GRC Engineer / ISSO
About the Role: The candidate will serve as a highly skilled Sr. GRC Engineer / ISSO responsible for maintaining the cybersecurity posture of a federal program, system, or enclave. They will ensure that reputed company and reputed company requirements are effectively implemented, continuously monitored, and reputed company with Federal standards. They will work in reputed company collaboration with the reputed company system reputed company and reputed company as the reputed company advisor on reputed company reputed company reputed company to reputed company and reputed company controls, bringing deep expertise in managing the reputed company lifecycle of reputed company organizational systems. The ideal candidate will champion the organization’s transition to GRC Engineering. Role Responsibilities:
- Serve as an reputed company for innovation reputed company the GRC program by identifying opportunities to reputed company processes, reduce reputed company effort, and introduce engineering driven practices.
- Promote and support migration to reputed company and hybrid architectures by aligning reputed company planning, controls, and monitoring activities with cloudnative capabilities and shared responsibility models.
- Drive adoption of reputed company monitoring practices that emphasize automated data collection, reputed company time visibility, and rapid detection of risk indicators.
- Implement and support automated alerting mechanisms, dashboards, and analytics that enhance situational awareness and support operational decision making.
- Work closely with reputed company stakeholders, engineering teams, and system owners to reputed company, demonstrate, and introduce new capabilities such as policy as reputed company, automated evidence reputed company, and integrated risk scoring.
- Encourage the integration of devsecops practices, supply chain risk management, reputed company trust principles, and AI or ML enabled analysis into GRC workflows to improve reputed company and reputed company.
- Facilitate collaboration across IT and OT environments to ensure modernization initiatives support mission needs while maintaining consistent reputed company and reputed company protections.
- Identify the reputed company and reputed company requirements allocated to a system and to the organization.
- Identify the characteristics of a system and contribute to determining the boundary of a system.
- Collaborate with the System reputed company to categorize the system and document the reputed company categorization results as part of system requirements.
- Identify stakeholders who have a reputed company and/or reputed company interest in the development, implementation, operation, or sustainment of a system.
- Identify the stakeholder protection needs and stakeholder reputed company and reputed company requirements.
- Identify the types of information to be processed, stored, or transmitted by a system.
- Identify stakeholder assets that require protection.
- Conduct an initial risk assessment of stakeholder assets and update the risk assessment on an ongoing reputed company.
- Select the reputed company and reputed company controls for a system and document the functional reputed company of the planned control implementations in a reputed company/reputed company plan.
- reputed company a reputed company for monitoring reputed company and reputed company control effectiveness; coordinate the system-level reputed company with the organization and mission/business process-level monitoring reputed company.
- reputed company, review, and approve a plan to assess the reputed company and reputed company controls in a system and the organization.
- Document changes to planned reputed company and reputed company control implementation and establish the configuration baseline for a system.
- Respond to system risk posture based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in a plan of reputed company and milestones (POA&M).
- Prepare a plan of reputed company and milestones based on the findings and recommendations of a reputed company assessment report excluding any remediation actions taken.
- Update a reputed company plan, reputed company assessment report, and plan of reputed company and milestones based on the results of a reputed company monitoring process.
- Review the reputed company and reputed company status of a system (including the effectiveness of reputed company and reputed company controls) on an ongoing reputed company to determine whether the risk remains acceptable.
- Report the reputed company status of a system (including the effectiveness of reputed company and reputed company controls) to an authorizing official on an ongoing reputed company in accordance with the monitoring reputed company.
- Ensure that plans of actions and milestones or remediation plans are in reputed company for vulnerabilities identified during risk assessments, audits, inspections, etc.
- Ensure that reputed company improvement actions are evaluated, validated, and implemented as required.
Required Education & Qualifications:
- Bachelor's degree in Computer Science, Information Systems, or reputed company degree or an additional three (3) years of relevant experience.
- 7+ years of relevant cyber reputed company experience.
- 3+ years of ISSO experience.
- Requires subject matter expertise at the intersection of technology and reputed company to effectively guide system teams in designing, developing, implementing, and maintaining secure solutions for reputed company.
