Talent.com
System Security Compliance Officer Sr- MINI TEAM CAPTAIN
System Security Compliance Officer Sr- MINI TEAM CAPTAINHiring Our Heroes • Arlington, VA, US
System Security Compliance Officer Sr- MINI TEAM CAPTAIN

System Security Compliance Officer Sr- MINI TEAM CAPTAIN

Hiring Our Heroes • Arlington, VA, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Job Description

Job Description

System Security ComPLIANCE OFFICER SR MINI TEAM CAPTAIN

MILITARY FRIENDLY & PREFERRED - HOH SPONSOR

Zermount Inc. is seeking a Senior Compliance Officer Mini Team Captain who will perform complex risk analyses and ensure systems and technologies satisfy Information Assurance (IA) and Cybersecurity requirements, based on federal requirements, laws, mandates, policies, procedures, standards, and guidelines (e.g., EOs, OMB, BODs, NIST, and agency specific requirements). The Compliance Officer will provide Plan of Actions and Milestones (POA&M) management, conduct FISMA Compliance meetings, and work with Information Systems Security Officers (ISSO), System Owners (SO), stakeholders, and leadership to meet performance and scorecard metrics. The Compliance Officer will conduct regular (e.g., daily, weekly, monthly) system security compliance meetings for assigned systems of responsibility, provide feedback and recommended mitigations to ensure systems meet the minimum requirements and security posture. Support customer at the highest levels to ensure the implementation of doctrine and policies.

Duties & Responsibilities :

The Senior Compliance Officer Mini Team Captain will provide the following support and services :

  • Perform Compliance reviews and analyses to verify compliance with federal requirements (e.g., EO, OMB Memos, A-130, NIST SP 800-37, 800-53, FIPS199, and FIPS-200, etc.).
  • Perform analyses of security implementations for assigned systems pertaining to people, processes, and technologies, identify gaps and recommend solutions.
  • Conduct daily, weekly, monthly compliance monitoring of assigned systems for all RMF steps.
  • Conduct compliance assessments of assigned systems, based on the Zermount approved Compliance Support Services Framework.
  • Execute day to day FISMA compliance monitoring, ensuring that all FISMA activities, including Information Security Continuous Monitoring (ISCM), Continuous Diagnostic and Mitigation (CDM), and FISMA program activities assigned are prioritized correctly, completed on schedule, and are in accordance with Agency and organizations policies.
  • Research major obstacles related to the ever-changing FISMA requirements, which customers will need to overcome and provide recommendations.
  • Track system ATO status, security documentation expirations (Contingency Plan, Contingency Plan Test, Configuration Management Plans, Incident Response Plans, etc.) Information Security Vulnerability Management (ISVM) compliance, DHS Performance Plan requirements, audit efforts, and CDM support efforts.
  • Conduct analysis of system level POA&Ms and provide guidance and recommendations on potential mitigation to close current or delayed POA&Ms.
  • Track and report on whether assigned systems have mitigated their weaknesses on time using the appropriate processes and reporting timelines.
  • Track and report on whether mandated FISMA activities are being executed in accordance with the current DHS Information Security Performance Plan (ISPP) for the fiscal year.
  • Provide compliance monitoring metrics and reporting to Agency leadership.
  • Review the DHS Scorecard, for each assigned system, conduct analysis, and generate "Get to Green" reports.
  • Conduct Get-to-green meetings with SOs and ISSOs, provide status, deficiencies, recommendations, and document action items with estimated completion dates (ECDs) with the goal of improving system scores within the DHS Scorecard.
  • Manage ISVM alerts and bulletins for TSA systems to include tracking, distributing, and providing reports.
  • Support systems of responsibility to ensure all ISCM and CDM requirements are met and mitigations for failing requirements are identified and discussed to ensure a plan is established to meet all requirements defined. Provide monthly reports with action items for stakeholders and leadership.
  • Create briefings and reports, as required for, but not limited to the following items : high valued assets, ISVMs, POA&Ms, system scores (FISMA & ISCM).
  • Provide input into the GRC presentations for monthly ISSO Townhall training, as required by management or the Communications & Training Team Lead.
  • Provide updates and input to the GRC SharePoint sites to include document uploads, page updates, access requests, permissions, etc. on an ongoing basis.
  • Create or update existing templates for memos, risk assessments, disposal packages, to standardize and simplify the process.
  • Conduct system compliance assessment to identify progress on ATO conditions, develop extension packages as required annotating analysis of system data / progress.
  • Conduct POA&M management activities, to include processing, reviewing, verifying, and validating creation and closures.
  • Report on expiring and overdue POA&Ms and ensure compliance with all DHS POA&M metrics and requirements as outlined in agency policy and the DHS ISPP.
  • Review waiver and risk acceptance requests for compliance with the Agency's Policies and Procedures.
  • Provide Quality Reviews of security documentation to ensure accuracy and compliance throughout the RMF process.
  • Support systems of responsibility to ensure all Ongoing Authorization (OA), requirements are met, and any deficiencies are identified and tracked. Monitor activities and ensure all deficiencies exceeding 30 days are identified as requiring a POA&M.
  • Assist with conducting review and analysis of Requests for Change (RFC) and providing recommendations to conduct risk assessment (as applicable) based on the change and / or Security Impact Assessment (SIA).
  • Support Security Control Assessors (SCAs) as required for assigned systems.
  • Provide input and assist with all audits, data calls, and queries relating to assigned systems.
  • Stay current with the latest developments in cybersecurity, information assurance, GRC, and related cybersecurity trends.
  • Create or update existing templates such as memos, risk assessments, disposal packages, to standardize and simplify GRC processes.
  • Assist in completing customer's Management Control Objectives Program (MCOP) reporting requirements.
  • Provide Weekly status reporting to leadership
  • Assist and support other team members as required by the Program Manager.
  • Provide Leadership and Mentoring 2-3 compliance officers

Qualifications :

  • Experience and expert knowledge on NIST guidelines, FISMA, Cybersecurity principles and methodologies, Executive Orders (EO's), Office of Management and Budget (OMB) Memorandums, Federal, DoD and CISA Technical Reference Architectures, Maturity Models, Risk Management Framework (RMF), Cybersecurity Framework (CSF), technical knowledge of IT systems, and cloud security (is preferred).
  • Knowledge of and experience using relevant cybersecurity and analysis tools such as Archer, Nessus Security Center, Splunk, etc.
  • Experience with cloud-based environments and technologies is preferred.
  • Knowledge of cybersecurity threats, risks, and vulnerabilities and how to mitigate them.
  • Excellent communication skills (written and verbal), with the ability to explain complex concepts in a clear, concise manner.
  • Strong problem-solving skills, proactive, ability to adapt to changes in priorities, attention to detail and organization skills, and possesses good problem solving and decision- making skills.
  • Must be able to conduct system analysis and quality reviews to detect performance issues.
  • Well versed in developing compliance solutions to resolve weaknesses or challenges.
  • Ability to work independently and as part of a team.
  • An analytical mind with excellent problem-solving ability is required.
  • Education and / or Experience :

  • Minimum of a Bachelor of Science (or higher) in one of the following : computer engineering, computer science, IT, cyber security, or a related field and 7 years of IT Cybersecurity experience including direct support of the US government and 4 years acting as an ISSO, Assessor, or Compliance Analyst.
  • Without a B.S. degree, a minimum of 10 years of IT cybersecurity experience including direct support for the US Government will be accepted
  • Certifications :

  • A minimum of at least one of the following certifications is required : Certified Authorization Professional (CAP), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Chief Information Security Officer (CCISO).
  • Clearance level :

  • Minimum of active Secret Clearance.
  • Work Location :

  • Primarily Remote. (Required onsite work at the client location in Springfield, VA and Zermount HQ in Arlington, VA., may be occasionally required.)
  • Hours of Operation :

  • Business Hours : 8 : 00 am EST - 4 : 30 pm EST.
  • [job_alerts.create_a_job]

    Security Officer • Arlington, VA, US

    [internal_linking.similar_jobs]
    Inside / OSP Manager (RCDD)

    Inside / OSP Manager (RCDD)

    CompQsoft • Washington, DC, United States
    [job_card.full_time]
    Location : Mark Center (Pentagon) and in Crystal City, VA.Security Clearance required : Active Top Secret Clearance, SCI Eligible. Must have proof of current or the ability to attain OSP Confined Spac...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Contractor SAP Security Officer (CSSO)

    Contractor SAP Security Officer (CSSO)

    The Aerospace Corporation • Crystal City, VA, United States
    [job_card.full_time]
    The Aerospace Corporation is the trusted partner to the nation's space programs, solving the hardest problems and providing unmatched technical expertise. As the operator of a federally funded resea...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Information System Security Officer (ISSO)

    Information System Security Officer (ISSO)

    The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
    [job_card.full_time]
    Do you love to be on a team of highly skilled, motivated and dedicated professionals charged with protecting sensitive data while administering enterprise Information Systems (IS) that support the ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Consulting Solutions Architect, Networking & Security, Federal (VA, DC)

    Consulting Solutions Architect, Networking & Security, Federal (VA, DC)

    Presidio Networked Solutions, LLC • Waldorf, MD, United States
    [job_card.full_time]
    Presidio, Where Teamwork and Innovation Shape the Future.AtPresidio, we're at the forefront of a global technology revolution, transforming industries throughcutting-edge digital solutions and next...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Smart Home Security Technician

    Smart Home Security Technician

    Safe Streets USA LLC • Columbia, MD, US
    [job_card.full_time]
    Our Elite Home Pro's mission is to show our residential customers that they are truly valued as we have a strong emphasis on providing an unparalleled 5-Star experience unmatched in the Smart S...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Team Member - Columbia

    Team Member - Columbia

    Honeygrow LLC • Columbia, MD, US
    [job_card.full_time]
    Philadelphia-based fast-casual restaurant with a growing number of locations in the mid-Atlantic and northeast regions.Founded on the principles of bringing people together over quality, wholesome,...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Multi-Site Security Officer

    Multi-Site Security Officer

    Securitas • Columbia, MD, US
    [job_card.full_time]
    Availability to cover 2nd and 3rd shifts.Reliable transportation to travel within the Glen Burnie to Columbia area.We help make your world a safer place. Are you interested in being part of our Secu...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Sr. Compliance Associate - Equities

    Sr. Compliance Associate - Equities

    Kraken • Washington, DC, US
    [job_card.full_time]
    Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology. Kraken is a mission-focused company roote...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Apple Store Security Officer - Prior law enforcement / Military

    Apple Store Security Officer - Prior law enforcement / Military

    Blueline Security Services, LLC • Washington, DC, US
    [job_card.full_time]
    Job Description : This is where the job description goes.It provides details about the role, responsibilities, and expectations for the position. It's important to highlight the key skills and qualif...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Cybersecurity Assessment & Authorization (A&A) SME

    Cybersecurity Assessment & Authorization (A&A) SME

    Nationwide IT Services • Fort Belvoir, VA, United States
    [job_card.full_time]
    Cybersecurity Assessment & Authorization (A&A) SME.IT-II Non-Critical Sensitive or Tier 3 (T3) Secret.Remote or DLA HQ, Fort Belvoir, VA. Certified Cloud Security Professional (CCSP) and DoD 8570 / 81...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Team Member 1

    Team Member 1

    Maryland - KFC • Columbia, MD, US
    [job_card.full_time]
    Do you want to be a part of a dynamic and growing industry with over 200,000 restaurants in the U.Yum Brands, a leader in the industry, owns nearly 60,000 restaurants globally, including over 30,00...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Director of Housekeeping

    Director of Housekeeping

    Merriweather Lakehouse • Columbia, MD, US
    [job_card.full_time]
    The Director of Housekeeping will oversee all aspects of housekeeping operations at our hotel, ensuring the highest standards of cleanliness, organization, and guest satisfaction.The ideal candidat...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Azure Security Engineer

    Senior Azure Security Engineer

    AllianceIT Inc • Washington, DC, United States
    [job_card.full_time]
    Job Title : Senior Azure Security Engineer.Location : Washington, DC (Hybrid) On-site 3 days a week at minimum.Skills : Security Controls, Security Tools, System Security. Certifications : Active DoD 85...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Security & Transportation Supervisor

    Security & Transportation Supervisor

    Acts Retirement-Life Communities • Sykesville, MD, United States
    [job_card.full_time]
    Security & Transportation Supervisor.Join our team and grow with us both professionally and personally!.Next day pay : Work today, get paid tomorrow with our PayActiv benefit!.We strongly believe in...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Compliance Officer

    Compliance Officer

    Rolls Royce • Washington, Virginia, US
    [job_card.full_time] +1
    Increase your chances of an interview by reading the following overview of this role before making an application.Indianapolis, IN OR Reston, VA / Hybrid - 3 Office Days / Week.As a Compliance Officer ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Network Security Engineer

    Network Security Engineer

    Office of The Chief Financial Officer • Northern Virginia, VA, United States
    [job_card.full_time]
    Government of the District of Columbia.Office of the Chief Financial Officer (OCFO).Network Security Engineer (INFOSEC).This position is located in the Office of the Chief Financial Officer (OCFO),...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Systems Technician - Service

    Senior Systems Technician - Service

    Vector Security, Inc. • Columbia, MD, US
    [job_card.full_time]
    At Vector Security We Think Big, Do the Right Thing, and Make a Difference Every Day! If this is how you like to work, we’d like to invite you to join our team as a Senior Systems Technician ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Team Member

    Team Member

    CAVA - Columbia • Columbia, MD, US
    [job_card.full_time] +1
    At CAVA, we make it deliciously simple to eat well and feel good every day.We are guided by a Mediterranean heritage that’s been perfecting how to eat and live for four thousand years.We prio...[show_more]
    [last_updated.last_updated_30] • [promoted]