Security Controls Assessor (SCA) Manager
Company: MindPoint Group
Location: Washington
Posted on: January 26, 2023
|
|
Job Description:
Security Controls Assessor (SCA) Manager Department:GRC
Location: Text code SCAMG to 202-915-6712 to apply! MindPoint Group
delivers industry-leading cybersecurity solutions, services, and
products. We are trusted cybersecurity advisors to key government
and commercial decision-makers and support security operations for
some of the most security-conscious organizations globally. Our
relationship with you is for the long run because your success is
our success. We invest in your success through fantastic benefits
(healthcare, generous PTO, paid parental leave, and tuition
reimbursement, to name a few). Beyond just excellent pay and
benefits, you-ll want to work here for reasons that can-t be
written into an offer letter-the challenge, growth opportunities,
and most important: the culture of a company that cares about you.
A position at MPG promises you + A diverse organization + A safe
workplace with zero tolerance for discrimination or harassment of
any kind + A balanced work life. Seriously. + A stable,
established, and growing business + A leadership team focused on
your professional growth and development Job Description MindPoint
Group seeks to hire a Security Control Assessor (SCA) Manager to
provide information security Assessment and Authorization (A&A)
support to Contractor and Government facilities processing
information and guidance to more junior SCAs. SCAs enhance the
Information System security awareness of Directorates' & Offices'
staffs, ensure that proper IS security resources are appropriately
applied, and act as a liaison between the Directorates and various
Offices. What you get to do every day: + Provide continuous
management of customer cyber policies, technical solution
implementation, certification process guidance, and incident
responder + Assess the effectiveness of NIST 800-171/CMMC security
controls + Design/integrate a cyber strategy that outlines the
vision, mission, and goals that align with the organization-s
strategic plan + Draft, staff, and publish cyber policy + Develop
methods to monitor and measure risk, compliance, and assurance
efforts + Develop specifications to ensure risk, compliance, and
assurance efforts conform with security, resilience, and
dependability requirements at the software application, system, and
network environment level + Draft statements of preliminary or
residual security risks for system operation + Maintain information
systems assurance and accreditation materials + Perform security
reviews, identifies gaps in security architecture, and develop a
security risk management plan + Perform security reviews and
identify security gaps in security architecture resulting in
recommendations for inclusion in the risk mitigation strategy +
Perform risk analysis (e.g., threat, vulnerability, and probability
of occurrence) whenever an application or system undergoes a
significant change + Plan and conduct security authorization
reviews and assurance case development for the initial installation
of systems and networks + Verify that application
software/network/system security postures are implemented as
stated, documents deviations, and recommend required actions to
correct those deviations + Assess policy needs and collaborates
with stakeholders to develop policies to govern cyber activities +
Monitor the rigorous application of cyber policies, principles, and
practices in the delivery of planning and management services +
Provide policy guidance to cyber management, staff, and users +
Review, conduct, or participate in audits of cyber programs and
projects + Interpret and apply applicable laws, statutes, and
regulatory documents and integrate them into policy + Promote
awareness of cyber policy and strategy as appropriate among
management and ensure sound principles are reflected in the
organization-s mission, vision, and goals + Supervise, develop, and
train the SCA team + Review and evaluate work prepared by the SCA
team + Train SCA Team on how to use current software tools and
Industry Specialty Services methodology + Schedule and supervise
the workload of associates and senior associates Qualifications
Secret Clearance required What skills are required? + Bachelor-s
Degree or an additional 8 years of relevant experience + Minimum of
10 years of general work experience and 8 years of relevant
functional experience + Experience in cybersecurity project
management + Experience providing guidance, mentorship, and reviews
to security control assessment team members + Experience providing
Information Security advice and guidance to Government and Industry
Stakeholders + Communicate effectively with all customer
stakeholders + PMP required What is ideal? + Practical experience
performing information systems assessment and authorization
(A&A) as defined in applicable ICDs and guidance and performing
the processes involved in developing and implementing
security-related directives and guidance for IA/IT/IM + Experience
utilizing risk management strategies for information technology
solutions + Technical understanding of emerging technologies and
their implementation within Government systems and network
environments + Knowledge of information technology concepts used in
the evaluation of security performance and integrity of
state-of-the-art applications, communications systems, hardware,
software, satellite control systems, and information processing
systems + Ability to effectively coordinate A&A activities of
industry and Government information systems and manage and track
systems involved in the A&A process + (ISC)2Certified
Authorization Professional (CAP) Additional Information + All
offers are contingent upon proof of full vaccination against
COVID-19 or successful accommodation for an exemption. + All your
information will be kept confidential according to EEO guidelines.
+ Compensation is unique to each candidate, and relative to the
skills and experience they bring to the position. The salary range
for this position is typically $150-160k. This does not guarantee a
specific salary, as compensation is based upon multiple factors
such as education, experience, certifications, and other
requirements and may fall outside of the above-stated range. +
Highlights of our benefits include Health/Dental/Vision, 401(k)
match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses,
professional development reimbursement, maternity/paternity leave,
mobile phone stipend, pre-tax commuter benefits, the opportunity to
participate in our mentorship program, and more! + MindPoint is
committed to maintaining a diverse environment. All qualified
applicants will receive consideration for employment without regard
to sex, race, ethnicity, age, national origin, citizenship,
religion, physical or mental disability, medical condition, genetic
information, pregnancy, family structure, marital status, ancestry,
domestic partner status, sexual orientation, gender identity or
expression, veteran or military status, or any other basis
prohibited by law. Text code SCAMG to 202-915-6712 to apply!
Keywords: MindPoint Group, Washington DC , Security Controls Assessor (SCA) Manager, Executive , Washington, DC
Click
here to apply!
|