|
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Security Control Assessor. In this role you will lead independent security control assessments of DHS Intelligence Enterprise systems, on-premise and in the cloud, from discovery through a completed authorization package supporting ATO, ATC, and IATT decisions. You will write assessment reports, validate remediation, and work closely with system owners and ISSOs. This position is on-site in a Government SCIF in Washington, DC. Duties include but not limited to:
- Conduct discovery and kick-off meetings with project stakeholders for new and re-authorization activities.
- Assess management, operational, and technical security controls against NIST, CNSSI, and IC standards.
- Conduct vulnerability, configuration, container, and serverless testing across on-premise and cloud environments.
- Document findings in Security Assessment Reports and ensure alignment with POA&Ms.
- Validate POA&M remediation and document evidence of compliance.
- Prepare A&A packages in the GRC tool, including risk memoranda and ATO/ATC/IATT letters.
- Produce System Security Test Reports and A&A portfolio reports.
- Provide recommendations to mitigate risk and improve the security posture of assigned systems.
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
- Minimum of 3 years' experience in RMF security control assessment.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of the Risk Management Framework (RMF), NIST SP 800-53A, and CNSSI 1253.
- Knowledge of the ATO, ATC, and IATT authorization process.
- Knowledge of POA&M management and risk acceptance processes.
- Skill in using at least two security tools (e.g., Nessus/ACAS, SCAP, Nmap, WebInspect, SonarQube, STIG Viewer).
- Skill in writing Security Assessment Reports and risk recommendations.
- Ability to lead an assessment independently and coordinate with system owners.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Desired
- CGRC (formerly CAP), CompTIA Security+, or CySA+ certification.
- Cloud authorization experience (AWS or Azure).
- Experience with RSA Archer.
|