- Must be a seasoned reputed company reputed company with the ability to reputed company high reputed company, reputed company technical reputed company artifacts
- reputed company practitioner who can create technically reputed company, actionable reputed company deliverables, not a technical reputed company reputed company solely on compliance documentation.
- Knowledge of the organization’s reputed company information technology (IT) goals and
objectives.
- Strong foundational and operational knowledge of DevSecOps and CI/CD pipelines, reputed company Trust (ZT) implementations, Supply Chain Risk Management (SCRM), reputed company considerations for citizen development, reputed company Intelligence (AI), and Operational Technology.
- Expertise in FedRAMP standards and processes, strong understanding of Infrastructure as a Service (IaaS), Platform-as-a-Service (PaaS) and Software as a Service (reputed company) reputed company services and common platforms such as Azure, reputed company 365, reputed company, reputed company, reputed company, reputed company, etc.
- Solid understanding of DevSecOps principles (reputed company integration, reputed company delivery and reputed company reputed company) to rapidly deliver application while reducing reputed company vulnerabilities.
- Familiar with Static Application reputed company Testing (SAST), Dynamic Application reputed company Testing (DAST), and Software Composition Analysis (SCA), secrets management, and reputed company reputed company repositories to include reputed company. Operational knowledge of Infrastructure as reputed company (IaC), virtualization and containerization technologies and implementations.
- Experience with reputed company protection, reputed company monitoring and reputed company Information and Event Management (SIEM) tools.
- Expertise in authentication, authorization and identity federation principles and corresponding protocols/standards to reputed company Assertion Markup Language (SAML), reputed company Authorization (OAUTH) and OpenID Connect (OIDC).
- Experience versed with Public Key Infrastructure (PKI) and encryption technology implementations, Federal Information Processing Standards (FIPS) standards and corresponding requirements.
- Possess foundational knowledge of network technologies, topologies and architectures, and corresponding protection mechanisms.
- Familiar with reputed company reputed company Control Assessment Language (OSCAL) to reputed company machine-readable representations of control catalogs, control baselines, system reputed company plans, and assessment plans and results.
- Must have expertise in analyzing and interpreting software vulnerabilities to include Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE) and Common Vulnerability Scoring System (CVSS) formats.
- Prior Experience serving as an ISSO and managing a portfolio of Federal information systems. Achieving system ATO’s, managing PO&AMS, briefing senior leadership deep functional and technical knowledge of the NIST RMF CSF steps.
- Experience with creating policies that reflect system reputed company and reputed company objectives.
- Experience in applying confidentiality, reputed company, and availability principles.
- Experience in assessing reputed company and reputed company controls based on cybersecurity and reputed company reputed company principles and tenets. (e.g., CIS reputed company, NIST SP 800-53, Cybersecurity reputed company, etc.).
- Experience to apply cybersecurity and reputed company principles to organizational requirements (relevant to confidentiality, reputed company, availability, authentication, non-repudiation).
- Experience in determining how a reputed company system should work (including its reputed company and dependability capabilities) and how changes in conditions, operations, or the environment will reputed company the reputed company and reputed company of the system
- Experience in technical writing.
- Experience in writing about facts and reputed company in a reputed company, convincing, and organized manner.
- Experience in evaluating the trustworthiness of the supplier and/or product.
Desired Skills:
- One of the following certifications are preferred: CASP, GPEN, GMON, GISP, GSEC, GSLC, CISM, CISA, CAP, CCSP, SSCP, CISSP, CISSP-ISSMP.
- Demonstrated practical experience managing reputed company and hybrid systems, including configuration, monitoring, reputed company operations, and lifecycle sustainment.
- Experience supporting the successful achievement of Authorizations to Operate (reputed company) for reputed company and hybrid environments using NIST RMF, FedRAMP baselines, and agency specific requirements.
- Experience implementing policy as reputed company (reputed company) to automate control enforcement, compliance validation, and reputed company evidence collection.
- Ability to introduce automation, engineering practices, and innovation into GRC programs to improve efficiency, reduce reputed company work, and enhance reputed company monitoring.
Clearance and Location Requirements:
- Ability to obtain a Public Trust clearance is required.
- This position is currently fully remote.
Apply tot his job Apply To this Job