Sr. ISSO/Security Specialist

3 Months ago • 6 Years + • Cyber Security

Job Summary

Job Description

Job Details

Be Challenged and Make a Difference 

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture. 

Description of Task to be Performed:
AnaVation is seeking a Sr. ISSO/Security Specialist for our mission critical customer in Washington, DC. You will work as part of a fantastic team providing security expertise on high priority projects. Daily duties include, but are not limited to:
· Leading agency’s risk assessment program, performing internal audits, and building streamlined assessment processes.
· Having in depth security knowledge and experience in managing the security of a system’s accreditation boundary.
· Focusing on the enterprise governance and risk of exposure across a multi-cloud and on-premise environment that will include multiple vendors, customers and XaaS products.
· Evaluating agency’s current system infrastructure and recommending changes to improve its security posture.
· Providing customer support for security compliance and audit liaison activities.
· Developing, maintaining, and assessing Security Assessment & Authorization (SA&A) packages resulting in an authority to operate (ATO) for IT systems.
· Creating and maintaining SSPs and supporting documentation in accordance with agency guidelines and directives. This includes writing implementation statements, creating supporting documentation (e.g., Contingency Plans, Incident Response Plans, Account Management Plans, etc.), and performing self-assessments, while working with system stakeholders.
· Develop, coordinate, test, and train personnel on Incident Response Plans and Contingency Plans.
· Ensuring that information systems are accredited, maintain their ATO, and are being continuously monitored.
· Performing risk assessments for government systems, to include cloud-based systems.
· Performing security control assessments to include collecting supporting artifacts/evidence and interviewing system owner/owner representatives.
· Maintaining and tracking system POA&Ms.
· Reviewing and analyzing government policy.
· Taking ownership on various projects.
· Improving on processes and procedures and making recommendations to improve the security posture of the agency's IT systems and applications.

This position is currently hybrid (2 days per week on site at the customer location in DC) but is subject to change at the customer’s direction.

Required Qualifications:

    • 6+ years’ experience with NIST, FISMA, and Security Assessment & Authorization.
    • FedRAMP and Cloud experience (e.g., Azure, AWS, Oracle (OCI))
    • Knowledgeable on various security-related NIST publications (e.g., SP 800-53r5, SP 800-53A, SP 800-18r1, etc.)
    • An in-depth knowledge of the Risk Management Framework (RMF).
    • Ability to obtain and maintain a customer Public Trust clearance required. Qualified candidates can be sponsored for this clearance.
    • Certifications: CISSP required

Preferred Qualifications:

    • Desirable Qualifications (Education/Certificates, Experience, Physical, etc.):
    • Familiarity with the security control families from the NIST guidance covered by the documents that they are responsible for evaluating.
    • Ability to provide subject matter expert-level knowledge to the project team to ensure compliance with applicable requirements.
    • Demonstrated knowledge of IT Security policy implementation statements, the regulatory structure of policy, the role of the Department of Homeland Security (DHS), the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST).
    • Hands-on experience using a Governance, Risk, and Compliance tool, such as CSAM or eMASS.
    • Ability to conduct gap analysis on non-federated vendor audit results, such as SOC Type 2, HIPAA comparison review and analyze against NIST SP 800-53 Revision 5 security controls.
    • Hands-on experience providing C-Level presentation and reporting.
    • Excellent written communication skills and understand the purpose and use of the System Security Plan (SSP).
    • Possess an understanding of control inheritance as applied to the RMF implementation in the CSAM tool.
    • Ability to accurately manage complex workstreams, comprehend the application of the RMF, and understand the application of security controls across the interface, application, operating system, network, and database layers of modern information systems.
    • Understand the applicable artifacts used as evidence to assess compliance.
    • Experience with multiple tools providing security functions such as vulnerability management (e.g., Nessus), configuration management (e.g., BigFix, SCCM, ePO), endpoint protection (e.g., antivirus, ATP), data loss prevention, and intrusion detection software and hardware.
    • Ability to evaluate data flows, network diagrams, and logical security boundaries.
    • Excellent oral and written communication skills
    • Familiarity with the use of data analysis tools, including the use of Microsoft Excel or PowerBI to combine data from multiple sources.
Benefits 
·        Generous cost sharing for medical insurance for the employee and dependents 
·        100% company paid dental insurance for employees and dependents 
·        100% company paid long-term and short term disability insurance 
·        100% company paid vision insurance for employees and dependents 
·        401k plan with generous match and 100% immediate vesting 
·        Competitive Pay 
·        Generous paid leave and holiday package 
·        Tuition and training reimbursement 
·        Life and AD&D Insurance

About AnaVation 
AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.  

If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you! 

