Information Security Risk Specialist
BOOZ, ALLEN & HAMILTON, INC.
Information Security Risk Specialist
The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to a program responsible for fielding a worldwide enterprise warfighter mission support system. In all of this "cyber noise," how can program managers understand their risks and how to mitigate them? The answer is you. We need your knowledge as an information security risk specialist to help break down complex threats into manageable plans of action. As an information security risk specialist on our team, you'll work with DoD acquisition programs to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You'll get technical and operational details from Assistant Program Managers and Lead Systems Engineers to assess the entire threat landscape. Then, you'll help your team perform risk and vulnerability assessments in network, system, and application areas. You'll work on translating security concepts for your client so they can make the best decisions to secure their mission critical system. This is your opportunity to take an active role in information security while growing your skills in complex connected system vulnerability detection, mitigation and remediation. Work with us as we secure and protect our military's critical mission systems for the better. Join us. The world can't wait. You Have:- 5+ years of experience working with the Information Technology (IT) systems for a DoD or government agency
- 3+ years of experience with Navy Risk Management Framework (RMF) projects, including Assessment and Authorization (A&A) activities, support for SCI systems or networks, and the preparation, direct development, or maintenance of RMF artifacts, packages, or deliverables
- 3+ years of experience implementing security controls or policies, performing cybersecurity compliance testing or reviews, and performing vulnerability analysis and remediation of networks, systems, or communications protocols
- Experience with Xacta, including Security Plan development or hands-on processing of packages through workflows
- Knowledge of operating systems, platforms, and technologies, including Windows, Linux, networking, virtualization, or containers
- Knowledge of architecture visualization, and developing and maintaining system artifacts, including Boundary Diagrams and Data Flow Diagrams
- Ability to devise and execute client deliverables, work independently, identify problems, and devise analysis and solutions, communicate results to both technical and non-technical audiences, and lead the accomplishments of client tasks from inception to completion
- TS/SCI clearance
- Bachelor's degree
- DoD 8140 Certification
- Experience with tools such as Assured Compliance Assessment Solution (ACAS), DoD Security Technical Implementation Guides (STIG), and Evaluate-STIG
- Experience integrating security into DevSecOps pipelines
- Experience implementing automation methodologies and processes
- Experience deploying, implementing, maintaining, and integrating cybersecurity tools and applications in alignment with the current threat landscape, and analyzing risks and opportunities at both tactical and strategic levels
- Experience with network engineering functions, including Windows, Linux, and virtual operating systems, security tools, platforms, and technologies, including network and web application firewalls, web proxy, intrusion prevention systems, vulnerability scanners, and penetration tools
- Experience with developing and maintaining cyber schedule, performance, and quality metrics within the systems development lifecycle and acquisition lifecycle
- Master's degree in an Engineering, Computer Science, or equivalent technical discipline
- OS Certification
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
- Remote : If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid : If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite : If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Vacancy posted more than 2 months ago
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Risk Specialist. Be the first to apply!
