Logo
Ampcus, Inc

Senior Cloud Security Specialist.

Ampcus, Inc, Washington, District of Columbia, us, 20022


PROJECT DESCRIPTION : RAPID (Rapid Agile Product Innovation & Development) Security and Privacy Workstream.

BACKGROUND : The Division of Financial Management (DFM) seeks an experienced individual to provide services in support of the continuous monitoring of FedRAMP authorized cloud solutions. We are looking for an experienced information security specialist to work directly with cross-division subject matter experts (SMEs) and provide insight, advice, support, and recommendations to ensure the success of the continuous monitoring process, with a targeted focus in FedRAMP, FISMA, Privacy Act, and OMB requirements. The selected individual shall have experience successfully reviewing FedRAMP continuous monitoring packages and advising on secure cloud control implementation. The successful candidate shall be adept at working collaboratively in a consensus-based environment while serving as an individual contributor who develops information security related work products.

REQUIREMENTS :Bachelor's degree or higher in information security, or a related field or equivalent experience.At least one advanced cybersecurity certification such as: CISSP, CCSP, CRISC, or other relevant security certifications; multiple are preferred.At least seven (7) years of information security experience, including cloud security and continuous monitoring activities.Extensive NIST experience: NIST SP 800-30 rev 1, 800-37 rev 1 or 2, 800-53 rev 5, 800-60 Vol 1 rev 1 & 2 rev 1, and 800-171 rev 3.Experience with implementing systems in a FedRAMP, FISMA, and SOX compliant environment.Proven ability to forge consensus and work collaboratively, without positional authority, to influence stakeholder groups in different hierarchical structures.Demonstrate strong project execution and project management capabilities.Experience with FedRAMP reporting requirements, including but not limited to, risk assessments, Plan of Action, and Milestones (POA&M), and remediation plans.PREFERRED KNOWLEDGE AND EXPERIENCE:Experience with government compliance, including OMB requirements, FISMA, FedRAMP, RMF, and CSF.Experience with cloud environments, architectures, technologies, and services.FedRAMP experience and certification.Advanced knowledge and experience with project management methodology, information security compliance, and implementation of security architectures and related standards.Knowledge of the laws and regulations governing information security and compliance.Excellent communication skills (verbal and written), and able to adjust to changing priorities and customer needs.Strong interpersonal and organizational agility skills. Must be able to deal effectively with all levels of management and staff.Detail-oriented and committed to excellent customer service.RESPONSIBILITIES:Review current continuous monitoring program and provide recommendations for improvement.Conduct monthly FedRAMP continuous monitoring package analysis, including reviewing deviation requests and POA&Ms as well as documenting a summary for the client.Advise clients on FISMA/FedRAMP compliance activities while staying current with legislation, NIST, and OMB requirements.Conduct security risk assessments for third-party applications and service providers.Ensure organizational structure recommendations integrate cohesively into the overall DFM and Client strategic direction and are in alignment with other high-priority work across the division.Identify and help plan for long-term financial considerations due to cloud migration and business transformation.Review and advise on post-implementation decommissioning scheme for legacy applications, as well as migration and maintenance of historic data.Review additional processes and procedures and make recommendations for improvement to the client.Provide ad-hoc support services, including advisory consulting services for Client leaders, facilitating strategic meetings or working sessions, and reviewing and opining on FR system documentation.

#J-18808-Ljbffr