Jobs and Careers
NO

Cyber-Security Risk Analyst

Noblis
United Statesfull_timeVerifiedPosted 21 Nov 2024
💰 $141,075/yr($90,300/yr$141,075/yr)

About the role

Responsibilities

Noblis is seeking an Cyber Security Subject Matter Expert (SME) to consult with a Federal client on the availability, appropriateness and procurement of Cyber Security solutions.  The candidate will lead Governance, Compliance and Risk (GRC) efforts and drive organizational strategy to manage governance and risk while maintaining compliance with industry and government regulations.   Candidates will organize, access, and analyze cybersecurity risk assessments to drive impactful risk mitigation strategies.  Candidates will Identity and assess the cyber risks associated with external parties, monitor third party performance and ensure external control effectiveness.

In addition, thecandidate will assist with the development, management, and execution of government acquisition of information security services and support. Responsibilities include market analysis; requirements development; drafting statements of work; supporting RFP activities; evaluating vendor responses for technical, past performance, and cost reasonableness; supporting evaluations; and making or recommending source selection decisions. Successful candidates will conduct on-going program activities including processing contract modifications, and analyzing cost savings.

As part of a Noblis team, candidates will work closely with government clients to understand current issues and challenges, generate practical and effective solutions, and assist with acquisition/deployment/management of those solutions, typically working “on the government side of the table” as an unbiased, trusted partner.

 

Technical:

  • Experience with compliance with industry and government regulations such as SOC 1, SOC 2, FedRAMP, NIST SP 800-53, Risk Management Framework, PCI DSS.
  • Experience with GRC methods, tools, and/or software solutions to achieve secure performance, alignment with IT and business goals, and address risks for large Federal organization.
  • Research and conduct market analysis of Cyber Security solutions.
  • Apply information assurance principles; define and document system requirements; support planning and scheduling activities; perform technical analyses of vendor capabilities; perform feasibility analyses and technical risk assessments.
  • Working independently with general instruction, adapt and apply Noblis’ principles, concepts, processes, tools and methodologies to solve real-world problems in a team environment.
  • Develop and apply knowledge of Federal acquisition practices and regulations to the competitive best value procurement of information security services.
  • Prepare and/or contribute to technical reports, memos, analyses and briefings. Plan and manage assigned deliverables.
  • Gather and document business and technical requirements.
  • Knowledge of contract management activities is a plus.
  • Support meetings, inter-team communication, and issue resolution with the client and internal/project stakeholder groups.
  • Work closely and collaboratively with Noblis and customer team leaders and members.

Required Qualifications

  • A Bachelor’s degree in a business or technical discipline such as Electrical or Systems Engineering, Computer Science, etc with 9 years of experience OR Master's degree in a business or technical discipline such as Electrical or Systems Engineering, Computer Science, etc with 6 years of experience.
  • Knowledge of one or more relevant technical subject areas within information security, intrusion detection, compliance assessment & audit, incident response. High preference for GRC expertise. 
  • Familiarity with relevant Federal technology issues, policies, regulations or practices.
  • Experience with or knowledge of government acquisition/contracting practices, programs and regulations (FAR, DFAR, etc.) is especially useful.
  • Ability to obtain and maintain a public trust (US citizenship OR green card holder living in the US for at least 5 years).

Hybrid positon, 2 days on-site at either Raleigh, NC (preferred) or Falls Church, VA. 

Desired Qualifications

  • Excellent communication, collaboration, presentation, and leadership skills. Proven results-oriented problem solving abilities. Facility with presentation graphics and/or spreadsheet tools highly desirable.
  • Ability to work in a dynamic team-oriented environment, demonstrate teamwork and initiative, and function productively in the face of new assignments and the re-prioritization of existing assignments.

The following certifications are preferred but not required:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified Ethical Hacker (CEH)
  • Security+
  • GIAC Information Security Fundamentals (GISF)

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Noblis

View company profile →