Full-Time

Senior Security Control Assessor Representative/Systems Security Engineer

Arlo Solutions

Arlo Solutions

No salary listed

No H1B Sponsorship

Arlington, VA, USA

In Person

US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
Risk Management
Requirements
  • Must have an active TS Clearance SCI eligible
  • Bachelor’s degree in Computer Science/Information Technology, or other related degree fields (master’s degree is preferred or at least 10 years of related experience)
  • At least 10+ years of cybersecurity experience including a senior technical or management role, Project or Program Management experience a plus
  • At least one IAT/IAM or equivalent security certifications e.g. CISSP, CCSP, CISM, CISA, or CASP
Responsibilities
  • Provide the Authorizing Official with an independent risk assessment of assigned systems and an authorization recommendation
  • Advise Program Managers on AO determination utilizing Operational Vulnerability List (OVL) documentation
  • Provide senior advisory support to CDAO Authorizing Official regarding authorizations of CDAO capabilities
  • Utilize expert knowledge and experience regarding risk management strategies
  • Provide support regarding the agile authorization and OVL processes
  • Provide independent risk analysis and recommendation
  • Collaborate between the AO and the program as well as Program leadership
  • Identify the security baseline based on the mission and security impacts to the system
  • Determine assessment criteria, develop, review, and create a plan to assess the security requirements
  • Assess the security requirements in accordance with the assessment procedures defined in the Security Assessment Plan (SAP)
  • Prepare the Security Assessment Report (SAR)
  • Monitor Plan of Actions and Milestones (POAM) actions based on findings and reassess remediated risk(s) as appropriate
  • Develop the Risk Recommendation and AO Determination Brief
  • Develop a system-level continuous monitoring strategy
  • Author and present briefs regarding status of authorizations to AO and other senior Government officials
  • Provide security architecture and DoD compliance advisory support
  • Perform other duties as assigned or required
Desired Qualifications
  • Experience supporting and assessing risks within a CI/CD DevSecOps environment; key areas include data mesh, data orchestration, control gates review, and vulnerability management within a pipeline
  • Expansive knowledge integrating IaaS, PaaS, and SaaS into government cloud environments (AWS, Azure, GCP); experience with cloud computing, cloud storage, cloud native solutions, cloud data transfer, Cross Domain Solutions, and cloud networking
  • Experience assessing STIGs, Cloud Compliance Guides, Shared responsibility models, and System Mission Owner responsibilities within Government Cloud Environments
  • Experience working with Office of the Secretary of Defense (OSD) leadership or a Military component or branch
  • Expert understanding of NIST 800 series guidelines, DoD 8500.01, DoD 8140.03, ISO 27001, COBIT, DoD RMF, OVL, and current cybersecurity best practices
  • Excellent communication/presentation skills briefing senior military and government civilian leadership
  • Experience in writing policies, guides, procedures
  • Experience hands-on with eMASS, Xacta and/or other Governance, Risk and Compliance tools
  • Experience with Federal and Federal Risk and Authorization Management Program (FedRAMP) Assessment and Authorization Processes
  • Experience advising at the Senior Executive Service (SES) level of customers

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

Your Connections

People at Arlo Solutions who can refer or advise you