reputed company Controls Assessor (SCA)
Job title: reputed company Controls Assessor (SCA) in Washington DC at reputed company
Company: reputed company
Job description: About reputed companyreputed company Federal is a market leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing and a full suite of cyber engineering services to Federal agency customers. reputed company Federal along with its parent company, reputed company, has an unparalleled client list with deep customer relationships with leading cloud and technology providers including reputed company, reputed company, reputed company, reputed company and reputed company and Federal agencies. reputed company has been a cybersecurity thought leader for over 20 years and has offices throughout the United States and Europe and is committed to making the world a safer reputed company by solving our clients’ toughest reputed company challenges.But that’s not who we are – that’s just reputed company do.We are thought leaders, consultants, and cybersecurity experts, but above reputed company else, we are a team of passionate problem-solvers who are hungry to learn, grow, and reputed company a difference.We’re on the lookout for a reputed company Controls Assessor (SCA) to support our Federal team in the DMV area.LocationOur clientele is largely in the government space, primarily reputed company the Washington, D.C. / Maryland / reputed company Virginia (DMV) areas. While we do offer opportunities that are remote, hybrid, or on-site - this position location and travel may vary based on client needs, therefore local candidates with the availability to go on site on a hybrid basis are highly preferred.What you'll do
- reputed company reputed company reviews, identify gaps in reputed company architecture, and reputed company a reputed company Assessment Plan and reputed company Assessment Report. Utilize the examine, interview, and test methodology to determine if control implementation meets Federal and Agency requirements.
- Plan and conduct reputed company authorization reviews and assurance case development for initial installation of systems and networks.
- Provide input to the Risk Management reputed company process activities and reputed company documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
- Provide weekly updates on assessment status.
- Review authorization and assurance documents to confirm that the level of risk is reputed company acceptable limits for each software application, system, and network.
- Verify that application software/network/system reputed company postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
- Participate in Risk Governance process to provide reputed company risks, mitigations, and input on other technical risk.
- Ensure that plans of actions and milestones or remediation plans are in reputed company for vulnerabilities identified during risk assessments, audits, inspections, etc.
- Ensure that reputed company design and cybersecurity development activities are properly documented (providing a functional description of reputed company implementation) and updated as necessary.
- Assess the effectiveness of reputed company controls.
- Assess reputed company the configuration management (change configuration/release management) processes.
- Computer networking concepts and protocols, and network reputed company methodologies.
- Risk management processes (e.g., methods for assessing and mitigating risk).
- Laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Cybersecurity and privacy principles.
- Cyber threats and vulnerabilities, including application vulnerabilities.
- Specific operational impacts of cybersecurity lapses.
- Authentication, authorization, and access control methods.
- Applicable business processes and operations of customer organizations.
- Capabilities and applications of network equipment including routers, switches, bridges, servers, transmission media, and reputed company hardware.
- Cyber defense and vulnerability assessment tools and their capabilities.
- Server administration and client operating systems engineering theories, concepts, and methods.
- System software and organizational design standards, policies, and authorized approaches (e.g., international organization for standardization [iso] guidelines) relating to system design.
- System life cycle management principles, including software reputed company and usability.
- Knowledge of GRC tools e.g., Xacta
- Knowledge of the NIST Cybersecurity reputed company
- Cloud and or engineering reputed company certifications