Senior Specialist - IT Security
Marsh McLennanAbout the role
Company:
TorrentDescription:
Torrent Technologies is seeking candidates for the following position based in the Overland Park KS office or any other local office:
Senior Security Specialist
This is a high profile, dynamic work environment supporting the Federal Emergency Management Agency (FEMA) and the Department of Homeland Security (DHS). The position shall serve as the Information Systems Security Officer (ISSO) for information assurance activities at the IT system level.
What can you expect?
- The ISSO shall ensure that management, operational, and technical controls for securing the applications and environment used in support of the National Flood Insurance Program and that Information Systems are in place and are followed. This includes ensuring that appropriate steps are taken to implement information security requirements for IT systems throughout their life cycle, from the requirements definition phase through disposal.
- The ISSO shall possess effective interpersonal and presentation skills as he/she operates in a client-facing role. The ISSO must possess experience with NIST 800 publications standards.
- The position requires experience with vulnerability scanning and assessments. The ISSO shall conduct Assessment and Authorization (A&A) activities in accordance with NIST 800-37 standards.
- All A&A deliverables must meet the metrics in the DHS Information Security Performance Plan and be well versed in DHS 4300. The ISSO shall also respond to Information Security Vulnerability Management (ISVM) notifications and ensure all systems under their purview are in compliance with DHS IT Policies. The ISSO shall manage single or multiple systems depending on the size and complexity.
What is in it for you?
Torrent offers a dynamic, engaging work environment that places a high value on customer service, respect, and quality relationships. We want our hard-working team members to be their best in an atmosphere that encourages the expression of ideas which will contribute to our clients’ and to the company’s success. Motivated employees are well rewarded, and Torrent offers competitive benefits including comprehensive medical insurance. Check out Torrent's Company Values to see if you might be a good fit.
- Benefits: Health, Dental, Vision, 401K
- Rewarding career helping others
- Fun and engaging work environment built on team unity
- Paid Time Off for the things you love to do
- Holiday and Sick Time available
- Training to help advance your skills for career development
We will count on you to:
- Execute Risk Management Framework Assessment and Authorization activities.
- Assist in developing unified guidelines and procedures for conducting authorizations and/or system-level evaluations of federal information systems and networks including the critical infrastructure of DHS.
- Develop and present, both verbally and in writing, highly technical information and presentations to non-technical audiences at all levels of the organization; audiences for this information include, but are not limited to, senior executives at DHS and other agencies.
- Ensure IT systems have all security controls in place and functioning properly in accordance with NIST 800-53A publication.
- Conduct and evaluate/analyze vulnerability results from security tools including but not limited to: Tenable.sc/NESSUS, Splunk, AppDetective, and WebInspect.
- Support onsite external and internal audits for designated systems.
- Report incidents within the time frame prescribed by DHS 4300 policy for incident response.
- Experience as a security control assessor a plus for this position.
We would like you to have:
- MUST be a US Citizen
- At least one year of experience as an ISSO or performing the duties of an ISSO
- Minimum of three years of experience in Federal IT Security
- Must possess one of the following security professional certifications: Certified Information Systems Security Professional (CISSP), Certification and Accreditation Professional (CAP), CompTIA Advanced Security Practitioner (CASP), or similar widely recognized advanced IT Security certification.
- Thorough knowledge of, and experience with, the NIST 800 series publications to include: 800-30, 800-37, 800-53, 800-53a, 800-60.
- Previous experience creating all necessary A&A documentation.
- Minimum of three years demonstrated experience with Enterprise Network devices (i.e. routers, switches, firewalls).
- Minimum of three years demonstrated experience with Operating platforms (i.e. UNIX, Solaris, and Microsoft) and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s