Job description :
- Willingness to serve as a risk management expert providing meaningful input to ensure risk drivers are appropriately considered, assessed, and prioritized.
- Evaluate the appropriateness of the audit response to changes in risk ratings.
- Expertise in the risk and controls questionnaire-based risk identification, control evaluation, testing, sampling methodologies, technology controls, audit engagement processes, controls substantiation.
- General knowledge of the Secure Application Development Lifecycle (SADLC) and the Software Development Lifecycle (SDLC) processes and practices.
- Excellent analytical and problem-solving skills
- Self-motivated with strong attention to detail
- Excellent verbal and written communication skills.
Top Skills & Years of Experience :
5+ years of experience with cybersecurity related job functions.Strong knowledge of - NIST SP800-53 Rev 4 & 5, HIPAA, FERPA, etc.IaaS, PaaS, SaaSWillingness to serve as a risk management expert providing meaningful input to ensure risk drivers are appropriately considered, assessed, and prioritized.Expertise in the risk and controls questionnaire-based risk identification, control evaluation, testing, sampling methodologies, technology controls, audit engagement processes, controls substantiation.Preferred : Bachelor's Degree in cybersecurity or related field is highly preferred, Cybersecurity certifications are a plusKnowledge / Skills :
In-depth knowledge and understanding of compliance practices and methodologies, including risk assessment, monitoring, surveillance, and testing activities.Desire to work in a collaborative environment, develop and drive strategic direction contribute day-to-day on implementing tactical solutions.Strong knowledge and understanding of compliance regulations and their related frameworks, such as :NIST SP800-53 Rev 4 & 5Criminal Justice Information Services (CJIS) Security Policy. Version 5.9The Privacy Act of 1974The Health Insurance Portability and Accountability Act of 1996 (HIPAA)The Family Educational Rights and Privacy Act (FERPA)Experience :
5+ years of experience with cybersecurity related job functions.Strong knowledge and understanding of information technology systems and services to include :VirtualizationContainerization (Docker)Cloud Hosting Operations and TechnologiesIaaS, PaaS, SaaSWindows Workstations / Servers FunctionalitiesLinux Server FunctionalitiesIdentification and Authentication processes and technologies (SSO / Reverse Proxies)Encryption and CryptographyDisaster Recovery and Business Continuity processesComputer NetworkingQualification :
Preferred : Bachelor's Degree in cybersecurity or related field is highly preferred, Cybersecurity certifications are a plusRequired Skills : Risk Management
Additional Skills : Technical Writer