Cyber Security Specialist
Current•Conduct comprehensive assessments of security and privacy controls to determine their compliance with the NIST RMF.•Identify risks associated with security and privacy control failures and provide recommendations for mitigating identified risks and improving overall security posture.•Verify documented policies, processes and procedures accurately reflect operational practices. (e.g. System Security Plans (SSPs), Contingency Plans, Incident Response Plans, Privacy Impact Assessments… Show more •Conduct comprehensive assessments of security and privacy controls to determine their compliance with the NIST RMF.•Identify risks associated with security and privacy control failures and provide recommendations for mitigating identified risks and improving overall security posture.•Verify documented policies, processes and procedures accurately reflect operational practices. (e.g. System Security Plans (SSPs), Contingency Plans, Incident Response Plans, Privacy Impact Assessments (PIAs), and System of Records Notice (SORNS)).•Analyze and evaluate SOC 2 reports to confirm compliance and identify gaps in control implementation against the NIST SP 800-53 control set.•Coordinate with Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) to provide security solutions and interpretations of security policies.•Prepare and present clear and concise assessment findings to senior management, system owners, and stakeholders.•Maintain strong relationships with all stakeholders by providing continuous support related to assessment outcomes. Show less