Cloud Security Control Assessor

Peraton
Alexandria, VA
Job Description
Role Overview

Peraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER). The role involves conducting assessments, facilitating risk mitigation planning, and implementing risk management programs. The successful candidate will have experience with cloud security concepts, protocols, and methodologies, as well as knowledge of national and international laws, regulations, and ethics related to cybersecurity.

What You Will Do

The main responsibilities of this role include conducting assessments and risk mitigation planning, providing Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure, and executing a security control assessment plan. The candidate will also review vulnerability scans and remediation, implement risk management programs, and monitor the privacy landscape.

Why It Might Be a Fit

This role requires a strong background in cybersecurity, cloud security, and risk management. The successful candidate will have experience with enterprise solutions across multiple cloud operating environments, as well as knowledge of computer networking and cloud computing concepts and protocols. They will also have the ability to work in a virtualized environment and have experience with cybersecurity principles, risk management framework processes, and industry methods for evaluating and implementing IT security assessment tools.

Requirements

  • Minimum experience of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D.
  • Current IAM level III certification (such as CISM)
  • Knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet)
  • eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience
  • Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies
  • Knowledge of cyber threats and vulnerabilities in a virtualized environment.
  • Knowledge of cybersecurity principles
  • Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity
  • Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk)
  • Knowledge of specific operational impacts of cybersecurity lapses
  • Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities
  • Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
  • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment
  • Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption)
  • Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins
  • Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth)
  • Knowledge of organization's evaluation and validation requirements
  • Knowledge of penetration testing principles, tools, and techniques
  • Knowledge of relevant laws, policies, procedures, or governance related to critical infrastructure.
  • Knowledge of Risk Management Framework (RMF) requirements
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return oriented attacks, malicious code)
  • Knowledge of the Security Assessment and Authorization process
  • Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes
  • Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing
  • Knowledge of IT supply chain security and risk management policies, requirements, and procedures
  • Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability
  • Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing
  • Knowledge of organization's enterprise and/or cloud computing information security architecture system
  • Knowledge of Personal Identifiable Information (PII) data security standards
  • Knowledge of Personal Health Information (PHI) data security standards
  • Active TS clearance with ability to obtain/maintain SCI

Benefits

  • Target Salary Range: $146,000 - $234,000
  • Overtime, shift differential, and discretionary bonus in addition to base pay
  • U.S. Citizenship Required
]]>