[SJ-JOB] Compliance Officer, Pentagon City
[email protected] 18 Nov 2008 00:10:28 -0000
| Newsgroups | gmane.comp.security.jobs |
|---|---|
| Message-ID | <[email protected]> |
--------------------------------------------------- SECURITYFOCUS JOBS - NEW OPPORTUNITY --------------------------------------------------- JOB DESCRIPTION --------------------------------------------------- Position: Compliance Officer Location: Pentagon City, Virginia, United States Type: Permanent F/T Closing Date: 2008-12-12 FISMA Compliance Analyst (449)=0D =0D Applicants selected will be subject to a government security investigatio= n and must meet eligibility requirements for access to classified informa= tion. Must be clearable to the Top Secret level. =0D =0D IT Security’s FISMA Compliance team is responsible for monitoring TS= A Information Systems during the 4 phases of Certification and Accreditat= ion (C&A) in order to assess their compliance with the FISMA metrics set = forth by DHS. These ever-evolving metrics currently include Annual Testin= g, POA&M Management, C&A, and Program Management. FISMA Compliance is als= o frequently tasked with short term, tight-deadline, ad hoc projects span= ning all aspects of IT Security. Project deliverables include presentatio= ns, manuals, reports, mass information dispersion, spontaneous training, = research projects, etc. The content of this work includes the analysis of= privacy information, C&A artifacts, various security statistics, financi= al/budgetary statistics, and more. =0D • Assist in ongoing training efforts for TAFT, RMS, FISMA and other = DHS/TSA related IT Security mandates which may include developing and pre= senting briefings given to an audience of other IT professionals. =0D • Participate in the development and maintenance of reports (mostly = MS Excel) which serve to monitor and track multiple FISMA related metrics= . =0D • Analyze DHS-issued fiscal year policy documentation to determine t= he upcoming annual metrics TSA must follow and enforce. =0D • Use and maintain expertise in Trusted Agent FISMA Tool (TAFT) and = the Risk Management System (RMS). Tasks include data research, report cre= ation, account maintenance, data entry, file upload/downloading, etc.=20 JOB REQUIREMENTS --------------------------------------------------- Must possess 5 years dedicated security experience. BS Degree preferred. = =0D =0D • Ability to and interest in providing support and guidance to ISSO/= SO’s through the four phases of C&A, including monitoring C&A artifa= ct compliance, annual self-assessment (NIST 800-53A) completion, vulnerab= ility scans, annual contingency plan testing, and POA&M management. Must = possess experience with FISMA. =0D • Able to assist with other ISSO responsibilities including document= ation, policy compliance, and CM review, as well as user training. =0D • Working knowledge of Microsoft Office Suite (to include Excel, Wor= d, and Powerpoint). =0D • Ability to work effectively in a team management environment and p= articipate in collaborative initiatives which foster the mutual exchange = of knowledge and expertise. =0D • Must be able to multi-task, work independently and as part of a te= am, share workloads, and deal with sudden shifts in project priorities. =0D • Ability to communicate effectively orally and in writing to build = and maintain customer satisfaction and express conclusions in a clear, te= chnically sound manner on matters associated with IT security. =0D • Ability and interest in obtaining a security/C&A certification (e.= g., CAP). =0D =0D Desired Skills: =0D • Working knowledge of the Trusted Agent FISMA Tool (TAFT) and the R= isk Management System (RMS). =0D • Awareness of current information security issues and the ability t= o interpret the requirements of relevant policies and standards set forth= in NIST documentation, specifically, 800-37, 800-53A, FIPS-199/200, and = 800-30. =0D • Knowledge of NIST in regards to how it applies to FISMA reporting.= =0D • Above average skills in MS Excel, and MS Access (to include abilit= y to write macros, and/or code) =0D • CAP (Certification and Accreditation Professional) =0D • CISSP (Certified Information System Security Professional)=20 CONTACT --------------------------------------------------- Knowledge Consulting Group Andrea Rodway Sr. Recruiter [email protected] --------------------------------------------------- SECURITYFOCUS JOBS --------------------------------------------------- SecurityFocus now offers an online interface for searching and managing job opportunities and resumes. http://www.securityfocus.com/jobs