Job title: - Information Security Analyst – III Location: - Richmond, VA 23219 Duration: - 18 months
Job Description: - Security Compliance and Assessment Advisor - Experienced Position Overview:
The Security Control Assessor plays an integral role in ensuring that an organization’s information systems are evaluated for security risks and vulnerabilities, aligning with established information security policy and standards.
This position involves a thorough examination of security controls, policies, and procedures to identify any weaknesses that could potentially be exploited. By conducting comprehensive assessments, the Security Certification Assessor provides essential insights and recommendations to enhance the security posture of the organization.
Their expertise supports the development of strategies to mitigate identified risks, ensuring the protection of sensitive information and the integrity of IT systems.
Through their work, the Federal Reserve system is better equipped to navigate the complex landscape of cybersecurity threats, maintaining compliance with SAFR requirements, and safeguarding assets.
Key Responsibilities:
Conduct thorough evaluations of information security controls to identify potential threats and vulnerabilities to the Systems information systems.
The process includes a detailed review of security controls, policies, and procedures to prioritize risks and recommend enhancements that support organizational security goals
Reviews data and assists in advising districts on best practices and how to implement the necessary changes to address their business and information security needs.
Key participant in project development surrounding new processes and the integrating of new processes with existing ones. Assists in developing communications of these changes to impacted clients and other resources.
Performs other related duties as assigned.
Working Conditions:
Will require the use of standard office equipment such as computers, phones, photocopiers, etc.
Physical Demands: Requires some degree of sitting (for prolonged periods of time), standing, lifting carrying, pushing, pulling less than 20 lbs.
Hours of Work:
May require extended work hours. The ideal candidate will work a hybrid schedule and be in a district office two days a week. Occasional travel including overnight stays may be necessary.
Required Qualifications:
Bachelor’s degree in computer science, Information Security, or equivalent experience with 3 to 5+ years of relevant work experience
Proven experience with conducting security assessments
Knowledge of compliance frameworks and continuous authorization processes. Prefer NIST SP800-37, SP800-53/53a.
Excellent communication skills and the ability to work collaboratively.
Reviewing data and advising customers on SAFR requirements and best practices
Building strong collaboration and negotiation relationships
Poses creativity, attention to detail
Understands and applies the risk management discipline in decision making and contributes to the functional area’s risk management
Preferred Qualifications:
Certifications such as CISSP, CISA, CISM.
Experience in a policy and assurance or quasi-governmental environment
Familiarity with cloud service providers and associated security challenges
Knowledge of SAFR lifecycle compliance and testing
The candidate must possess skills that include experience with:
Reviewing data and advising customers on SAFR requirements and best practices
Building strong interpersonal collaboration, negotiation, creativity, attention to detail, and communication relationships
Numbers & Facts
Location
Richmond, VA
Skills
Best Practicesunmatched
CISA - Certified Information Systems Auditorunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Scienceunmatched
Computer Securityunmatched
Copying Machinesunmatched
Detail Orientedunmatched
Establish Prioritiesunmatched
Information Technology & Information Systemsunmatched
Information/Data Security (InfoSec)unmatched
Internet Securityunmatched
Interpersonal Skillsunmatched
Maintain Complianceunmatched
Negotiation Skillsunmatched
Office Equipmentunmatched
Photocopyunmatched
Physical Demandsunmatched
Policy Developmentunmatched
Project Developmentunmatched
Regulatory Complianceunmatched
Risk Analysisunmatched
Risk Managementunmatched
Security Analysisunmatched
Security Complianceunmatched
Security Policyunmatched
Strategic Planningunmatched
Systems Analysisunmatched
Team Playerunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Willing to Travelunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.