Cybersecurity/CDM Lead

Full Time
Remote
Posted
Job description
Overview:
At Criterion Systems, we developed a different kind of business—a company whose real value is a reputation for excellence built upon the collective skills, talents, perspectives, and backgrounds of its people. By accepting a position with Criterion Systems, you will join a group of professionals with a collaborative mindset where we share ideas and foster professional development to accomplish our goals. In addition to our great culture, we also offer competitive compensation and benefit packages, company-sponsored team building events, and advancement opportunities. To find out more about how Criterion can help you take your career to the next level please visit our website: www.criterion-sys.com.

Criterion Systems is Military/Veteran Friendly Company therefore we encourage Veterans to apply.
Responsibilities:

IT Security Governance & Policy/Change Management:

1. Manages weekly change management board (CMB) processes, including:
  • Facilitate meeting/agenda – Weekly Change Control Board (CCB)
  • Validation/closure – post implementation
  • Document meeting minutes
  • Review current processes, suggest improves and efficiencies
2. Support Security Control Assessments for (ATOs)/Continuous Monitoring
  • Provide response/supporting artifacts at the modal/program level to validate the implementation of controls per NIST/DOT requirements as needed.
3. Support the modal security team as needed.
4. Update CM SOPs as required.
  • Create, review, manage and maintain program documentation
  • Manage and maintain documents, policies, procedures, and SOPs for the modal cybersecurity program.
  • Review cybersecurity program documents, policies, and procedures to ensure they adequately developed and in keeping with current best practices, federal law, regulations, and federal/departmental policy.
  • Create a review system for ensuring all documents for the cybersecurity program are reviewed at least annually and/or as needed.

Cybersecurity and Information Technology (IT) Security:

1. Assess the current state of the Cybersecurity Program, identify areas for improvement, and execute approved recommendations.
2. Assist with the creation of documents to support ATO and SA&A to include:
  • System Security Plan
  • Business Impact Analysis
  • Risk Assessment
  • Contingency Plan
  • Incident Response Plan
  • Security Test and Evaluation (Plan and Results)
  • Plan of Action and Milestones
  • Certification Statement; and
  • Accreditation Statement
3. Evaluate new software requests for security considerations and compliance with Federal regulations and guidance.
4. Provide support and manage Education, Training (general and specialized) and Awareness (ETA) initiatives for PHMSA staff with cybersecurity responsibilities.
5. Provide support for implementation and compliance with DOT and other Federal initiatives such as Federal Risk and Authorization Management Program (FedRAMP); Cybersecurity Workforce Assessment Act (including National Institute for Cybersecurity Education (NICE) Cybersecurity Workforce Framework); Cybersecurity National Action Plan (CNAP); Federal Data Center Optimization Initiative (DCOI); Federal Identity, Credential, and Access Management (ICAM), Internet Protocol version 6 (IPv6) and future memorandums, orders, directives, laws, or policies
6. Provide support, as directed by the PHMSA Information System Security Manager (ISSM), to PHMSA Community concerning Cybersecurity policies, processes, and procedures; and
7. Perform other activities relating to PHMSA’s Cybersecurity program as directed by the PHMSA ISSM.

Continuous Diagnostics and Mitigation (CDM):

1. Work with PHMSA and DOT stake holders to implement a holistic CDM capabilities across the modal footprint.
  • Analyze threats to identify gaps in current defensive posture.
  • Ensure PHMSA’s CDM capabilities utilize or tie into departmental CDM capabilities and solutions.
  • Conduct scans and track IOCs and vulnerabilities and communicate those out to DOT and PHMSA stake holders to include system owners, DOT SOC, and others.
  • Configure and execute vulnerability scans enumerating vulnerabilities within PHMSA’s internal and external network.
  • Analyze and prioritize specific activities designed to remediate discovered vulnerabilities such as patch deployment or configuration hardening.
  • Effectively support and maintain DOT/PHMSA compliance efforts with Federal, State, and other industry information security reporting requirements and obligations.
  • Respond to technical issues in a professional and timely manner.
Qualifications:

  • Minimum of eight (8) years' experience
  • Proficiency in implementation and management of cybersecurity related projects for the Federal government.
  • Must have experience with security principles in relation to information technology risk management, vulnerability management, privacy assessments, and contingency planning.
  • Expertise in applying standards and guidance from National Institute of Standard Special Publications (NIST SP), Federal Information Processing Standards (FIPS), Federal Information Security Management Act (FISMA), Clinger-Cohen, Patriot Act, Office of Management and Budget (OMB) A-130, the DOT Departmental Information Resources Management Manual (DIRMM), and related computer security guidance through ongoing examination and analysis of cybersecurity projects.
  • Expertise in creating, reviewing, and analyzing system ATO documentation.
  • Knowledge in formation and implementation of DOT cybersecurity policies to ensure confidentiality, integrity, and availability of DOT information systems.
  • Proficiency with enterprise cybersecurity tools, such as: BigFix, Elastic Search, Splunk, ForeScout CounterACT, SailPoint, CyberARK, and Tenable Security Center.
  • Expertise in detecting, mitigating, and troubleshooting security threats to network infrastructure, verifying vulnerability mitigation, and managing security assessments.
  • Expertise in assessing current and emerging technologies, platforms, and applications to help ensure greater security and efficiencies.
  • Must be familiar with CDM capabilities (Network asset management, Identity and Access Management, Network Security Management, Data Protection Management), the tools that support them and how they are deployed within an enterprise.
  • Must have at least one Cybersecurity-related certification, for example: Certified Information System Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), GIAC Cloud Security Automation (GCSA), Certified Authorization Professional (CAP), GSDC Certified DevSecOps Engineer Certification or Global Information Assurance Certification (GIAC) Systems and Network Auditor (GSNA).
  • Proficiency in applying standards and guidance from National Institute of Standard Special Publications (NIST SP), Federal Information Processing Standards (FIPS), Privacy Act, Federal Information Security Management Act (FISMA), Clinger-Cohen, Patriot Act, Office of Management and Budget (OMB) A-130 and related privacy guidance through ongoing examination and analysis of Privacy Threshold Analysis (PTAs), Privacy Impact Assessments (PIAs), and Systems of Records Notices (SORNs).

Criterion Systems, LLC. and its subsidiaries are committed to equal employment opportunity and non-discrimination at all levels of our organization. We believe in treating all applicants and employees fairly and make employment decisions without regard to any individual’s protected status: race, ethnicity, color, national origin, ancestry, religion, creed, sex/gender, gender identity/gender expression, sexual orientation, physical and mental disability, marital/parental status, pregnancy (including childbirth, lactation, and related medical conditions), age, genetic information (including characteristics and testing), military and veteran status, or any other characteristic protected by law.
For our complete EEO/AA and Pay Transparency statement, please visit https://careers-criterion-sys.icims.com/ .

gatheringourvoice.org is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, gatheringourvoice.org provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, gatheringourvoice.org is the ideal place to find your next job.

Intrested in this job?

Related Jobs

All Related Listed jobs