NuCrest is seeking an Information Assurance Auditor to join our team in Washington, DC.
The Information Assurance Auditor will conduct security control assessments, using the National Institute of Standards and Technology (NIST) Risk Management Framework, the security status of existing information systems with an Authority to Operate (ATO), perform appropriate assessments on any new system developed or deployed by OIG that falls within the scope of this contract, and to ensure continuous monitoring of all systems. Assess systems that have previously been assessed and received an ATO and systems that have not yet been assessed and do not have an ATO.
Assist in developming a Security Control Assessment (SCA) strategy for the organization; to include an overall assessment process flow or swim-lane diagram which documents the steps required to conduct assessment activities and interact with all necessary parties.
Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs)
Work closely with ISSOs (contractors and Government) and the technical team and ensure all appropriate A&A supporting documentation is provided prior to conducting the assessment.
Develop associated schedules and resource plans to complete the assessments.
Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization.
Review cyber/system/network security body of evidence and documentation for accuracy and completeness
Review and provide assurance that applicable security controls are implemented correctly across systems
Identify and document the appropriate security assessment level of effort and project management information to include tasks, reviews (including compliance reviews), resources, due dates, and milestones for the system being tested
Include an overall assessment process flow or swim-lane diagram which documents the steps required to conduct assessment activities and interact with all necessary parties (including but not limited to: System Owners, CIO, ISOs, IT Support, System Administrators).
Conduct Security Assessment Kickoff briefings and SAR briefings
Assess implemented security controls and provide assurance that they are operating as intended.
Perform independent verification and validation (IV&V) of each system and provide an authorization recommendation based on determination of risk to agency; IV&V will include unprivileged and privileged scans against each applicable system and unprivileged and privileged database scans against each applicable database management system (DBMS).
Perform quality control on the assessment and associated deliverables
Conduct Post Assessment Meetings with the customer
Provide Plan of Action and Milestones (POA&M) management to ensure has mitigated or is working to mitigate all vulnerabilities in a timely fashion and within policies
Develop a Continuous Monitoring Plan including a schedule to perform ongoing security assessments once the initial assessments are complete.
Perform continuous monitoring to ensure implemented security controls remain functional throughout the lifecycle of the information system.
6+ years expert experience performing security testing, security control assessments, security configuration testing, vulnerability scanning
6+ years of experience with developing and documenting the Rules of Engagements (ROEs), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs)
6+ years of experience and expert knowledge of the FISMA, FIPS, Risk Management Framework, Cybersecurity Framework, other NIST A&A publications, and other IT Security Federal law and regulations.
6+ years of experience utilizing NIST 800-53 and 800-53A
Familiar with cloud environments (services/security) and the FedRAMP A&A process.
Expert knowledge and skills to perform, document, write the results of the security assessment report. Knowledge of VA and VA OIG IT Security policies/guidance and required templates a plus.
Strong experience assessing and providing recommendation on the following: Privacy Impact Assessment, Risk Assessment, System Security Plan, Disaster Recovery / Contingency Plan, and Incident Response Plan.
Strong knowledge of the Systems Development Life Cycle (SDLC) and its application in the development of technology solutions
Significant experience with tools such as Nessus, Web Inspect, Db Protect and Splunk.
Strong technical background with Windows, Unix, legacy systems, databases, web servers/applications, cloud and virtualization environments.
Effective verbal and written communication skills with ability to effectively communicate with all levels of users and teammates both written and verbally.
Effective technical writing and documentation processing skills.
Strong project management, time management,and work sequencing skills.
Ability to work on the customer site 2-3 days a week in the DC area and travel to customer sites in Martinsburg, WV; Austin, TX; and Hines, Ill.
One of the following certifications: CISA, CISSP, C/EH, GSNA, CAP, CASP, CISM, GSLC. CISSP, CISA, and C/EH preferred
All professional certifications and CPE credits must be up to date each year for validation by the customer
Work Core Hours:
NuCrest, LLC is a minority-owned Service-Disabled Veteran-Owned Small Business (SDVOSB)/Small-Disadvantaged Business (SDB) based in Anne Arundel County, Maryland focuses on delivering a diverse portfolio of security-focus IT Enterprise Services and Solutions to support the critical missions of Federal and Civic clients. We deliver our services across multiple enterprise platforms, data networks, and cloud environments.
At NuCrest we support our Veterans and encourage all to apply!
NuCrest provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.