Overview
We are seeking a talented and knowledgeable Cloud Security Specialist to serve as an expert in Information Assurance and cloud computing. This role focuses on Certification and Accreditation (C&A) and encompasses the application of National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) standards and guidance as detailed in NIST Special Publication(s) (SP) 800-53 and 800-37.
Primary Duties and Responsibilities
- Manage services on Google Cloud Platform (GCP).
- Maintain current certification as a Certified Cloud Security Professional and possess extensive cloud computing security expertise.
- Identify, manage, and mitigate cloud computing security risks while implementing industry best practices in different cloud environments.
Other Duties and Responsibilities
Investigate and assess information security incidents to evaluate potential impacts on national security information and automated systems.Define security objectives and system-level performance requirements.Stay updated on cybersecurity tools, techniques, and emerging trends in network vulnerabilities.Configure and validate secure systems, conducting tests to identify cybersecurity weaknesses.Oversee the incident, damage, and threat assessment programs for computer and information security.Lead formal Security Test and Evaluation (ST&E) for government accreditation, including preparation, participation, and result analysis.Conduct periodic reviews of system audits and ensure corrective actions are completed.Design or recommend integrated system solutions that protect proprietary and confidential data.Establish program controls to mitigate risks and support certification and accreditation efforts.Review current processes and security protocols, recommending enhancements to bolster cybersecurity protections.Minimum Qualifications
Bachelor's Degree in Computer Science or a related field.Strong understanding of FedRAMP assessment methodologies across six domains : Architectural Concepts & Design Requirements, Cloud Data Security, Cloud Platform & Infrastructure Security, Cloud Application Security, Operations, and Legal & Compliance.Five years of relevant experience in C&A, RMF, and NIST frameworks.Experience with DOD Information Assurance (IA).Proven ability to assess IA controls and conduct C&A reviews for complex information systems.Security Clearance
Active Secret level clearance.Sensitivity Level : IT-I Critical Sensitive.Certifications
Computing Environment : IAT II or IAT III (Security+ or similar).Cloud certifications : One of the following Azure or AWS certifications from the DLA Approved CE list.AWS Certified Security Specialty.AWS Certified Solutions Architect (Associate and Professional).Microsoft Certified : Azure Administrator Associate and Azure Solutions Architect Expert.Microsoft Certified : Azure Security Engineer Associate.Other Job Specific Skills
Ability to communicate effectively and present technical findings clearly.Capable of exercising a limited degree of latitude in defining technical objectives.Strong attention to detail and ability to manage multiple tasks concurrently.Advanced knowledge in encryption, vulnerability assessment, penetration testing, cyber forensics, intrusion detection, and incident response.Compensation Ranges
Compensation for this position varies based on factors such as location, skill set, education level, certifications, and years of experience. This role's compensation is a guideline based on these elements and is tailored to the specific opportunity. Monetary compensation is part of a comprehensive benefits package at ASM.
EEO Requirements
ASM is committed to equal employment. Employment decisions are made without regard to race, color, religion, sex, disability, age, sexual orientation, or national origin. All recruiting, hiring, training, and promotion practices align with this commitment.
Disclaimer
This job description outlines the general nature and level of work performed by employees in this classification and is not an exhaustive list of all responsibilities, duties, and qualifications required.