
Information Security Compliance and Assessment Specialist
- Washington DC
- $110,000-120,000 per year
- Permanent
- Full-time
- Ensuring the implementation of DOE and NNSA cyber security policies and procedures for information systems
- Performing process and system evaluations (assessments) to ensure compliance with established policies, processes, procedures, and applicable standards
- Validating security control assessments results
- Performing a variety of technical and administrative activities related to the function of QA (auditing), including, but not limited to, scheduling, checklist development, report writing, facilitating root cause/lessons learned analysis, and internal/external presentations
- Compiling, analyzing, and reporting on findings of non-compliance and providing recommendations for improvement
- Capturing and maintaining plans of action and milestones on findings of non-compliance
- Tracking and escalating unresolved non-compliance issues and corrective and preventative action plans to closure
- Validating cyber security tests and assessments are conducted in accordance with established policies and procedures
- Formally and informally presents information in group and individual settings
- Performs other job-related duties as assigned
- Bachelor's degree in Computer Science or related field, or 4 years of professional IT experience.
- 5+ years of related work experience.
- Familiarity with NIST SP 800-53, RMF, and security assessment tools.
- Proficiency in Microsoft Office Suite.
- Strong attention to detail, organizational skills, and initiative.
- Must achieve/maintain NICE Framework certification (e.g., CISSP, CISM) within 6 months.
- Must pass pre-employment qualifications of Cherokee Federal