Cyber Information Security SME

Iron Vine Security, LLC Career Center
Washington, DC Full Time
POSTED ON 4/15/2024

Position Title: Cyber Information Security SME

Location: Washington D.C

 

Position Summary:

Iron Vine Security is a rapidly growing information security and information technology company in Washington, DC. We are looking to hire a Cyber Information Security SME to support a full range of cyber security services on a long-term contract in Washington DC. The position is full time/permanent and will support a US Government civilian agency. The position is available immediately upon finding a qualified candidate with the appropriate background clearance.

 

Job Requirements:

· Strong written and verbal communication skills.

· Demonstrated ability to interact effectively with senior management and leadership.

· Possess knowledge of NIST Risk Management Framework at the subject matter expert level, particularly including SP 800-30, 37, 39, 53, and 53-A.

· Ability to craft enterprise-specific implementation guidance for system owners who are attempting to satisfy NIST SP 800-53 controls.

· Extensive experience drafting SOPs, System Security Plans, Security Assessment Plans, POAMs

· Ability to analyze and interpret Federal legislation, directives, Office of Management and Budget (OMB) mandates, and guidance provided by the National Institute of Standards and Technology (NIST) against existing information security and privacy policy to identify required updates.

· Understanding of FIPS 199 Federal Computer Systems Categorization standards.

· Experience with supporting the Authorization to Operate (ATO) process.

· Ability to conduct research on new and emerging information technologies and develop comprehensive information security and privacy policy, standards/guidelines, and procedures to facilitate the implementation of information security and privacy controls.

 

Certifications/Licenses:

· BS degree or other 4-year college degree or equivalent work experience

· 5 years’ experience in information security and assurance

· One of the following certification or equivalent certifications preferred:

- Certified Information Systems Security Professional (CISSP);

- Certified Information Security Manager (CISM);

- Certified Information Privacy Professional (CPP);

- Certified Information Privacy Manager (CIPM);

· Active Public Trust clearance or higher

 

Additional Experience Preferred:

· Knowledge of risk and how to measure risk with respect to IT systems.

· Knowledge of IT systems used in health care or health research.

· Experience reviewing and drafting Privacy Impact Assessments (PIAs).

· Has reviewed and developed Security Assessment and Authorization (SA&A) documents.

· Possesses an in depth understanding of the NIST Risk Management Framework (RMF).

· Supported efforts to ensure compliance with FISMA and NIST Guidance.

· Ability to provide recommendations and guidance to the customer which enables them to enhance and optimize their information security program.

 

Position Responsibilities:

· Review and update existing information security policy, standards, and Standard Operating Procedures based on federal and departmental regulations.

· Draft, review, and/or update SA&A security artifacts such as FIPS 199, PTA, PIA, NIST SP 800-60-3 Digital Identity, Information System Contingency Plan and Contingency Test Plan, System Security Plan, Security Assessment Plan, Security Assessment Report.

· Draft security policies and procedures and provide recommendation for improvement and compliance with applicable standards.

· Support Disaster Recovery and Incident Response efforts

· Examine system documentation, interview appropriate system stakeholders, test system technical security configuration settings, review vulnerability scan results for compliance requirements

· Assist with the interpretation and analysis of Security Assessment Results upon completion of each Security Assessment and/or as requested to assist with post-assessment questions, to assess the vulnerability and risk to the system and to the customer or other connected systems.

Salary.com Estimation for Cyber Information Security SME in Washington, DC
$182,261 to $230,009
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs with skills like those required for the Cyber Information Security SME.

Click the checkbox next to the jobs that you are interested in.

  • Data Security Skill

    • Income Estimation: $91,233 - $116,441
    • Income Estimation: $122,268 - $158,377
  • Endpoint Protection Skill

    • Income Estimation: $76,560 - $106,749
    • Income Estimation: $85,971 - $130,387
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Iron Vine Security, LLC Career Center

Iron Vine Security, LLC Career Center
Hired Organization Address Suitland, MD Full Time
Job Requirements: Strong written and verbal communication skills. Knowledge of capabilities and requirements analysis, c...
Iron Vine Security, LLC Career Center
Hired Organization Address Washington, DC Full Time
Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintainin...
Iron Vine Security, LLC Career Center
Hired Organization Address Washington, DC Full Time
Job Requirements: · 8 years of Executive-Level cyber RMF consulting experience advising Cybersecurity programs in large ...
Iron Vine Security, LLC Career Center
Hired Organization Address Washington, DC Full Time
Position Title: Program Manager Location: Washington, DC (On-site twice a week) Hours: 8am - 4pm Position Summary: Iron ...

Not the job you're looking for? Here are some other Cyber Information Security SME jobs in the Washington, DC area that may be a better fit.

Cyber Security Analysis Support - SME - A298

SME - A298 - TLA-LLC, Chantilly, VA

ISSO SME

Cyber Security Innovations, Springs, MD