TL;DR
Senior Security Specialist (Cybersecurity): Managing security assessment and authorization (SA&A) processes for mission-critical federal systems with an accent on RMF compliance, NIST standards, and cloud-based infrastructure security. Focus on maintaining Authority to Operate (ATO), conducting risk assessments, and ensuring continuous monitoring for high-priority projects.
Location: Must be based in Washington, DC
Company
hirify.global delivers advanced software and systems engineering solutions to solve complex technical challenges for the U.S. Federal Intelligence Community.
What you will do
- Perform internal audits and build streamlined security assessment processes.
- Develop, maintain, and assess SA&A packages to obtain and maintain Authority to Operate (ATO).
- Manage the security accreditation boundary for multi-cloud and on-premise environments.
- Perform risk assessments and provide recommendations to improve the overall security posture.
- Act as a liaison for security compliance and audit activities.
- Create and maintain System Security Plans (SSPs) and supporting documentation.
Requirements
- 6+ years of experience with NIST, FISMA, and Security Assessment & Authorization.
- CISSP certification is required.
- In-depth knowledge of the Risk Management Framework (RMF).
- Experience with FedRAMP and cloud environments (Azure, AWS, or Oracle).
- Ability to obtain and maintain a customer Public Trust clearance.
- Must be able to work on-site in Washington, DC.
Nice to have
- Hands-on experience with GRC tools like eMASS or CSAM.
- Experience with vulnerability management and endpoint protection tools.
- Ability to conduct gap analysis on non-federated vendor audit results (SOC 2, HIPAA).
- Experience with C-Level presentations and reporting.
Culture & Benefits
- Generous cost-sharing for medical, dental, and vision insurance for employees and dependents.
- 401k plan with generous match and 100% immediate vesting.
- 100% company-paid long-term and short-term disability, plus life and AD&D insurance.
- Tuition and training reimbursement programs.
- Generous paid leave and holiday package.
- Engaging, collaborative team environment focused on mission success.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →