
IT System Assessor
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in United States.
• Assess the Enterprise IT infrastructure systems, including tasks such as conducting security control evaluations through an independent (firewalled) team.
• Conduct interviews, test controls, develop Security Assessment Reports (SARs), and create Plans of Action and Milestones (POAMs).
• Evaluate Authority to Operate (ATO) packages for precision and thoroughness.
• Enforce stringent quality standards and offer technical assistance for the completion of ATO packages.
• Create and update Standard Operating Procedures (SOPs) for Security Assessment and Authorization (SA&A), ensuring adherence to NIST SP 800-53 and conducting periodic reviews for revisions.
• Identify essential roles (AO, CISO, System Owner, etc.) and establish a matrix of cybersecurity responsibilities for each FISMA system.
• Concentrate on reducing risks to Personally Identifiable Information (PII), Protected Health Information (PHI), and sensitive data, maintaining comprehensive Privacy Impact Assessments (PIAs), and keeping abreast of privacy laws and regulations.
• Provide guidance to senior management on best practices for privacy and data protection.
• A minimum of THREE (3) years of experience in Risk Management Framework / Security Assessment and Authorization.
• Experience with RMF in producing complete ATO packages for systems, including SSP, FIPS 199, E-Authentication, PTA/PIA, Incident Response Plan, Contingency Plan, and Configuration Management Plan.
• Proven experience in developing and conducting Incident Response tabletop exercises and Contingency Plan functional tests.
• Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must secure approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse.
• Preference will be given to candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and who maintain an active HHS/NIH clearance.
• Familiarity with NIST 800-53 and NIST 800-37.
• Experience with cloud systems and SaaS products, along with an understanding of FedRAMP requirements.
• Possession of at least one of the following certifications: CISA, CISSP, CompTIA Security+ CE, Certified Professional CompTIA Network+ CE, or Certified Cloud Certificates (AWS, Azure, and/or Google).
• Experience in assessing at least 2 of the 8 types of platforms/systems listed: ICAM Solution (preferably with Active Directory, SailPoint, and CyberArk), Network (firewalls, IDS/IPS, switches, routers, VPN), Cloud Hosting (experience with at least 2 of the following – AWS, Azure, Google), On-premise Hosting (Windows and Linux platforms), Microsoft 365 Tenant, Third Party SaaS Platforms, High Performance Computing Systems, AI applications and Systems.
• Medical, Rx, Dental & Vision Insurance
• Personal and Family Sick Time & Company Paid Holidays
• Parental Leave
• 401(k) Retirement Plan
• Group Term Life and Travel Assistance
• Voluntary Life and Accidental Death & Dismemberment Insurance
• Health Savings Account, Health Care & Dependent Care Flexible Spending Accounts
• Transit and Parking Commuter Benefits
• Short-Term & Long-Term Disability
• Tuition Reimbursement, Personal Development, Certifications & Learning Opportunities
• Employee Referral Program
• Corporate Sponsored Events & Community Outreach
• Care.com annual membership
• Employee Assistance Program
• Supplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance, and ID theft protection, etc.)
Julesetmoi
National University
MeridianLink
Woolpert
Get handpicked remote jobs straight to your inbox weekly.