NewInformation Assurance Support Analyst Axient LLCInformation Assurance Support AnalystRockville, MDKnowledge of major cloud platforms (Azure/ Amazon Web Services [AWS]), virtualization, networking devices (e.g., routers and switches), web services (e.g., IIS, Apache Tomcat), network security appliances (e.g., firewalls, VPNs), databases (e.g., Microsoft SQL), and intrusion prevention/ anti-malware software. This includes security categorizations, digital identity risk assessments, system security plans, system policy and procedures, privacy impact assessments, contingency plans, configuration management plans, incident response plans, vulnerability assessment reports, deviation requests, and any other documents necessary to support systems' authorization and continuous monitoring.
Jr. Information Assurance Specialist Soft Tech ConsultingJr. Information Assurance SpecialistSuitland, Maryland$85,000–$120,000 / yearWith contracts in both the public and private sectors in the DC metro area and across the country, Soft Tech is an organization made up of highly successful and talented Information Technology professionals offering enterprise class solutions for any size organization at great value. Define policies to ensure and audit control of system access, user accounts, and other best practice security controls are in place to maintain existing Authority To Operate (ATO), physical security, and required protection of sensitive or classified information.
SECURITY & COMPLIANCE ENGINEER (SCE) Zermount, IncSECURITY & COMPLIANCE ENGINEER (SCE)Arlington, VAFull timeAt least one of the following security certifications is required:Certified Authorization Professional (CAP)Certified Information Security Auditor (CISA)Certified Information Security Manager (CISM)Certified Information Systems Security Professional (CISSP), or Certified Chief Information Security Officer (CCISO)Governance Risk & Compliance Certification (CGRC)Or alternatively approved certificationsClearance LevelMinimum of active Secret Clearance and ability to obtain and maintain DHS suitabilityWORK LOCATIONThe position is primarily remote - Continental U.S onlyPrimary location when on site: Arlington, VA, and Springfield, VA Must be willing to travel - Not to exceed 10% of the time HOURS OF OPERATION8:00 am EST - 4:30 pm EST Times may fluctuate based on client and business requirements REPORTING STRUCTURE Reports To: Security Compliance Engineering Team Lead Direct Reports: N/A reported complianceTranslate NIST, EO 14028, OMB, and TIC 3.0 requirements into specific technical remediation actions Validate remediation actions with repeatable verification methods (not documentation review) Produce executive-quality outputs (risk findings, remediation plans, executive summaries) Maintain system artifacts and documentation only as a byproduct of validated technical workSUBJECT MATTER EXPERTISE (SME) SME Area #1 - Primary Expertise: Technical Risk Validation (Modern GRC Execution)Expert-level means:Ability to independently assess systems using direct technical inspection techniques, leveraging logs, configs, architecture documents, etc.
OT Security Architect Segmentation & Compliance PeopleNTech LLCOT Security Architect Segmentation & ComplianceAlexandria, VAThe role involves performing due diligence on the current state to define strategy and roadmap, conducting healthchecks per OEM and industry best practices, and creating metrics reports and dashboards for executive and operational consumption. The incumbent will be a senior expert who solutions requirements, designs architecture, defines HLD and LLD, collaborates with customers, and leads / executes implementation of security projects.
Senior Security Governance and Policy Analyst LinTech GlobalSenior Security Governance and Policy AnalystWashington, DCFull timeThis plan is available for inspection upon request.http://Lintechglobal.com/wp-content/uploads/2017/09/poster_screen_reader_optimized.pdf#DICE#LI-LM1This role requires an active Top Secret Security Clearance, customer approval, and successful completion of a pre-employment background screening. Certification Requirements: CISSP/CISM.Clearance Requirements: TS/SCI with CI PolygraphCompany DescriptionDexian Government Solutions is an award-winning, ISO 9001:2015 certified, business and GSA contract holder providing diversified Information Technology services to both Civilian and Defense agencies.
Security Specialist IV Semper Valens SolutionsSecurity Specialist IVFort Belvoir, VAFull timeResponsibilities:Provides the highest level of technical expertise related to a DoD client's security and program protection operations team and responsibilitySupports the client by providing security expertise and hands‐on experience within one or more security disciplines, including personnel, physical, anti‐terrorism (AT), industrial, operations security, classification management, information security, and foreign disclosure. About Semper Valens Solutions:Semper Valens Solutions, Inc. (SVS) is a Service-Disabled Veteran Owned Small Business (SDVOSB) providing Cost Effective Software and Systems Engineering, Field Support, Training and Full Life cycle Support Management to the DOD and VA community.
Senior Security Governance and Policy Analyst Concurrent Technologies CorporationSenior Security Governance and Policy AnalystDC Metro Area, DC$145,000–$168,000 / yearConcurrent Technologies Corporation (CTC) is a nonprofit, mission-driven organization dedicated to delivering innovative science and technology solutions that advance national security and strengthen the nation's defense capabilities. This individual will collaborate with executive leadership, cybersecurity teams, system owners, and stakeholders to ensure security policies effectively protect critical systems operating in both cloud and on-premises environments.
Risk Manager, Endpoint Security Discover Financial ServicesRisk Manager, Endpoint SecurityMcLean, VA$197,300–$225,100 / yearThe Risk Manager, Endpoint Security represents a unique opportunity for those with hands-on cybersecurity technical and operational experience who have a desire to leverage and enhance that expertise in a risk management organization. This individual will have the ability to use technical skills and cyber subject matter expertise to provide effective oversight, credible challenge, and expert advice to help manage and control risk associated with cyber operations.
Security Program Manager (INFOSEC) Watermark Risk Management InternationalSecurity Program Manager (INFOSEC)Washington, DCFull timeYou’ll work across teams and integrate with other disciplines and teams for mission protection and success and serve as an expert for Classified National Security Information (CNSI), Controlled Unclassified Information (CUI), and Sensitive but Unclassified (SBU) information security programs, while supporting USCG-wide information security policy development, compliance, and training activities. Multiple considerations are taken into account when determining the final salary/hour rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor categories.
Vice President, Partnerships - Security Solutions (Gsis) MasterCardVice President, Partnerships - Security Solutions (Gsis)Washington, DCAll activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: Abide by Mastercard's security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and. The Vice President, Partnerships- Security Solutions (GSIs) is a global, quota-carrying, revenue-producing leadership role responsible for building and scaling the partnership motion across Mastercard Security Solutions, which includes cyber, fraud, and identity capabilities.
Director, Security Platform Product Management MasterCardDirector, Security Platform Product ManagementArlington, VA$156,000–$265,000 / yearAll activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: Abide by Mastercard's security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and. The role is accountable for moving approved strategy into execution by clarifying the work, validating user needs, shaping requirements, preparing prioritization inputs, partnering through design and build, coordinating adoption activities, and measuring progress against agreed outcomes.
Senior Security Risk Management Engineer LinTech GlobalSenior Security Risk Management EngineerWashington, DCFull timeThe Senior Security Risk Management Engineer provides technical leadership for:Risk Management Framework (RMF) execution Assessment & Authorization (A&A) Security control implementation Security architecture risk analysis Continuous Monitoring (ConMon) Risk assessment and mitigation Authorization package development Security engineering support to system owners The position serves as the senior technical advisor helping DHS I&A understand, document, assess, and manage cybersecurity risk across classified and unclassified environments. This plan is available for inspection upon request.http://Lintechglobal.com/wp-content/uploads/2017/09/poster_screen_reader_optimized.pdf#DICE#LI-LM1This role requires an active Top Secret Security Clearance, customer approval, and successful completion of a pre-employment background screening.
Manager, Cyber Security ICFManager, Cyber SecurityReston, VirginiaRemotePay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position. The ideal candidate has demonstrated experience supporting federal cybersecurity programs that require RMF alignment, assessment documentation, POA&M management, contingency planning, vulnerability coordination, cybersecurity reporting, and integration with engineering and product delivery teams.
Database Security Engineer American International GroupDatabase Security EngineerReston, VAAbility to understand security risks and controls, to analyze various methods of controlling information security problems, determine the strengths and weaknesses of each method and implement the best cost-justified solution. Evaluating updates to new/existing database security controls by determining the strengths/weaknesses and coordinate the testing and implementation of the new/enhanced controls with all business partners that are affected.
NewIT Security Architect - DM InfoPeopleIT Security Architect - DMNW Washington DC 20024, DCShort Description: The client is looking for an IT Security Architect to work on a team of IT project professionals to review, assess, and remediate issues across a number of initiatives across the IT portfolio. • Relies on experience and judgment to plan and accomplish goals, independently performs a variety of complex tasks, and a wide degree of creativity and latitude is expected.
Security Specialist ManTechSecurity SpecialistFort Belvoir, VAProcess new incoming Program Access Request (PAR) packages by quality-reviewing the PAR and route PAR for necessary approvals/signatures, tracking via the JADE database; and, as part of the PAR process, review DD-254s to verify individual’s authorization for program access. + Interact with customers concerning issues on PARs, Risk Assessments, programclearances, and other general information, as needed; and interact with other PERSEC offices for PAR processing/coordination.
Security Control Assessor (SCA) — Level II RividiumSecurity Control Assessor (SCA) — Level IIWashington, District of ColumbiaThe Security Control Assessor provides expert guidance on security control implementation, risk management, continuous monitoring, and authorization package development while working closely with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Engineers, Government Authorizing Officials (AOs), Security Control Assessor Representatives (SCARs), Branch Chiefs, and the DHS I&A Chief Information Security Officer (CISO). This position conducts comprehensive security control assessments for classified and unclassified information systems, cloud environments, Cross Domain Solutions (CDS), and C-LAN extension sites in support of the NIST Risk Management Framework (RMF) and DHS/Intelligence Community (IC) cybersecurity requirements.
Personnel Security Analyst / Adjudicator – Senior w/ TS/SCI with FSP VMD CorpPersonnel Security Analyst / Adjudicator – Senior w/ TS/SCI with FSPMcLean, VAPersonnel Security Analyst / Adjudicator – Senior The Senior Security Analyst is a subject matter expert who independently applies ICD 704 and EO 12968 to the most complex cases involving significant derogatory information. Minimum Requirement: Education/Experience: Bachelor’s degree (in a related study) + 5 years of relevant experience OR High School Diploma/GED + 7 years of relevant experience.
ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT SME) Zermount, IncZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME (VIRTUALIZATION AND APPLICATION DEVELOPMENT SME)Arlington, VAFull timeSUBJECT MATTER EXPERTISE SME Area #1 – Application Security, Cloud Workload Protection & DevSecOps AdvisoryExpert-level mastery of application security architecture including ZT application access control design, API security strategy, authorization gateway architecture, and DevSecOps integration demonstrated through operational implementation or senior advisory engagement in a federal or large enterprise environment. ZERO TRUST (ZT) APPLICATION DEVELOPMENT SECURITY SME POSITION OVERVIEWThe Zero Trust Virtualization / Application Development Technical SME exists to serve as the agency's primary technical advisor for the CISA ZTMM v2.0 Applications & Workloads pillar - the pillar responsible for extending ZT enforcement to the application layer across the agency's enterprise software portfolio.
Lead, Cryptographic Security Engineer MasterCardLead, Cryptographic Security EngineerArlington, VA$161,000–$266,000 / yearAll activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: Abide by Mastercard's security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and. Mastercard is developing the next generation of applications and services to enable consumers and businesses to securely, efficiently, and intelligently conduct payment transactions, and is leveraging state-of-the-art cryptographic practices to protect its assets.