Senior System Security Analyst (AI Risk Management Framework)
Coalfire Federal
- Rockville, MD
- Permanent
- Full-time
Open to local candidates in the Washington, D.C. / Northern VA / Maryland areas.What you'll do:
- Support federal customers and provide a firm understanding of how to apply the principles of information security in a variety of circumstances and security requirements into common technical implementations
- Support customers with implementing the core principles of the NIST AI Risk Management Framework
- Support teams in the review and analysis of Security Packages for completeness and compliance with FedRAMP/DoD/NIST requirements
- Assist in the development of Risk Assessment Reports (RAR), and security briefings
- Validate Cloud Service Provider (CSP) compliance with FedRAMP/DoD/NIST security control baselines through review of evidence, testing, interviews, and analysis of scans, etc
- Familiarity with SSP, SAP, SAR, Plan of Action and Milestones (POA&M) Report, Deviation Requests, Significant Change Requests, Continuous Monitoring artifacts is required
- Conduct client interviews to assess the technical and operational effectiveness of security control implementations
- Assess existing security environments to validate that security implementations remain up to date throughout the life cycle of a system or environment
- Knowledge of the NIST AI Risk Management Framework
- Knowledge of computer networking concepts and protocols, and network security methodologies.
- Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Knowledge of cybersecurity and privacy principles.
- Knowledge of cyber threats and vulnerabilities.
- Knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations.
- Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
One or more of the following: CISSP or CISMYears of ExperienceAt minimum 7 years of information security experience relative to the position qualifications.Bonus Points:
- Knowledge of GRC tools e.g., CSAM