You will manage security compliance and assessment for application and infrastructure modernization projects.
Responsibilities
Support the ISSO in managing system security plans and ensuring systems obtain and maintain Authorization to Operate (ATO).
Provide security compliance oversight for applications and systems within the ATO boundary using MARS-E, NIST, and HIPAA guidelines.
Collaborate with Enterprise Architecture, DBA, and development teams to implement automated Disaster Recovery, security event logging, and monitoring processes.
Perform internal assessments of security controls and monitor infrastructure assets using NIST 800-53.
Track remediation efforts from audits through Plans of Action and Milestones (POA&Ms) and Correction Action Plans (CAPs).
Review RFPs, MOUs, and MOAs for privacy, security, Business Continuity Planning, and Disaster Recovery requirements.
Required Skills
5+ years of related IT security work experience.
5 years of experience providing security compliance for applications in cloud environments (AWS, Azure, or Google).
5 years of experience updating or maintaining SSP/SSPP documentation.
5 years of experience participating in the Assessment & Authorization (A&A/ATO) process.
5 years of experience monitoring and testing application/system components utilizing NIST 800-53.
Working knowledge of CMS, USDA, and ACF requirements.
Proficiency with NIST and HIPAA guidelines.
Experience with security control implementation and risk mitigation strategies.