Security Control Assessor/Auditor/Risk Assessor
NTT DATAAbout the role
Req ID: 261050
NTT DATA Services strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.
We are currently seeking a Security Control Assessor/Auditor/Risk Assessor to join our team in Arlington, Virginia (US-VA), United States (US).
NTT seeks to hire someone to provide information security Assessment and Authorization (A&A) support to Contractor and Government facilities processing information. This person will enhance the Information System (IS) security awareness of system owners, PMO’s, directorates and the Cybersecurity Services Section. Ensure that proper IS security resources are appropriately applied, and act as an IS liaison between the CISO/CIO and System owners, PMO’s and various offices.
Personnel assigned to this role will serve primarily on the Cybersecurity Support and Assessment Units.
This role is responsible for coordinating with both the Cybersecurity Services Section and other
sections or divisions. Other sections include, but are not limited to, IT Operations, Engineering & Integration, and Software Operations. Other divisions include, but are not limited to, the Office of Investigative Technology. The contractor shall employ a mixture of technical and non‐technical
personnel for this role.
Job Duties:
- Analyzes IT system functionality and integration with management processes, structure, culture, and performance.
- Conducts cybersecurity analysis using qualitative and quantitative tools and techniques to assess the effectiveness of the network, system, or application’s security posture.
- Provides coaching, workshops, or training regarding the DEA SPAA process and associated sub‐processes.
- Perform aspects of the NIST six‐step Risk Management Framework and ongoing information system authorization through continuous monitoring processes.
- Provide the technical expertise and judgement for security control validation of system‐specific, hybrid, and common controls to determine the extent to which the controls are implemented correctly operating, operating as intended, and producing the desire outcome with respect to meeting the security requirements for the information system.
- Provide the technical expertise and judgment to validate the security controls employed within or inherited by the information system using assessment procedures and provide specific recommendations on how to correct weaknesses or deficiencies in the controls and reduce or eliminate identified vulnerabilities.
- Provide the technical expertise and judgment to determine the security impact of proposed or actual changes to the information system and its environment of operation to determine the extent to which proposed or actual changes may affect the security control(s) currently in place, produce new vulnerabilities in the system, or generate new requirements for new security controls no needed previously.
- Coordinate with other subject matter experts, such as the enterprise architect, to assess impacts to proposed changes and provide recommendations to senior management.
- Provide the technical expertise and judgment to deliver the results of the security control validation documented in the security assessment report at a level of detail appropriate for the assessment in accordance with the reporting format prescribed by organizational and/or federal policies, including recommendations for correcting any weaknesses or deficiencies in the controls.
- Provide the technical expertise and judgement to validate the security controls employed within or inherited by the information system, after the initial authorization on an ongoing basis.
- Demonstrated experience developing tailored artifact request lists that serve as evidence for assessments.
- Demonstrated experience reviewing and integrating vulnerability scan results into consolidated findings reports.
- Proven success with developing executive level findings briefings and communicating/defending assessment results and progress to internal and external stakeholders.
- Ability to prioritize tasks to support assessments on multiple boundaries at a given time.
- Ability to present IT security risks to executive management.
- Perform A&A activities to include coordinating with stakeholders; developing/reviewing documentation; and identifying, documenting, communicating assessment results.
- Documentation to be developed includes Security Assessment Plans and Security Assessment Reports.
- Documentation to be reviewed includes, but is not limited to, System Development Lifecycle documentation, network topology diagrams, System Security Plans and other documents that comprise existing A&A pac
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Security & Compliance Engineer, AWS Security Assurance Services, LLC
Amazon Web Services Singapore Private Limited
Spécialiste de sûreté - Centre de données / Data Center Security Specialist
Amazon Data Services Canada, Inc.
Cloud Systems Engineer I, ADC System Security Engineering
Amazon Development Center U.S., Inc.