• Skip to main content
  • Skip to primary sidebar

ConvoCourses

Cyber Security Compliance and IT Jobs

  • Cyber Security Training
  • about me.
  • Information Assurance Jobs

information system compliance

cybersecurity compliance project manager alexandia VA job

February 22, 2020 by cyberaware2 Leave a Comment

check out the courses:
http://convocourses.com

Job Title: #Cybersecurity #Compliance Project Manager
Job Location: Alexandria, VA, US
Project Length: Long Term

Clearance Requirement: Active Secret clearance.

Key Role:
Serve as a Task Lead responsible for the creation of a Cybersecurity Governance, Risk, and Compliance (GRC) team assessment program for a DoD organization. Design, develop, and implement the assessment program independently to measure Cyber GRC metrics, determine readiness for audits and inspections based on DoD policies and NIST standards, identify risks, and provide automated remediation plans. Work to improve communication and enhance the organization’s security posture through risk assessment preparation. Perform blind, non-punitive readiness assessments for organizational units to provide a preparatory remediation plan for upcoming inspections. Measure the effectiveness of the GRC programs and provide leadership with an unfiltered view of the organization’s security posture, measuring the balance between its objectives and risk profile. Recommend strategic enhancements and structural improvements for a compliance division.

Basic Qualifications:
10+ years of experience with Cybersecurity.
Ability to design, develop, and manage the implementation of risk assessment process methodology and tools, including eMASS.
Ability to communicate effectively and professionally in a fast-paced client-environment.
BA or BS degree in a Technology, IT, or Cybersecurity field.
DoD 8140 and 8570 IAM level II Certification.

Additional Qualifications:
Experience with GRC and assessment processes.
Experience with DoD 8500 series, NIST SP 800 series, DoD regulations, and instructions, including DoDI 8140-01, DoDI 8530.01, CJCSI 6510.01, and the Risk Management Framework (RMF).
Experience with briefing senior government officials at the General Officer and SES-levels.
PMP Certification.

Direct: 703-653-0218
karthik@param-solutions.com
https://recruiting-as-a-service.param…

https://param-solutions.com/careers

Filed Under: cyberspace workforce, DIARMF Jobs, Information Assurance Jobs, information system compliance, IT Security Jobs, Risk Management For DoD IT, security compliance Tagged With: 8570, and the Risk Management Framework (RMF), CJCSI 6510.01, cybersecurity compliance, dod 8530, DoDI 8140-01, DoDI 8530.01, emass, grc, nist 800, NIST 800-37, NIST 800-53, pmp, program management, security compliance

Data Security Analyst State of Colorado denver RMF NIST JOB

February 1, 2020 by cyberaware2 Leave a Comment

check out the course:
http://convocourses.com

Check out the job:
Job Details:
Job title: Data Security Analyst (0000076025)
Location: Denver, #Colorado(80203)
Estimated Duration: 01/13/2020 – 09/30/2020

Job Description:
Reports to the Director of Security Risk and Compliance or Delegate to perform activities for the oversight of the risk and compliance program.
Perform activities to reduce vulnerabilities for the overall enterprise risk management program.
Performs duties to facilitate confidentiality, integrity, and availability of systems to protect data from unauthorized users.
May require a bachelor’s degree in area of specialty and at least 5 years or more of risk management, experience working in a complex environment, and assessment of internal controls.
Has knowledge of commonly-used concepts, practices, and procedures in accordance with the #NIST #RMF (risk management framework).
The specialized individual must have previous experience with implementing an enterprise risk management (ERM) framework and applicable certifications such as CISSP, CISA, or CISM.
In addition, experience working with a Governance Risk and Compliance tool is highly desired, but not a must-have.
This individual should be a self-starter, able to provide consultative advice and able to work autonomously.

