Job description
Global Networks Inc. (GNI) is looking for a Cyber Security Analyst for our Cyber Security Support Unit in Washington, DC.
REQUIREMENTS:
- Certified in Risk and Information Systems Control (CRISC), International Information System Security Certification Consortium (ISC)2 Certified Information Systems Security Professional (CISSP), (ISC)2 Certified Authorization Professional (CAP), ISACA's Certified Information Security Manager (CISM) or Security+
- 3+ years of expert experience consulting with federal agencies on cyber security matters
- Subject Matter Expert (SME) with NIST SP 800-37 Risk Management Framework, 800-60, 800-53, 800-53A, FIPS199, FISMA, FedRAMP, NIST SP guidance and other federal cybersecurity-related policies, directives, and mandates (e.g., related OMB)
- Demonstrated experience with system/application security, risk management, information assurance third party management and risk remediation.
- Demonstrated experience performing risk management activities developing and maintaining System Security Plans (SSPs), Risk Assessment and Recommendations (RARs), Plan of Action and Milestones (POA&M) and developing Executive-level briefings.
- In-depth understanding of Cloud Based Systems, and Cloud Service Providers (CSP); This can be Azure, AWS, or comparable.
- Knowledge and support of Cyber Security Assessment and Management (CSAM)
- Experience with preparing and presenting deliverables to clients Proficiency understanding the technical architecture of IT systems built using Windows, UNIX, Linux, IBM AIX, VMware, Citrix, Oracle and MySQL platforms.
- Experience using and analyzing technical assessment tools such as Nessus, McAfee Vulnerability Manager (MVM), HP WebInspect, AppDetective, BurpSuite, Backtrack, Wireshark, QualysGuard and Redseal.
- In-depth understanding of processes used to assess risk and establish security requirements and documentation to ensure that information systems possess security safeguards commensurate with the level of exposure to potential risk, as well as damage to assets or individuals.
- In-depth knowledge of information assurance levels and risk impact thresholds in meeting applicable security policies, standards and requirements to ensure that accrediting authorities have the information necessary to make an objective authorization determination based on an acceptable level of risk.
- Knowledge of all System Security artifacts
- Ability to assist ISSOs and/or system owners address security controls and implementation methods in the SSP as well assist in contingency planning and testing, security control assessment and vulnerability scanning.
- Able to analyze, assess, control, determine, mitigate and manage risk within a federal management framework or within federal interest computer systems that store, process, display or transmit Personally Identifiable Information (PII).
- Able to identify, implement and integrate management and administrative risk methodologies for securing critical and sensitive information infrastructures and establishing standards necessary to help protect the confidentiality, maintain the integrity and ensure the availability of critical organizational computing resources
- Proficiency with Microsoft Teams, Microsoft Project, Microsoft SharePoint
- Prepared to jump into a fast-paced environment with the ability to understand and use executive level communication
Demonstrated technical experience with:
- Windows Servers, Desktops, Laptops
- UNIX/LINUX Servers (Solaris, Red Hat Enterprise etc.)
- Network Switching and Routing (Cisco IOS & PIX)
- Oracle and SQL Server Databases is a plus
- Vulnerability/Port scanning solutions such as Nessus, nMAP, MVM, QualysGuard and Tripwire IP360.
- Experience with web application scanning solutions such as HP WebInspect.
- Experience with database scanning solutions such as AppDetective.
- Experience with analysis tools such as Redseal.
- Familiarity of TCP/IP and associated protocols.
Technical writing experience:
- Weekly, Monthly, Quarterly management level reports
- Monthly and Quarterly executive level reports and briefings
- Standard operating procedures documents
- Formal policy and procedure documents
blackflymedia.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, blackflymedia.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, blackflymedia.com is the ideal place to find your next job.