Saliense Consulting logo

Intermediate Security Assessor

Saliense Consulting

Remote · USJobPosted 7mo agoSeen in employer's feed 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Remote · US
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

ISC2 Certified In Governance, Risk And CompliancePublic Trust clearanceBachelor's degree

Job overview

Saliense Consulting is hiring an Intermediate Security Assessor. Saliense Consulting is seeking an Intermediate Security Assessor to conduct independent security assessments of various environments, including on-premise, cloud systems (IaaS, PaaS, SaaS), and applications. This role involves analyzing existing security processes, providing system administration support to the GRC module, and developing and maintaining assessment schedules. The assessor will lead assessment meetings, conduct risk assessments, and develop Security Assessment Reports.

Key focus areas include Conduct independent security assessments of environments and applications, Analyze existing security processes including automation and security service delivery models, and Provide system administration support to the GRC module.

Successful candidates bring Bachelor's Degree in Business/Engineering, 8+ Years Experience, and ISC2 CGRC Certification. Important skills include Conducting Independent Security Assessments, Analyze Security Process, System Administration Support, Developing Master Assessment Schedule, Schedule Security Assessments, and Leading Assessment Meetings.

Skills & qualifications

RequiredNice to have

Skills

Conducting Independent Security AssessmentsAnalyze Security ProcessSystem Administration SupportDeveloping Master Assessment ScheduleSchedule Security AssessmentsLeading Assessment MeetingsLeading Risk AssessmentsDeveloping Security Assessment ReportDocumenting Plans of Action and MilestonesDeveloping Executive SummariesRMFNIST Cybersecurity FrameworkCSAMNIST SP 800-53NIST SP 800-137NIST SP 800-171NIST SP 800-37Federal Risk and Authorization Management ProgramAssessing Systems and Applications in Cloud EnvironmentsWorking CooperativelyComputer Networking ConceptsProtocolsNetwork Security MethodologiesRisk Management ProcessesRisk Management ToolsCybersecurity Laws and RegulationsCybersecurity PoliciesCybersecurity EthicsCurrent Cybersecurity ThreatsPast Cybersecurity ThreatsCurrent Cybersecurity VulnerabilitiesPast Cybersecurity VulnerabilitiesManage Multiple TasksPrioritize Multiple TasksEffective CoordinationCommunicationTake InitiativeWork With Minimal SupervisionWork and Collaborate as Part of an Integrated Team

Qualifications

Bachelor's Degree in Business or Engineering8 Years of Experience in Listed TasksISC2 Certified in Governance, Risk and CompliancePublic Trust Clearance

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off

Full job description

McLean, VA, US

Saliense is a growing Management and Technology Consulting Solutions provider based out of Tysons, VA. We work to solve our client’s toughest challenges within the Defense, Civilian, Financial, and Healthcare industries. Our diverse employees support vital missions for government and commercial customers. For more information, visit www.saliense.com.

Why Saliense?

In addition to providing a fun, energetic environment that promotes innovation and personal growth, we offer excellent compensation packages with plenty of opportunities for advancement. We pay 100% of the premiums for employee Healthcare, including medical, dental, and vision. We offer 401K match and all company contributions are 100% vested immediately. Since we believe in work-life balance so much, we offer 20 days of paid leave per year. Use it as you need it or use it all at once and go travel for a month! There are many more - connect with us to get a preview of the full benefits package.

Role: Intermediate Security Assessor

Location: Remote (Must be available to work EST hours)

Duties & Responsibilities:

  • Conducting independent security assessments of environments (on premise, Cloud (Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)) systems) and applications. Analyze existing security process including automation, security service delivery models. Provide system administration support to the GRC module, to include upgrades, patching, and account management.

Duties include:

  • Developing and maintaining the master assessment schedule and schedule security assessments

  • Leading and conducting assessment meetings as required

  • Leading and conducting independent assessments of security controls as documented in the System Security Plan (SSP)

  • Leading and conducting risk assessments based on findings of security controls assessments

  • Developing Security Assessment Report (SAR), documenting Plans of Action and Milestones (POA&Ms), and developing Executive Summaries (ES)

Qualifications:

  • 4 year degree (Bachelors Degree) from an accredited College or University in Business/Engineering

  • Minimum of 8 years of experience in listed tasks

  • Need (or contingency to have within 8 months) ISC2 Certified in Governance, Risk and Compliance (CGRC) (Formerly CAP) or industry equivalent certificate.

  • Must have or be eligible to obtain a Public Trust Clearance

Technical Skills:

  • Experience with RMF and applying the NIST Cybersecurity Framework.

  • Experience using CSAM in an RMF Assessor role.

  • Solid understanding and application of NIST Special Publications including SP 800-53, SP 800-137, SP 800-171, and SP 800-37.

  • Experience with Federal Risk and Authorization Management Program (FedRAMP).

  • Experience with assessing systems and applications deployed in local and cloud environments following federal guidelines and best practices.

  • Ability to work with cooperatively and at a technical level with developers, engineers, and managers on system teams.

  • Knowledge of computer networking concepts, protocols, and network security methodologies.

  • Knowledge of risk management processes and tools (e.g., methods and tools for assessing and mitigating risks).

  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy in a federal environment.

  • Knowledge of current and past cybersecurity threats and vulnerabilities.

Professional Skills:

  • Ability to effectively manage and prioritize multiple tasks and duties simultaneously while effectively coordinating and ensuring that scheduled delivery dates and milestones are achieved.

  • Able to communicate effectively in a accurate and concise manner through written and verbal means to system teams and product and cybersecurity leadership.

  • Ability to take initiative on assigned systems and related tasks and work with minimal supervision.

  • Ability to work and collaborate as part of an integrated team with diverse backgrounds.

***Saliense Consulting LLC provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.