Назад
Company hidden
5 дней назад

Assessment and Authorization Specialist III (Cybersecurity)

150 000 - 160 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Assessment and Authorization Specialist III (Cybersecurity) (NIST/FISMA): Leading security and privacy control assessments for Department of Energy systems across cloud and on-premises environments with an accent on federal cybersecurity frameworks, control effectiveness, and remediation. Focus on analyzing vulnerabilities and technical documentation, preparing A&A packages and assessment reports, and validating corrective actions for complex systems.

Location: Remote within the United States; Conditions: District of Columbia, Washington, DC

Salary: $150,000–$160,000 annually

Company

hirify.global Mission Optimization provides administrative support services and federal project solutions as part of hirify.global, an Alaska Native Corporation.

What you will do

  • Lead comprehensive assessments of security and privacy controls, including system-specific and inherited controls.
  • Assess NIST and FISMA systems across SaaS, PaaS, IaaS, and on-premises environments.
  • Prepare and review Assessment Readiness Workbooks, Security Assessment Plans, Security Assessment Reports, risk assessments, and findings packages.
  • Analyze vulnerabilities, test reports, POA&Ms, system documentation, network diagrams, data flows, and change requests.
  • Evaluate deficiencies, recommend corrective actions, oversee remediation, and reassess remediated controls.
  • Support security-related data calls and internal and external audits, including FISMA activities.

Requirements

  • Bachelor’s degree or four years of equivalent professional experience.
  • 5–7 years of experience in security control assessments, cybersecurity evaluations, or related technical security work.
  • Strong knowledge of NIST SP 800-53, the NIST Cybersecurity Framework, NIST RMF, and information security and privacy regulations.
  • Experience working with Security Assessment Teams, Security Control Assessors, ISSOs, TPOCs, system owners, and assessment coordinators.
  • Ability to analyze technical documentation, identify security gaps, and communicate findings in written reports.
  • Must be able to complete a DOE background investigation and obtain federal government and DOE Q clearances.

Culture & Benefits

  • Remote work arrangement.
  • Medical, dental, vision, and life insurance.
  • 401(k) and retirement options.
  • Paid time off for regular full-time and part-time employees.
  • Supportive environment focused on innovation, diversity, and professional growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →