Your Impact to the Mission: As a Senior Cybersecurity Specialist you will be responsible to deliver security and compliance expertise leadership to support multiple IT projects, programs, and initiatives.
You will be supporting the assessment and authorization (A&A) process, determining current security postures, tracking vulnerabilities and POA&Ms, and identifying potential cybersecurity risk.
The Senior Cybersecurity Specialist will be responsible for:
- Actively participate and lead meetings to review and assess compliance of systems and technology
- Perform risk assessments based on Federal guidelines and industry best practices
- Assist teams in identifying vulnerabilities and providing recommendations to reduce cybersecurity risk
- Create and mature control-specific procedures for RMF control families by interpreting NIST requirements, identifying system-specific implementation needs, and developing effective procedural documentation that supports both mission operations and defensible compliance.
- Articulate and report on cybersecurity risk and compliance to executives and senior leaders
- Understand Vulnerability details, both technical and control-based, and craft actionable remediation plans and mitigation strategies
- Create, maintain, and track POA&Ms – working with system owners and technical teams to identify corrective actions, document mitigations, monitor remediation progress, and support timely closure of security findings.
- Support remediation of control-based POA&Ms by analyzing control weaknesses, recommending corrective actions or mitigations, coordinating with technical teams, and reviewing closure evidence to confirm the weakness has been resolved.
- Author A&A documentation to create foundational RMF documentation to support system authorization
- Continually improve the cybersecurity risk assessment and POA&M process and program
- Aggregate and track cybersecurity POA&Ms and risks across projects, teams, and programs
- Respond to and triage security incidents as a key member of the incident response team
- Communicate cybersecurity best practices based on policies, standards, and controls
- 5+ years of cybersecurity and compliance experience
- Active Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification
- Strong leadership and interpersonal skills to facilitate effective collaboration across a variety of stakeholders