Jobs and Careers
CR
Senior Cloud Security Specialist
Creative Information Technology, Inc.United StatescontractVerifiedPosted 6 Aug 2024
About the role
Senior Cloud Security Specialist - Remote – Washington, DC.
About us
- Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.
- Join us in driving growth and seizing new business opportunities.
Background
- We seek an experienced individual to provide services in support of the continuous monitoring of FedRAMP authorized cloud solutions. We are looking for an experienced information security specialist to work directly with cross-division subject matter experts (SMEs) and provide insight, advice, support, and recommendations to ensure the success of the continuous monitoring process, with a targeted focus in FedRAMP, FISMA, Privacy Act, and OMB requirements.
- The selected individual shall have experience successfully reviewing FedRAMP continuous monitoring packages and advising on secure cloud control implementation. The successful candidate shall be adept at working collaboratively in a consensus-based environment while serving as an individual contributor who develops information security related work products.
Role and Responsibilities
- Review current continuous monitoring program and provide recommendations for improvement.
- Conduct monthly FedRAMP continuous monitoring package analysis, this includes reviewing deviation requests and POA&Ms as well as documenting a summary for the client.
- Advises clients on FISMA/FedRAMP compliance activities while staying current with the legislation, and National Institute of Standards and Technology (NIST) and Office of Management and Budget (OMB) requirements.
- Conducts security risk assessments for third party applications and service providers.
- Ensure organizational structure recommendations integrate cohesively into the overall DFM and Board strategic direction and are in alignment with other high- priority work across the division.
- Identify and help plan for long-term financial considerations due to cloud migration and business transformation.
- Review and advise on post implementation de-commissioning scheme for legacy applications, as well as migration and maintenance of historic data.
- Review additional process and procedures and make recommendations for improvement to the client
- Provide ad-hoc support services. The Board requires the specialist to support some unexpected and ad-hoc tasks associated with planning and executing the system implementation.
- These services may include but are not limited to advisory consulting services for Board leaders, facilitating strategic meetings.
Minimum Qualification
- Bachelor’s degree or higher in information security, or a related field or equivalent experience.
- At least one advanced cybersecurity certification such as: CISSP, CCSP, CRISC, or other relevant security certifications; multiple are preferred
- At least seven (7) years of information security experience, including cloud security and continuous monitoring activities.
- Extensive NIST experience: NIST SP 800-30 rev 1, 800-37 rev 1 or 2, 800-53 rev 5, 800- 60 Vol 1 rev 1 & 2 rev 1, and 800-171 rev 3
- Experience with implementing systems in a FedRAMP, FISMA, and SOX compliant environment.
- Proven ability to forge consensus and work collaboratively, without positional authority, to influence stakeholder groups in different hierarchical structures
- Demonstrate strong project execution and project management capabilities.
- Experience with FedRAMP reporting requirements, including but not limited to, risk assessments, Plan of Action and Milestones (POA&M), and remediation plans.
Preferred Qualification
- Minimum of 6 years' experience in cybersecurity, including cloud security, compliance, and risk management with a background in system and network security engineering.
- Minimum of 6 years’ experience on any Cloud Platform (AWS
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s