Jobs and Careers
NA

IT Security and Compliance Associate

Nava
UKRemotefull_timeVerifiedPosted 7 Aug 2023

About the role

About NavaNava is a consultancy and public benefit corporation working to make government services simple, effective, and accessible to all. Since 2013, federal, state, and local government agencies have trusted Nava to build transformative digital services to help people access public benefits. Meeting our mission is an opportunity to restore trust between people and public institutions. We focus on populations that are the least protected because the stakes are higher.
As a client services company, we work with government agencies to improve how people apply for benefits, navigate their health care, and more. We bill for our time, selling our expertise and problem-solving methodology to government clients. Our clients hire us to help improve their products and services so that their users and beneficiaries have a better customer experience.
These end-users—the humans who benefit from our work—are at the core of everything we do. We research beneficiaries’ needs to help our government clients better deliver on their missions, providing everyone at Nava opportunities to do meaningful, impactful work.
Position SummaryThe IT Security and Compliance Associate assists the IT Manager in maintaining the essential IT infrastructure of Nava. The incumbent will be responsible for ensuring Nava’s continued compliance with existing corporate certifications, along with supporting Nava in obtaining new certifications. This role will support these processes in all aspects, from managing company policies and procedures, coordinating with other departments up to and  including Nava’s Executive Team, and managing Nava’s slate of tools and hardware in conjunction with Nava’s IT team.
All work will be done in support of Nava’s values: Be Active Stewards, Pursue the Root Cause, Think Long-Term, Build Together, Inclusion is Essential and Progress Takes Work.

What you'll do

  • Information Security Certification Management
  • Managing relevant infosec policies and procedures to ensure continued compliance with company certifications, including but not limited to ISO 27001, ISO 20000, and annual internal audits along with other regular processes as required by certifications.
  • Support other Nava teams with certification efforts, including but not limited to ISO 9001, CMMI Level 2, and others, as needed.
  • Conduct security reviews on vendor-supplied tools and services in order to confirm

  • Security Analyst 
  • Lead and manage the internal development and deployment of new security solutions and improvements, including creating new reporting systems (Splunk SIEM)  
  • Managing security incidents as they occur, including initial triage, resolution of simple situations, and incident escalation, communication, tracking, and review
  • Develop and deliver new security training materials for Nava employees

  • End User Support
  • Provide Nava employees with support when needed, by responding to support tickets within an appropriate amount of time
  • Support requests may include but are not limited to - tool license management and allocation, hardware troubleshooting, and software troubleshooting

Required skills

  • 1+ years of experience in IT support or tech-forward customer service support
  • 1+ years of experience in Information Security or Compliance Management
  • An adaptive, empathetic, collaborative, curious, and positive mindset
  • Experience with ISO certification standards, including but not limited to ISO 27001, ISO 20000, and ISO 9001
  • Experience with CMMC cybersecurity certification processes and procedures
  • Experience managing basic IT, e.g. A/V setup and configuration
  • Highly organized, resourceful, reliable, and detail-oriented
  • Ability to work independently and autonomously within a distributed team while soliciting feedback when necessary
  • Ability to think strategically around trade-offs and short term vs. long term benefits
  • Excellent written and verbal communication skills

Desired skills

  • Experience administering software for distributed 100+ person team
  • Beginner's knowledge of security practices and administration of security software (SentinelOne / Carbon Black)Ability to build and form strong relationships both internally and externally
Other requirementsThe individual working in this position: ●  Must be legally authorized to work in the United States and meet any other requirements for government contracts for which they are hired.●  Candidates who are offered a job with Nava must possess work authorization that does not require sponsorship by their employer for a visa now or in the future.●  May be subject to a government security investigation and must meet eligibility requirements for access to classified information or applicants who are eligible for security clearances.
Perks

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Nava

View company profile →