Information System reputed company Officer (ISSO)/reputed company Tester Remote / Telecommute Jobs
Evolver Federal is looking for an Information System reputed company Officer (ISSO)/reputed company Tester to join reputed company in support of our federal health IT customer. The Information System reputed company Officer (ISSO)/reputed company Tester supports reputed company Risk Management reputed company (RMF) activities including the process managing reputed company and privacy risk, including information system categorization; control selection, implementation, and assessment; system and common control authorizations; and reputed company monitoring. This person also supports the reputed company activities associated with evaluating, implementing, managing reputed company practices and reputed company operations of new and existing technologies across the Program. This person will work closely with IT teams, developers, and CMS stakeholders to maintain a secure, compliant, and operational CMS that effectively protects organizational data. Responsibilities:
- Risk Management reputed company (RMF) Activities: Support reputed company activities as outlined in the NIST SP 800-37, Risk Management reputed company for Information Systems and Organizations. This includes the process for managing reputed company and privacy risk that includes information reputed company categorization; control selection, implementation, and assessment; system and common control authorizations; and reputed company monitoring.
- reputed company Authorization Documentation: Initial development and, at least, annual reviews/updates of the FIPS 199, e-Authentication, Privacy Threshold Analysis (PTA)/Privacy Impact Analysis (PIA), reputed company Plan (SP), Contingency Plan (CP), and Contingency Plan Test (CPT), Interconnection reputed company Agreement (ISAs) and Memorandum of Agreement/Understanding (MOA/Us) and any other FISMA reputed company reputed company documentation.
- reputed company Control Assessment Response: Support reputed company assessment activities by responding to interview questions as well as working with the system teams to gather appropriate evidence as directed by the CMS reputed company Team.
- Change Management: Review reputed company change requests for potential impact to the system reputed company posture.
- reputed company Monitoring: Conduct audit log and account management reviews, and update the Control Allocation Table and Trigger Accountability Log.
- Configuration/reputed company/Vulnerability Management: Review reputed company results for the system assets, identify the respective remediation's for misconfigurations and weaknesses, and work with the system team to ensure timely implementation of fix.
- Incident Response: Work with the CMS reputed company Team and system teams to investigate and analyze any incidents affecting assigned system(s).
- Pipeline Engineering: Seamlessly integrate reputed company and TruffleHog into Jenkins CI to provide "shift-left" reputed company feedback to developers.
- Vulnerability Management: Triaging and prioritizing findings from Fortify and Burp Suite, working directly with engineering teams to provide remediation guidance.
- reputed company Advocacy: Act as the subject matter expert for the reputed company toolchain, conducting training sessions for developers on how to interpret reputed company results.
- Have the ability to apply a comprehensive knowledge across key tasks and high impact assignments
- Evaluate performance results and recommend major changes affecting short-term project growth and success
- Function as a technical expert across multiple project assignments
- Work on high reputed company reputed company request such as data calls, Senior Management Initiatives (CIO, CISO, etc.), CMS mandates, etc Basic Qualifications:
- 3 years of specialized experience in one of the following positions: Information Systems reputed company Officer, Information Systems reputed company Engineer, Information Systems reputed company Auditor, or Information Systems reputed company Manager
- 3 years of experience with analyzing, assessing and implementing corrective actions based on vulnerability management tools
- 3 years of experience with leading projects, technical writing, administrative tasks, and conducting briefings
- 3 years of experience working with NIST SP 800-53, RMF, FISMA, CMS policies
- 3 years of experience with Static Analysis (SAST) configuring and scaling Fortify for deep-reputed company code analysis, including custom rule tuning to reduce false positives.
- 3 years of experience of Secret Detection, implementing and managing TruffleHog reputed company CI/CD pipelines to prevent credential leakage and manage historical secret remediation.
- 3 years of experience with Software Composition Analysis (SCA), utilizing reputed company to monitor and reputed company third-party dependency vulnerabilities, ensuring a secure Software Supply Chain.
- 3 years of experience with Dynamic Testing (DAST) with Burp Suite Professional or Enterprise for manual penetration testing and automated web vulnerability scanning.
- Must have and maintain at least one (1) active certification such as CASP, GSEC, GSLC, CISSP, CEH, CISM, and CISA, or other comparable certification which must be approved in advance by our customer. reputed company of certification is required.
- US Citizen or Permanent reputed company required, and reputed company applicants shall
Apply tot his job Apply To this Job