
Project Lead – Senior Information System Security Specialist
Posted Sep 2

Posted Sep 2
This is a fully remote position, open to applicants in United States.
• Provide program management and technical cybersecurity support for the DOT/FHWA Cyber Security Management Support program.
• Plan, implement, operate, monitor, and report on cybersecurity activities that enhance FHWA information-system security.
• Develop and manage project plans, schedules, risk registers, issue logs, communications plans, quality plans, and related documentation.
• Coordinate and oversee program activities, tasks, milestones, staffing, finances, deliverables, and overall performance.
• Track deliverables, document rejection reasons, and manage corrective actions until resolution.
• Prepare monthly reports on quality, performance, and project status as well as briefings.
• Conduct project kick-off and monthly status review meetings, preparing agendas, minutes, and tracking action items.
• Coordinate transition-in activities with Government personnel, incumbent contractors, and stakeholders.
• Manage staffing, personnel acquisition and retention, training, and labor-category compliance.
• Maintain quality-control processes and conduct peer reviews.
• Recommend enhancements to operational efficiency, cost-effectiveness, cybersecurity effectiveness, and program value.
• Provide cybersecurity expertise in incident handling, vulnerability detection, remediation planning, secure application development, cloud environments, and cloud services.
• Assist the ISSM in maintaining the appropriate operational Information Assurance posture.
• Review Elasticsearch logs and investigate cybersecurity incidents.
• Support the FHWA DevSecOps implementation and the integration and management of static-code vulnerability scanners.
• Maintain FHWA network, asset, group, and custom-group inventory within the DOT CDM BigFix tool.
• Conduct and analyze vulnerability and compliance scans across Linux, Windows, and virtual environments.
• Identify, assess, track, and support the remediation of vulnerabilities in web applications, databases, networks, and infrastructure.
• Perform dynamic web application security testing.
• Maintain documentation for FHWA core systems and support Authorization to Operate and privacy documentation.
• Assist with FISMA, CFO, OIG, and GAO audits, evaluations, data calls, and inquiries.
• Track and report on audit findings, corrective actions, statuses, and resolutions.
• Execute Information System Contingency Plan testing and provide contingency training.
• Support tabletop and functional contingency tests, backup and recovery activities, and NIST contingency planning guidance.
• Analyze cloud-system security controls and aid in compliance with Federal cloud-security requirements.
• Provide cybersecurity guidance and programmatic assistance to system owners, business sponsors, developers, infrastructure teams, and IT operations personnel.
• Perform other job-related duties as assigned.
• Bachelor’s degree in Cybersecurity or a related technical field.
• Current, verifiable Certified Information Systems Security Professional (CISSP) certification.
• Current, verifiable Certificate of Cloud Security Knowledge, Microsoft Azure certification, or another recognized cloud-security certification.
• PMP certification is highly desirable.
• Desired certifications include ITIL v3 or later and relevant credentials from ISC2, ISACA, SANS, EC-Council, Cisco, or similar organizations.
• Demonstrated knowledge of project and program management principles, methodologies, and PMBOK practices.
• Experience with Tenable Nessus, Splunk, Netsparker, BigFix, and SYNACK.
• Experience assisting Government sponsors in responding to inspections and assessments.
• Experience in developing and managing project plans, schedules, status reports, risk registers, deliverable trackers, quality documentation, and management reports.
• Experience coordinating technical and administrative work across Government stakeholders, contractor management, technical teams, system owners, and other project participants.
• Strong written, verbal, analytical, organizational, briefing, and documentation skills.
• Ability to communicate effectively with both technical and nontechnical stakeholders.
• Expert knowledge of Federal cybersecurity and privacy laws, regulations, policies, procedures, and implementation standards.
• Expert experience supporting compliance with applicable NIST Special Publications, FIPS 199, and FIPS 200.
• Understanding of the FISMA assessment and authorization process, GSA FedRAMP processes, and current cloud-service technologies.
• Experience applying Federal Information Security Continuous Monitoring and Continuous Diagnostics and Mitigation program technologies.
• Knowledge of secure application development concepts, dynamic and static application-security testing tools, scan results, and remediation practices.
• Experience conducting vulnerability, application-security, database-security, and network-security assessments and interpreting assessment results.
• Understanding of Identity, Credential, and Access Management implementation.
• Expert experience with enterprise security architecture methodologies, concepts, procedures, principles, and tools.
• Knowledge of Windows Server, Linux/Unix, Active Directory, domain structures, network protocols, authentication, digital signatures, firewalls, data-loss-prevention technologies, intrusion-detection, and intrusion-prevention systems, and security best practices.
• At least three years of experience in contingency planning, backup and recovery best practices, and NIST contingency planning guidance.
• Experience assessing cloud-system security controls.
• Experience with risk-management tools, including JCAM (formerly CSAM).
• Proficiency with Microsoft Word, Excel, PowerPoint, Visio, Teams, Tableau, and SharePoint.
• Ability to manage multiple concurrent priorities.
• Must possess or be able to obtain a DOT Public Trust clearance.
• Must satisfy all applicable Cherokee Federal, Government, and DOT personnel-security and background-screening requirements.
• Must pass pre-employment qualifications of Cherokee Federal.
• Medical, Dental, Vision.
• 401K.
• Other possible benefits as provided.
• Veterans and active military transitioning to civilian status are encouraged to apply.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.