Security Analysis Sr. Advisor
Current- Lead the design, implementation, and maintenance of cybersecurity solutions to protect digital assets.- Perform regular security assessments, vulnerability assessments, and penetration testing to identify and address potential weaknesses in our clients' systems and applications.- Collaborate with internal teams and external partners to develop and enforce security policies, procedures, and standards that comply with relevant regulations and industry frameworks.- Monitor and analyze security incidents, respond to security breaches, and lead incident response efforts to minimize the impact of security events.- Applying knowledge of Internal Audit policy and procedures to perform analysis and evaluation to design, implement, test, and field secure systems, networks, and architectures.- Developing, implementing, and enforcing information systems security policies, ensuring system security requirements are addressed during all phases of the Information System (IS) lifecycle.- Conducting certification and testing by the Risk Management Framework (RMF) and National Institute of Standards and Technology (NIST) policies; identifying deficiencies and providing risk mitigation recommendations.- Utilizing testing methods, automated tools, plans, and procedures to verify compliance and vulnerability requirements.- Assess and mitigate system security threats or risks throughout the program life cycle.- Reviewing Plans of Action and Milestones (POA&Ms) to ensure weaknesses are identified, effective/acceptable mitigation strategies are planned, and timelines are acceptable.- Contributing to security planning, assessment, risk analysis, risk management, certification, and awareness of system and networking operations activities.- Creating, updating, and maintaining threat models for a wide variety of software projects- Assist in development of security processes and implementation of automated tooling that prevent security issues.