Risk Management Specialist
Current- Reviewing, maintaining, and ensuring all Assessments and Authorizations (A&A) documentation are included in the system security package.
- Ensure Implementation of appropriate security control for Information System based on NIST Special Publication 800-53 rev 5, FIPS 200, and System Categorization using NIST 800-60 Vol II Rev I, and FIPS 199.
- Review and update remediation on (POAMs), in the organization's Cyber Security Assessment and Management (CSAM) system. Work with system administrators to resolve POAMs, gathering artifacts and creating mitigation.
- Perform vulnerability and baseline scans, using tools such as Tenable Nessus, CIS-CAT, Retina Vulnerability scanner, analysis scan results and document findings in POA&M.
- Collaborate with system administrators to remediate (POA&Ms) findings. Ensure vulnerabilities and risks are efficiently mitigated in accordance with the organization's continuous monitoring Plan.
- Monitor controls post authorization to ensure continuous compliance with the security requirements.