Thanks,
Have a wonderful day!!
Maddy |Technical Recruiter | Email: v.madhuri@softpath.net
Direct: 678 783 7352| Ext. 522 | Softpath System LLC | 3985 Steve Reynolds Blvd | Bldg C Norcross GA 30093 www.softpath.net
Linkedin: https://www.linkedin.com/in/maddy-johnson-270220136/

Filed Under: information system compliance, IT Security Jobs Tagged With: CISSP, colorado, denver, enterprise risk management (ERM), nist, risk managment framework, rmf, state

POAM (an overview) Part 1

April 23, 2019 by cyberaware2 Leave a Comment

Check out the courses at: https://securitycompliance.thinkific.com

Here is the POAM template I was looking at:
https://www.fedramp.gov/developing-a-plan-of-actions-milestones/
https://www.fedramp.gov/assets/resources/templates/FedRAMP-POAM-Template.xlsm

PM-4 PLAN OF ACTION AND MILESTONES PROCESS
The organization:
a. Implements a process for ensuring that plans of action and milestones for the security program and associated organizational information systems:

1. Are developed and maintained;

2. Document the remedial information security actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation; and

3. Are reported in accordance with OMB FISMA reporting requirements.

b. Reviews plans of action and milestones for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.

Filed Under: DIARMF, diarmf - implement, information system compliance, security compliance Tagged With: plan of action and milestone, POAM

information assurance engineer maryland Aberdeen

April 16, 2019 by cyberaware2 Leave a Comment

check me out on:
https://securitycompliance.thinkific.com

the Job:
Job Title: Information Assurance Engineer
Location: Aberdeen, MD
Position Type: Full Time

Clearance: Minimum Interim Secret

Must Have IAT Level 3 Certification.

Job Description:
Provides security engineering designs and implementation in all aspects of Information Assurance and Information Security (InfoSec) Engineering.
Assesses and mitigates system security threats/risks throughout the program life cycle; validates system security requirements definition and analysis; establishes system security designs; implements security designs in hardware, software, data, and procedures;
verifies security requirements; performs system certification and accreditation planning and testing and liaison activities, and supports secure systems operations and maintenance.
Mandatory Skills:
Demonstrated experience performing IA activities in support of software and system requirements, design, development, testing and sustainment
Experience with employment of IA requirements, policies, and processes to include authorization and accreditation as part of the RMF process
Experience with risk and vulnerability assessments and mitigation
Demonstrated ability to provide guidance on Intelligence Community (IC) Cyber/IA regulations and requirements to senior customers, senior LM leaders, and the program engineering staff
Experience with Security Information and Event Management (SIEM) correlation tools, Scanning (Nessus), and Host Based
Security System (HBSS)
Please provide the following information
Rate Expectation:
Full Name:
Contact No:
Alternate contact (if any):
Email address:
Current Location:
Relocation:
Availability:
Visa status

Kindly share your detailed resume at zoeyw@etalentnetwork.com

If you are qualified and interested in making a change or know of a friend who might have the required qualifications, please call me ASAP at (877) 733-3555 Ext.267, even if we have spoken recently about a different position. If you do respond via e-mail please include a daytime phone number so I can reach you. In considering candidates, time is of the essence, so please respond ASAP. Thank you.

Sincerely yours,
ZoeyWest
E TalentNetwork

Home


8251 Greensboro Drive, Suite 250
McLeanVA
zoeyw@etalentnetwork.com
(877) 733-3555 Ext.267

Filed Under: cyberspace workforce, Information Assurance, Information Assurance Jobs, information system compliance, IT Security Jobs, risk jobs, Risk Management For DoD IT, security compliance Tagged With: 8570, cyber, cybersecurity, HBSS, IA, IAT, information assurance, information assurance engineer, infosec, maryland, nessus, Risk Management Framework (RMF) for DoD Information Technology (IT), rmf, security engineer, SEIM, SIEM

Senior Advanced Splunk IT Specialist

April 1, 2019 by cyberaware2 Leave a Comment

Check out how I am able to get all these offers:
https://securitycompliance.thinkific.com

More on that #splunk job:
Sr Advanced Splunk / IT Security Specialist
https://careers-gd-ais.icims.com/jobs…
POC:
quan.nguyen@gd-ms.com
443-755-8136 (O)

