CybersecurityJobs.io
← Back to all jobs

Job Description

Support FEMA OCISO in Washington, D.C. by conducting independent cybersecurity control assessments and producing assessment artifacts for security and compliance.

Responsibilities

  • Assess the effectiveness of IT security controls and verify compliance with NIST SP 800-53 Rev 5 and DHS RMF
  • Conduct comprehensive control assessments within a system boundary and across FEMA using interviews, examinations, and testing
  • Evaluate the effectiveness of security policies, procedures, and technologies to identify vulnerabilities, risks, and gaps
  • Review and analyze System Security Plans (SSPs), supporting policies and procedures, and evidence artifacts for completeness and accuracy
  • Identify security gaps, evaluate residual risk, and generate findings for security assessment reporting
  • Develop and maintain assessment artifacts and document findings while supporting continuous monitoring and ongoing authorization efforts
  • Highlight findings and recommendations, and collaborate with IT, security, and business units to support corrective actions

Requirements

  • U.S. Citizenship required
  • FEMA EOD suitability required; current DHS or FEMA EOD preferred
  • BS/BA + 7 years of applicable experience in RMF, control assessment, audit, cybersecurity compliance, or security engineering
  • Certifications such as CISSP, CISM, CISA, or equivalent
  • Strong knowledge of NIST SP 800-53, NIST SP 800-37 (RMF), and the DHS 4300 Series
  • Experience using security control assessment methodologies and tools
  • Experience conducting security assessments and producing security assessment artifacts, including SAPs, RTMs, and SARs
  • Analytical skills for identifying security gaps and evaluating residual risk
  • Knowledge of assessment methodologies and risk analysis
  • Experience developing POA&Ms
  • Excellent analytical and problem-solving skills for vulnerability prioritization and trend analysis
  • Strong communication and interpersonal skills; able to work independently and as part of a team
  • Detail-oriented approach with a commitment to accuracy and thoroughness

Technologies / Artifacts

  • NIST SP 800-53 Rev 5
  • DHS RMF
  • NIST SP 800-37 (RMF)
  • DHS 4300 Series
  • Security Assessment Plans (SAPs)
  • Risk Traceability Matrices (RTMs)
  • Security Assessment Reports (SARs)
  • System Security Plans (SSPs)
  • POA&Ms

Benefits

  • Flexible time off benefit
  • Robust learning resources
  • Comprehensive benefits including healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits

Additional Opportunity Details

  • Serve as an independent assessor for control design, implementation, and effectiveness across assigned systems and authorization boundaries
  • Support assessment procedures including interviews, examinations, and testing to verify control implementation and effectiveness
  • Collaborate with system owners, ISSOs, stakeholders, and cybersecurity professionals to evaluate security control implementation effectiveness
  • Work with multiple teams to identify gaps, recommend improvements, and support compliance with regulatory requirements

Desired Qualifications

  • Active Secret security clearance
  • Previous DHS or DoD experience
  • Experience with CSAM, RegScale, eMASS, or similar GRC tools
  • Knowledge of FedRAMP assessment processes and DISA STIGs and cybersecurity compliance frameworks
  • Experience with continuous monitoring and ongoing authorization activities
  • Knowledge of cloud security and emerging technologies
  • Strong technical writing skills for assessment documentation
  • Experience supporting audit activities and authorization decisions

Travel / Location / Pay

  • Location: Washington, DC (onsite)
  • Travel: Up to 10% local travel
  • Pay range: USD 113,200 - 237,800 per year

Similar Jobs