Responsibilities:
• Provide information assurance for digital systems, ensuring adherence to security and compliance standards.
• Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks.
• Plan and execute security control assessments as an independent assessor using the Risk Management Framework for various information systems within the organization.
• Validate security control implementation and provide test results.
• Provide tailored documentation to support customer security authorization processes.
• Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure.
• Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations.
• Support development and maintenance of information security policies, procedures, and standards.
• Support compliance with government regulations and external cybersecurity frameworks.
• Provide SME review and recommendations for system designs, technical solutions, and operational procedures across functional teams.
• Work independently with limited supervision, managing projects or technical processes as assigned.
• Coach and review the work of junior team members to support professional development.
• Communicate effectively with internal stakeholders and external partners such as vendors or customers.
• Stay current with evolving cybersecurity threats, technologies, and best practices.
• Ensure compliance with security awareness training and alignment with organizational requirements.