Bachelor’s degree in a related specialized area or equivalent is required plus a minimum of 8 years of relevant experience; or Master’s degree plus a minimum of 6 years of relevant experience.
Knowledge Skills and Abilities:
Senior Splunk Administrator
Advanced knowledge of backend operating systems to implement, maintain, configure, and remediate issues (UNIX/Linux/Windows)
Knowledge of operating systems and networking.
Understanding of SIEM & logging fundamentals.
Understanding of SOC Monitor and Response fundamentals.
Experience in any type of SIEM – Splunk, Arcsight, Log Rhythm, etc.
Experience with implementation of SIEM products and tools.
Understanding of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc.
Knowledge of various operating system flavors including but not limited to Windows, Linux, Unix
Knowledge of applications, databases, middleware to address security threats against the same.
Proficient in preparation of reports, dashboards and documentation
Excellent communication and leadership skills
Ability to handle high pressure situations with key stakeholders
Good Analytical skills, problem solving and Interpersonal skills
Working knowledge and experience with MS office with proficiency in Excel

Preferred degree types and experience:

The leading candidate will have a Bachelor’s Degree in Computer Science, a related field, or equivalent experience. with a minimum of 5 years of experience in a SOC, or an Associates Degree in Computer Science, Information Systems, Cyber Security, or related discipline with a minimum of 7 years of experience in a SOC. Strong candidates will have previous experience working with users; possess a talent for problem-solving as well as organization and time management skills.

Filed Under: cyberspace workforce, Information Assurance Jobs, information system compliance, IT Security Jobs Tagged With: ArcSight, Linux, security job, SIEM, SOC, splunk, unix

Remote Work Cyber security Architect

October 22, 2018 by cyberaware2 Leave a Comment

For more on cybersecurity:
http://securitycompliance.thinkific.com

CyberSecurity Architect (remote work)
I would really appreciate if you can give me a call back at my contact # 302-401-6677 Ext- 330.

Job Title Remote position-Information Security Architect
Location Philadelphia PA
Duration 6 months /Contract

JOB DESCRIPTION

Interview Mode-Phone and Skype
Needs USC or GC Only

This role will be able to work remotely but the idea is someone in the Philadelphia area to be able to come in once/week.
If they are further away, it would be less than that.
The manager is open to remote candidates but they need to be in the Eastern Standard Time Zone.

Description:

[Information Security Architect]

Brief description of the role

• Collaborate with Security Architecture and Information Security leadership to help guide the Security Architecture Program
• Collaborate with and influence technology leaders and stakeholders to produce solutions and architectures

Key deliverables but not limited to:

• Interpret Information Security requirements, Policies, and Standards to help ensure delivery of secure IT solutions
• Identify and deliver strategic initiatives that drive revenue and improve efficiency, aligned with business strategy
• Develop technology visions and strategies that support and enhance the business strategy
• Cultivate relationships with business stakeholders and IT leadership
• Communicate architectural plans and strategies
• Develop, communicate, and deploy Enterprise Architecture processes, reference architectures, and technical standards/strategies
• Recommend and arbitrate between technical choices that best serve the enterprise needs and adhere to IT’s guiding principles
• Advocate and practice enterprise architecture as well as security solution architecture best practices
• Develop solutions for the enterprise and business application IT segments
• Create and maintain technology standards, strategies, and roadmaps for the enterprise
• Research and recommend current and future technologies by tracking trends and industry best practice
• Maintain in-depth knowledge of the organizations technologies and architectures
• Contribute to the enterprise technology roadmap
• Evaluate and assess new technologies

Key relationships

• Security Architecture Leadership
• Information Security Leadership team
• Information Technology Leadership and team
• Business technical team

High level skills:

• Change and Adaptability
• Client Focus
• Business Acumen
• Results Focus
• Broad knowledge of Information Security, IT and industry best practices
• 10 + years or equivalent experience
• Excellent written communication and presentation skills