Similar Jobs

Brightline - Information Systems Security Engineer

Brightline

Ashburn, Virginia, United States (On-Site)
3 Months ago
PwC - IN-Manager_SOC_Managed Services _Advisory _Pan India

PwC

Gurugram, Haryana, India (On-Site)
3 Months ago
 Sagecor Solutions - Systems Administrator 2 (JPE - 034)

Sagecor Solutions

Fort Meade, Maryland, United States (On-Site)
3 Months ago
 Sagecor Solutions - Systems Administrator 1 (QKS - 002)

Sagecor Solutions

Columbia, Maryland, United States (On-Site)
3 Months ago
Avathon - Senior DevOps Engineer

Avathon

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Axinous - Security Researcher Senior II

Axinous

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Razer - Senior Cybersecurity Specialist

Razer

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
4 Months ago
PwC - IN-Manager–Project Management–Strategy & Governance- Advisory - Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Relia Quest - Security Engineer - Pune

Relia Quest

Mumbai, Maharashtra, India (On-Site)
4 Months ago
Granicus - SOC Analyst II

Granicus

Bengaluru, Karnataka, India (Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Sinch - Security Engineer

Sinch

Victoria, British Columbia, Canada (Hybrid)
3 Months ago
PwC - AC Cyber Managed Services - Senior Associate - Operate

PwC

Mexico City, Mexico City, Mexico (Hybrid)
4 Months ago
Scopely - Principal Security Engineer

Scopely

Seville, Andalusia, Spain (Hybrid)
3 Months ago
Sinch - Security Engineer

Sinch

Melbourne, Victoria, Australia (Hybrid)
3 Months ago
PwC - IN_Associate_SOC_Managed Services_Advisory _Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago
CAE - Information Systems Security Officer

CAE

Binghamton, New York, United States (On-Site)
4 Months ago
Marvell India - Security Vulnerability Management Professional

Marvell India

Bengaluru, Karnataka, India (On-Site)
5 Months ago
PwC - IN-Senior Associate_SOC _Managed Services_Advisory_Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
3 Months ago
PwC - IN-Manager_SOC_Managed Services _Advisory _Pan India

PwC

Gurugram, Haryana, India (On-Site)
3 Months ago
Okta - Site Reliability Engineer, Kubernetes

Okta

Bengaluru, Karnataka, India (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Washington, District of Columbia, United States

Zoox - Automated Machine Learning Internship/Co-op

Zoox

Foster City, California, United States (On-Site)
3 Months ago
Zones - Advanced Technology Executive - IT Staffing, West Region

Zones

Washington, District Of Columbia, United States (Hybrid)
3 Months ago
Zones - Field Account Executive - Enterprise

Zones

Nashville, Tennessee, United States (On-Site)
3 Months ago
New York Times - Senior Data Engineer, Messaging Platforms

New York Times

New York, New York, United States (Hybrid)
3 Months ago
ION - Senior Business Consultant - RightAngle

ION

Houston, Texas, United States (On-Site)
4 Months ago
Zoox - Software Engineer - Automation Tools and Infrastructure

Zoox

San Diego, California, United States (Hybrid)
3 Months ago
The Walt Disney Company - Sr Software Engineer

The Walt Disney Company

Santa Monica, California, United States (On-Site)
3 Months ago
INSPYR Solutions - Game Designer 2

INSPYR Solutions

Santa Monica, California, United States (On-Site)
5 Months ago
K-RAD - Unreal Engine Video Game Developer

K-RAD

United States (Remote)
5 Months ago
Alpha Sense - Senior People Business Partner, Revenue

Alpha Sense

New York, New York, United States (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Assistant Manager - System and Process Assurance

PwC

Colombo, Western Province, Sri Lanka (On-Site)
4 Months ago
PwC - Engagement Manager - Cloud Optimization

PwC

Mexico City, Mexico City, Mexico (On-Site)
4 Months ago
ION - Information Security Manager - London

ION

London, England, United Kingdom (On-Site)
4 Months ago
ION - Pen Tester, Italy

ION

Italy (Hybrid)
4 Months ago
Canva - Security Engineering Director - Detection & Response - Remote across ANZ

Canva

Sydney, New South Wales, Australia (Remote)
3 Months ago
Granicus - Cloud Network Security Engineer

Granicus

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Smarsh - Senior Technical Product Manager - Runtime Network and Security

Smarsh

London, England, United Kingdom (Remote)
3 Months ago
Scientific Games  - Senior Information Security Analyst

Scientific Games

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Intel Corporation - Principal System Security Architect

Intel Corporation

Fairfax, Virginia, United States (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Reston, Virginia, United States (On-Site)

Reston, Virginia, United States (On-Site)

Chantilly, Virginia, United States (Hybrid)

Linthicum Heights, Maryland, United States (On-Site)

Linthicum Heights, Maryland, United States (On-Site)

Chantilly, Virginia, United States (On-Site)

Fort Meade, Maryland, United States (On-Site)

Chantilly, Virginia, United States (On-Site)

Reston, Virginia, United States (On-Site)

Chantilly, Virginia, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Anavation

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug