Job description
Are you a Cloud Computing and Cyber Assurance professional? Are you looking to make an impact across the entire federal government? Do you have NIST Risk Management Framework (RMF) knowledge and experience? Do you love researching new technologies and capabilities? Are you self-driven and detail oriented with excellent written and verbal skills? Then this job is for you. Come be a part of a rapidly growing team of highly skilled FedRAMP cyber-SMEs and help redefine the FedRAMP process.
FedRAMP Cyber Engineers are project managers and NIST RMF subject matter experts. We assist the cloud service provider through the FedRAMP process while evaluating compliance, providing technical evaluation, and ensuring the highest quality products are produced for reuse across the entire federal government. Cyber Engineers are required to review CSP implementation for compliance and risk acceptance criteria and work with stakeholders until the system security posture and documentation meets the high standards of FedRAMP. Cyber Engineers work with our teams to advise on new and emerging technologies with an emphasis on security impact. We are seeking qualified individuals to be technical SMEs and develop government-wide guidance.
Key Responsibilities:
- Analyze security posture and vulnerabilities present in cloud architectures
- Review security documentation to security status of cloud products and applications
- Perform security audit and compliance tasks for cloud applications
- Recommend and provide guidance to cloud service providers preforming remediation activities
- Communicate and run meetings with multiple vendors in a small team
- Perform project management for small projects
- Provide tracking and briefing of the security status of cloud service providers
- Develop policy/guidance for new/emerging technologies
- Bachelors degree in technology related field with 15+ years of experience reviewing or developing IT security and compliance documentation (NIST or FedRAMP). Or Masters + 13 years of experience. Work experience can be substituted with commensurate experience
- Experience performing risk assessments and analyzing risk
- Understanding of government cryptography requirements
- Understanding of cloud architecture and security concepts
- Understanding of networking principles and security best practices
- Strong analytical and writing skills
- Strong technical research skills
- Strong communication skills and ability to explain complex technical concepts to non-technical stakeholders
- Excellent teamwork, organizational, communication, and collaboration skills
- US citizen and eligible for public trust
- At least four (4) years of experience in the IT Security frameworks (FedRAMP, NIST, DoD CMMC, etc.)
- Application development and security testing experience
- Penetration testing and vulnerability management experience
- API development and security practices
- Experience developing enterprise security policies and procedures
- OSCAL experience
- CISSP, CISA, CISM or similar certifications
- Experience with operating system or network security management
- Experience managing incident response and after-action remediation
- Post graduate degree in computer science, cybersecurity or information systems
Salary at Noblis is determined by various factors, including but not limited to, the combination of education, certifications, knowledge, skills, competencies, and experience, internal and external equity, location, and clearance level, as well as contract-specific affordability and organizational requirements and applicable employment laws. The projected compensation range for this position is provided within the posting and are based on full time status. Part time staff receive a prorated salary based on regularly scheduled hours. The estimated minimum and maximum displayed represents the broadest range for this position (inclusive of high geographic and high clearance requirements), and is just one component of Noblis’ total compensation package for employees.
Why work at a Noblis company?
Noblis is an Equal Opportunity Employer. Employment decisions are made without regard to race (as well as because of or on the basis of traits historically associated with race, including hair texture, hair type, and protective hairstyles such as braids, locks, and twists), color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, pregnancy, childbirth, lactation and related medical conditions, genetic factors, military/veteran status, or other characteristics protected by law.
Noblis is committed to the full inclusion of all qualified individuals. As part of this commitment, Noblis will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact employee-relations@noblis.org .
seankuhnke.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, seankuhnke.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, seankuhnke.com is the ideal place to find your next job.