IT Security Specialist

Serigor Logo

Serigor

đź“ŤRemote - Worldwide

Summary

Join our team as an IT Security Specialist to support application and infrastructure modernization projects. You will assess client requirements, review documentation for security and compliance, identify risks, and develop mitigation strategies. Responsibilities include implementing security measures, supporting the authorization to operate (ATO) process, ensuring compliance with security standards, and collaborating with various teams. This role requires extensive experience in security compliance, cloud environments, and A&A processes. The ideal candidate possesses strong analytical and problem-solving skills and a comprehensive understanding of system security.

Requirements

  • 5+ years of related work experience
  • 5 years’ experience providing security compliance requirements for Applications in Cloud environments (AWS or Azure or Google etc.)
  • 5 years’ experience updating or maintaining SSP/SSPP documents
  • 5 years’ experience participating in Assessment & Authorization (A&A/ATO)
  • 5 years’ experience supporting infrastructure assets and services by proactive monitoring, evaluating application/system components through system compliance examinations and testing utilizing NIST 800-53
  • 5 years’ experience providing security engineering review and recommendations
  • 5 years’ experience working with large teams in an Agile environment
  • 5 years ISSO experience
  • Experience coordinating and working under an ATO
  • Experience assessing system modifications such as major and minor releases and potential security impacts
  • Experience providing recommendations for improvement to amend vulnerabilities
  • Experience assisting Program Managers and Senior Leadership developing Correction Action Plans (CAPs) when responding to IT and Financial audits
  • Experience implementing AWS Security configurations
  • 3 Years Experience performing Security Operations Center capabilities such as Logging and Monitoring, Incident Handling, Disaster Recovery
  • 3 Years Experience providing security compliance requirements for Applications/ Systems in Cloud Environments (AWS, Azure, Google cloud)
  • 5 Years Must be able to review & assess MES systems throughout all phases of their life cycle in an effort to identify Privacy, Security Architecture
  • 5 Years Risk Management - must be able to Identify gaps through risk management, and assist in the development of mitigation strategies
  • 5 Years Experience updating privacy and security policies based on gaps found through an assessment process
  • 5 Years Experience documenting vulnerability assessment results in a accurate, clear, actionable, and available way to appropriate personnel
  • 3 Years Must be able to serve as a knowledge base for organizations as it relates to CMS and state compliance requirements & mitigation strategies
  • 5 Years Experience Performing risk assessments based on NIST 800-53 Rev 4. HIPAA, SSA and IRS Pub 1075
  • 5 Years Experience with network mapping and vulnerability scanning tools such as NESSUS and NMAP
  • 5 Years Experience in reviewing RFP, RFQ, MOU and MOA for privacy and security architecture requiremetns
  • 3 Years Experience in reviewing the Business Continuity plans, Disaster Recovery Testing plans based on Federal and State requirements

Responsibilities

  • Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information
  • Continuously assess the development process and suggest improvements
  • Support the ISSO with the management of system security plans, ensure the systems obtain and maintain an authorization to operate (ATO), and meets all requirements for certification and provide support to achieve all activities associated with the Assessment and Authorization (A&A) process
  • Provide support and security compliance to meet the security standards for Applications and systems in Cloud environments (AWS or Azure or Google etc.)
  • Provide Security compliance oversight of information systems security program for applications and systems within the ATO boundary leveraging MARS-E, NIST, and HIPPA Guidelines
  • Coordinate with the O&M and Infrastructure team to ensure COTS and other support software is current and compliant with current InfoSec policies; The program participates in the IT Continuous Monitoring Program
  • Provide support to Software Developers, Engineers and other team members on the optimal methods to meet security requirements while minimizing impact and delays in meeting mission requirements
  • Work closely with the Enterprise Architecture (EA), Database Administrator (DBA), Migration and Application Development teams to develop and implement automated Disaster Recovery capabilities including automated alerting, notifications, containment, data backup & recovery
  • Partner with EA, and Application Development teams to develop Security Event Logging and Monitoring processes
  • Perform internal assessments of security controls to ensure compliance with legislation, regulation, and technical standards with technical teams
  • Monitor infrastructure assets and services, evaluate application/system components through system compliance examinations and testing utilizing NIST 800-53
  • Track and monitors remediation efforts stemming from IT assessment and financial audits through Plans of Actions and Milestones (POA&Ms) and Correction Action Plans (CAPs) and informing Senior Leadership of security measures in place
  • Ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure

Preferred Qualifications

  • Bachelor’s degree in computer science, management information systems, or related field
  • Security architecture knowledge like TOGAF and MITA
  • 3 Years MITA (Medicaid Information Technology Architecture) Experience
  • 3 Years Experience performing DevSecOps Engineering capabilities

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.