Job Summary :
The Cybersecurity Professional will conduct risk assessments, vulnerability analysis, and security control evaluations, ensuring compliance with security standards and policies. This role involves analyzing systems for potential risks, recommending mitigation strategies, and supporting the development of secure IT environments. The professional will also contribute to security governance, risk, and compliance activities.
Location : Capitol, Virginia, United States
Responsibilities :
- Conduct comprehensive risk assessments on information systems and applications.
- Evaluate compliance with Access Control family controls under security standards.
- Review and validate security artifacts, documentation, and technical configurations.
- Identify and document vulnerabilities, threats, and residual risks.
- Prepare draft and final assessment reports for leadership.
- Support security governance, risk, and compliance (GRC) activities.
- Participate in project meetings and provide progress updates.
- Collaborate with IT teams to recommend and implement corrective actions.
- Develop and scope assessment plans based on security requirements.
- Determine and document which security controls will be assessed.
- Collaborate with staff to collect information for evaluating compliance.
- Collect and review artifacts demonstrating compliance with applicable security controls.
- Prepare and deliver draft and final reports to the Chief Information Security Officer.
Required Skills & Certifications :
Experience in information security, compliance, or risk management.Possession of minimum two or more of the following certifications : CISSP, CEH, CISA, SSCP, CISM.Preferred Skills & Certifications :
Not specified in the provided text.Special Considerations :
Must adhere to security standards and policies.Scheduling :
Participate in bi-weekly project meetings and provide weekly progress updates.