High level technical skills

• Network Security
• Network Hardware Configuration
• Network Protocols
• Networking Standards
• Supervision
• Conceptual Skills
• Decision Making
• Informing Others
• Functional and Technical Skills
• Dependability
• Information Security Policies and Standards

Key Requirements
• Acquire a complete understanding of a company’s technology and information systems
• Plan, research and design robust security architectures for any IT project
• Full understanding of a vulnerability testing, risk analyses and security assessments
• Research security standards, security systems and authentication protocols
• Develop requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related network devices
• Full understanding of public key infrastructures (PKIs), including but not limited to use of certification authorities (CAs) and digital signatures (key management is a must)
• Prepare cost estimates and identify integration issues
• Review and approve installation of firewall, VPN, routers, IDS scanning technologies and servers
• Review final security structures to ensure they behave as expected
• Provide technical supervision for (and guidance to) a security team
• Define, implement and maintain corporate security policies and procedures
• Assist when required to security-related incidents and provide a thorough post-event analysis
• Recommend on update and upgrade security systems as needed
• Understanding of the Cloud security, predominantly Microsoft Azure cloud and Oracle cloud, special security needs for cloud systems

Qualifications:

• CISSP (required)
• CISSP-ISSAP (preferred)
• CEH (optional)
• CISA/CISM (optional)

The 3 main components to this role are:
1) Networking knowledge
2) Security knowledge
3) Writing/Communication

Note: Travel is not required, but could be an option.

Filed Under: cyberspace workforce, Information Assurance, Information Assurance Jobs, information system compliance, IT Security Jobs, risk jobs, Risk Management For DoD IT, security compliance, STIGS Tagged With: IT, IT work, Remote Work, Remote Work Cyber security Architect

  • Go to page 1
  • Go to page 2
  • Go to Next Page »

Primary Sidebar

search


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book


This book is an overview of how the NIST SP 800-37 risk management framework works from the perspective of an information system security officer (ISSO).

also available on Amazon!

View Book

NIST RMF 800-37 templates
Free 800-37 templates

The NIST 800 Template download contains a .doc file template and xls templates for POAMs, Federal, State, cloud based and a legacy template as well as resources where you can find more on NIST 800-37 documents for your use.

View Book

Learn to Make 6 Figures in CyberSecurity

RMF ISSO Foundations Training
RMF ISSO Foundations Training

RMF ISSO Foundations

I was an Information System Security Officer (ISSO) doing Risk Management Framework (NIST SP 800-37) for over a decade. I am a Cybersecurity veteran and I can explain (in plain English) what you DO in the Risk Management Framework process as an ISSO.

View Course

NIST SP 800-37 Presentation
NIST SP 800-37 Presentation

View Course

login

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Posts

  • Convocourses Podcast: Plan of Action and Milestone
  • Start with These IT Certifications (Part 1)
  • How to Tailor Security Controls in NIST 800
  • #cybersecurityjobs are recession proof
  • What IT Certifications for Information Security (part 2) (8140)

Meta

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Comments

  • http://Www.Finance.Ipt.Pw/ on SRG/STIG Applicability Guide and Collection Tool Update
  • Elsa7 on ConvoCourses podcast: Cyber Security day to day activity
  • Tony on STIG Update – DISA has released the Microsoft SQL Server 2016 STIG Version 1
  • horloge on SCAP Compliance Checker SCC)
  • 218 Information assurance Success Criteria – ITSECURITYSURVIVAL.COM on Information Assurance Vulnerability Alert

Tags

8140 8570 ArcSight c&a CISSP convocourses cyber cybersecurity cyber security DIACAP DIARMF diarmf - implement disa DISA STIG dodd 8140 dodd 8140 cyberspace workforce IA implement implementation info assurance information assurance information security ISSO IT it jobs it jobs in usa job jobs Linux mcafee network nist nist risk management framework nist risk management framework 800-37 podcast risk risk assessment risk management risk management framework rmf security STIG stigs unix windows


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book

Copyright © 2023 · Author Pro on Genesis Framework · WordPress · Log in