Control Validation Security Specialist
Control Validation Security Specialist
Responsibilities and Duties:
Under general supervision, performs IT audits on complex information systems, applications, and enclaves to ensure that appropriate controls exist, are correctly implemented, and that procedures comply with Federal and DOD standards.
Conducts accurate evaluation of the level of security required.
Performs procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction.
Provide guidance and assistance in the formulation and implementation of audit readiness issues requiring new approaches, establishment of precedents, or the interpretation of controversial law, regulation, or past practice.
Supports the Financial Statement Audit, Annual Statement of Assurance, SSAE-18 Audit, and the Audit Logging eOPR.
Provides technical support in the areas of vulnerability assessment, risk assessment, network security, and security implementation.
Provides technical evaluations of customer systems and assists with making security improvements.
Conducts cybersecurity control validation exercises on unclassified networks, applications, and systems to validate the effectiveness of current security measures.
Understands the concept of weighing business needs against security concerns and analyzes applied mitigations to evaluate whether they meet security requirements.
Basic Qualifications:
Two (2) years of experience working with DOD1 8500.2 or NIST SP 800-53 and understanding of the principles of the risk management framework.
Strong analytical and problem-solving skills for resolving security issues.
Proficiency in basic analytical software such as Microsoft Excel and Access, proficiency with the Microsoft Office suite, to include Word, PowerPoint
Understanding of Enterprise Mission Assurance Support Service (eMASS)
Understands the concept of weighing business needs against security concerns.
Experience analyzing applied mitigations to evaluate whether they meet security requirements.
Knowledge of RMF (800-53 rev5)
Experience with technical report writing and ability to provide evidentiary matter associated with findings and recommendations
Relevant certification from a nationally recognized authority
DoD Approved 8570 Baseline Certification: Category IAM-I or minimum of IAT-II
Preferred Qualifications
Previous SCAR or Auditor experience preferred.
Associates or higher degree preferred
Previous experience with FISCAM 2024 a plus.
Knowledge of Enterprise Log Management Systems and other systems as appropriate for log reviews, also a plus.
Pay Range
$85,000—$95,000 USD