Jobs and Careers
CA

Senior Security Controls Assessor

Capgemini
United Statesfull_timeVerifiedPosted 6 May 2024

About the role

Job Description: 

Capgemini Government Solutions (CGS) LLC is seeking a highly motivated Senior Security Controls Assessor to join our team in the Washington, D.C. metro to support our government clients. The Senior Security Controls Assessor is a multifaceted role that collaborates with other teams across the business.

The successful candidate will have the opportunity to apply and grow their skillset, work with a motivated and entrepreneurial team, engage with a wide range of stakeholders, and build CGS’ capabilities.

Key responsibilities:
  • Review and update existing information security policy, standards, and procedures based on federal and departmental regulations.
  • Perform independent security and privacy control assessments in support of Security Assessment & Authorization (SA&A).
  • Conduct assessments of existing and new FISMA systems, including subsystems in the respective system boundary, and communicate the results and potential implications of identified control weaknesses.
  • Reviews and analyze, Assessment & Authorization (A&A) packages to include System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Back-up Standard Operating Procedures (SOP), Incident Response Plans (IRP), Configuration Management Plans, (CMP), Hardware/Software lists, Network Diagrams, Data Flows, System Change Requests/Proposals, Vulnerability scan reports, test reports, and Plan of Actions & Milestones (POA&Ms) for completeness, accuracy, and document effectiveness of controls, plans and procedures implementation.
  • Create and maintain test cases for security assessment testing and perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.).
  • Develop and implement a security and privacy assessment plan in accordance with NIST SP 800-53A, as amended, requirements, for each security assessment project. SA&A activities shall include support for RMF steps 4-6
  • Document and provide findings and recommendations that are concise, system-specific, and actionable.
  • Analyze security tool reports and resolve residual risk or false positives from technical reports and artifacts before assigning findings.Add no more than 5-7 bullet points

Required Skills:

  • Three (3) years’ experience performing security control assessments required.
  • Experience in planning assessments and be a senior member in a team of security control assessors
  • Experience in communicating control requirements and deficiencies to both technical and non-technical audiences.
  • Experience performing detailed, full-scope technical security control testing for each of the component types, including development of security and privacy assessment plans is required.
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53r4/5 and other overlays
  • Possesses a solid grasp of the NIST Special Publication 800-53 security and privacy controls, the NIST Cybersecurity Framework and other information security and privacy laws and regulations.
  • Experience with development and writing of risk-based documentation.
  • Experience with Step 4 of RMF process- Assessing Security Controls
  • Strong written and verbal communication skills.
  • Good communication ability across all levels of management.
  • Ability to acquire Public Trust clearance or higher as required
  • Bachelor’s degree or higher in Computer Science’s, MIS/IT, Engineering, Information Security/IA, or related subject area to work requirements no more than 3-5 required skills.
  • Five (5) years of experience related to security control evaluation and compliance with Federal RMF requirements.
  • Two (2) years of experience with the use of eGRC tools in Federal environment
  • Experience performing Assessment and Authorization (A&A) activities, including risk assessments, Security Plans, Security Controls Assessments (SCA), Authorization document development and/or review.
  • Knowledge of current industry methods for evaluating, implementing, and disseminating information technology (IT) security assessment, monitoring, detection, and remediation tools and procedures applying standards-based concepts and capabilities.
  • Experience with cloud technology offerings from AWS and Azure and assessing systems hosted within those environments
  • Experience performing assessment in accordance with the policies, procedures, and standards of the Office of Management and Budget (

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Capgemini

View company profile →