JOBSEARCHER

DevSec Ops Analyst

The SA will assist with the creation, update, and maintenance of FedRAMP required security documentation, associated artifacts, and Continuous Compliance Monitoring (CCM) requirements such as the Plan of Action and Milestones (POAM) and assisting the Cloud Operations team with the identification and corrective actions associated with known vulnerabilities. Additionally, the SA provides advisement to stakeholders on changing regulatory, government and Cloud / FedRAMP policies, procedures, agreements, etc., including risk assessment, business impact analysis, system categorization, security authorization and accreditation/certification activities (A&A), security control inheritance from various providers, and other artifacts needed to validate control compliance.Required Skills The candidate must be able to:· Understand/document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system.· Advise stakeholders on multiple courses of action in an environment with changing unconfirmed policy, e.g., NIST RMF and DISA SRG.· Document multiple courses of action and identify risk mitigation recommendations in accordance with FedRAMP requirements, procedures, and best practices, with associated benefits/drawbacks to each.· Apply enterprise security frameworks and capabilities, such as FISMA, NIST SP 800, etc. towards existing initiatives such as cloud environments.· Develop/update policies and procedures to implement FedRAMP compliance as well as compliant with NIST 800-171 security requirements and other DFAR clauses.· Knowledge of Risk Based Vulnerability Framework and how to prioritize, assess, and remediate vulnerabilities that is and can be exploited· Ability to create automation scripts to minimize manual workload behind identifying and analyzing vulnerabilities across various scanning tools· Ability to analyze Container Vulnerabilities in secure cloud environments and identify the remediation path forward to address vulnerabilities from an Operating System and application level.· Understand enterprise operating environments, including security posture, application environment, and associated security controls.· Demonstrate familiarity with current FedRAMP, DOD and NIST Security controls and technologies, including vulnerability management capabilities.· Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation model, PPS compliance, and patching/CSVA mechanisms.Required Technical Experience· Experience in creating automation scripts through coding programs such as Python, Bash Java, and Powershell· Knowledge of Scanning Containers and experience with container scanning tools· Knowledge of the CI/CD pipelines, AWS ECR, Container Image Mirroring· Knowledge of determining attack vectors in the environment to determine if the vulnerability is exploitable· Knowledge in SAP products Required RMF Experience· Demonstrated knowledge and the ability to analyze systems for Cybersecurity compliance.· Ability to work in fast-paced, team-oriented environment.· Knowledge of Federal and DoD policies and risk assessment methodologies, including FedRAMP. NIST SPs and RMF overlays· Knowledge and hands on experience of DISA STIGs requirements and SRGs, Committee for National Security Systems Instructions and NIST Risk Management Framework.· Experience in writing or executing system security documentation, authorization to operate packages, POA&Ms, and policies.· Presentation and public speaking skills required.· Knowledge and understanding of systems and networking technologies and concepts.· Ability to interpret and assess network diagrams and drawings using Visio.· Familiarity with Testing, Development, Staging, and pre-production environment requiring cyber security support.· Knowledge of Privacy Act.(55-60/hr W2)