Jobs at Janus Soft Inc

View all jobs

Cyber Security Project Engineer, Manager and Architects - Herndon VA

Herndon, VA · Computer/Software

The Sponsor requires support in understanding and implementing standards like ICD 503, NIST Risk Management Framework, and cloud technologies. The work requires a healthy mix of technical and policy knowledge. The work will be driven by the Sponsors needs and priorities.
Work requirementS
The Sponsor will direct priorities and delegate tasks.

  • The Contractor Team shall manage security assessment, security compliance, change management, and continuous monitoring activities across five cloud service providers through the Sponsor’s office.
  • The Contractor Team shall assess cloud security technologies for security gaps and weaknesses according to industry standards.
  • The Contractor Team shall analyze security scan findings and perform risk analysis on security scan findings.
  • The Contractor Team shall review cloud security body of evidence packages for completeness and accuracy.
  • The Contractor Team shall collaborate with other internal components and security peers to determine security and potential weaknesses of cloud infrastructure and cloud services.
  • The Contractor Team shall advise Sponsor leadership on cloud security services.
  • The Contractor Team shall analyze system alerts to determine if a security weakness exists and document risk mitigation procedures.
  • The Contractor Team shall sustain and evolve the Sponsor’s standard operating procedures to meet Program Objectives.
  • The Contractor Team shall facilitate technical exchange meetings (TEMs) with cloud service providers to review cloud service architectures.

required skills and demonstrated experience

The Contractor shall have the following required skills, certifications and demonstrated experience:

  • Demonstrated experience facilitating Technical Exchange Meeting (TEM) with cloud service providers to review cloud service architectures.
  • Demonstrated experience maintaining assessment and authorization packages across multiple services or systems in accordance with FIPS-199, NIST 800-53, and CNSS 1253 requirements.
  • Demonstrated experience designing, implementing, assessing or reviewing systems that utilize cloud technology with either Amazon Web Services, Oracle Cloud, Google Cloud, IBM Cloud, or Microsoft Azure cloud architecture.
  • Demonstrated experience utilizing or reviewing cross domain technology and common architecture designs.
  • Demonstrated experience consulting project teams on system architecture and security posture.
  • Demonstrated experience with continuous monitoring requirements to include scan analysis for critical or high findings with common scan tools such as Rapid 7, Nessus or Qualys.
  • Demonstrated experience creating, monitoring, or closing system or service Plans Actions and Milestone items (POA&Ms).
  • Demonstrated experience utilizing compliance tools to track assessment and authorization activities such as Xacta 360, Service Now, or RSA Archer.
  • Demonstrated experience with the common control provider concept within the NIST Risk Management Framework.
  • Demonstrated experience with security control assessments (SCAs) to include working with SCAs and preparing security packages for SCAs.

Highly Desired skills and demonstrated experience

Skills and demonstrated experiences that are highly desired but not required to perform the work include:
  • Demonstrated experience using the Sponsors or similar element assessment and authorizing process.
  • Demonstrated experience creating or reviewing A&A body of evidence documentation in a cloud security environment.
  • Demonstrated experience identifying, implementing, or reviewing appropriate information security controls.
  • Demonstrated experience working in Xacta 360.

Share This Job

Powered by