree.
  • Experience conducting cybersecurity risk assessments in federal or DoD environments.
  • Strong knowledge of security planning, security assessments, risk analysis, and risk management.
  • Experience evaluating security controls across infrastructure, applications, and databases.
  • Exceptional written and verbal communication skills., * Experience supporting DoD CIO or federal cybersecurity programs with strong knowledge of NIST RMF and NIST 800-53. Experience supporting security authorization, continuous monitoring, vulnerability management, cybersecurity governance, and security control assessments. Skilled in security planning and assessments, threat and risk analysis, risk management, vulnerability assessment, security control evaluation, technical writing, executive communications, stakeholder coordination, and SLA management. Familiarity with SARs, POA&Ms, risk registers, continuous monitoring programs, and vulnerability management tools.

Benefits & conditions

Core Benefits:

  • Paid Time OffPTO):TEN (10) Paid days off & FIVE (5) Floating days off.
  • Holidays: 11 Paid Holidays. Flex time can be utilized instead of holiday time usage.
  • Payroll: Paid Bi-Monthly.
  • 401(k): Partnered with the SECOND LARGEST Retirement plan provider in the U.S. Guaranteed 3% match. Eligibility - 21 years of age or older, after 3 months of employment
  • Individual or company-wide performance and recognition awards (Quarterly

Health Benefits:

  • UNITED HEALTHCARE PPO, extensive national coverage.
  • INCLUDES: Medical/Dental/Vision/HSA.
  • Eligible on the first of the month, immediately after the start date.
  • Submit the enrollment form within 30 days of your start date otherwise, you will have to wait until October for the new year enrollment.

Quality of Life Benefits:

  • Training & Career Development Reimbursement of Tuition and training needed to support career development.
  • $150 monthly reimbursement contribution paid monthly towards parking expenses.
  • Receipts must be submitted by the close of business on the 25th of each month.
  • Reimbursements will be paid on the first payroll AFTER reimbursements are submitted each month.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all