Compliance Officer - MID

Zermount, Inc
Arlington, VA, US
Full-time
We are sorry. The job offer you are looking for is no longer available.

Job Description

Job Description

COMPLIANCE OFFICER MID

MILITARY FRIENDLY & PREFERRED - HOH SPONSOR

Zermount Inc. is seeking a Compliance Officer MID who will perform complex risk analyses and ensure systems and technologies satisfy Information Assurance (IA) and Cybersecurity requirements, based on federal requirements, laws, mandates, policies, procedures, standards, and guidelines (e.

g., EOs, OMB, BODs, NIST, and agency specific requirements). The Compliance Officer will provide Plan of Actions and Milestones (POA&M) management, conduct FISMA Compliance meetings, and work with Information Systems Security Officers (ISSO), System Owners (SO), stakeholders, and leadership to meet performance and scorecard metrics.

The Compliance Officer will conduct regular (e.g., daily, weekly, monthly) system security compliance meetings for assigned systems of responsibility, provide feedback and recommended mitigations to ensure systems meet the minimum requirements and security posture.

Support customer at the highest levels to ensure the implementation of doctrine and policies.

Duties & Responsibilities :

The Compliance Officer MID will provide the following support and services :

  • Perform Compliance reviews and analyses to verify compliance with federal requirements (e.g., EO, OMB Memos, A-130, NIST SP 800-37, 800-53, FIPS199, and FIPS-200, etc.).
  • Perform analyses of security implementations for assigned systems pertaining to people, processes, and technologies, identify gaps and recommend solutions.
  • Conduct daily, weekly, monthly compliance monitoring of assigned systems for all RMF steps.
  • Conduct compliance assessments of assigned systems, based on the Zermount approved Compliance Support Services Framework.
  • Execute day to day FISMA compliance monitoring, ensuring that all FISMA activities, including Information Security Continuous Monitoring (ISCM), Continuous Diagnostic and Mitigation (CDM), and FISMA program activities assigned are prioritized correctly, completed on schedule, and are in accordance with Agency and organizations policies.
  • Research major obstacles related to the ever-changing FISMA requirements, which customers will need to overcome and provide recommendations.
  • Track system ATO status, security documentation expirations (Contingency Plan, Contingency Plan Test, Configuration Management Plans, Incident Response Plans, etc.

Information Security Vulnerability Management (ISVM) compliance, DHS Performance Plan requirements, audit efforts, and CDM support efforts.

  • Conduct analysis of system level POA&Ms and provide guidance and recommendations on potential mitigation to close current or delayed POA&Ms.
  • Track and report on whether assigned systems have mitigated their weaknesses on time using the appropriate processes and reporting timelines.
  • Track and report on whether mandated FISMA activities are being executed in accordance with the current DHS Information Security Performance Plan (ISPP) for the fiscal year.
  • Provide compliance monitoring metrics and reporting to Agency leadership.
  • Review the DHS Scorecard, for each assigned system, conduct analysis, and generate "Get to Green" reports.
  • Conduct Get-to-green meetings with SOs and ISSOs, provide status, deficiencies, recommendations, and document action items with estimated completion dates (ECDs) with the goal of improving system scores within the DHS Scorecard.
  • Manage ISVM alerts and bulletins for TSA systems to include tracking, distributing, and providing reports.
  • Support systems of responsibility to ensure all ISCM and CDM requirements are met and mitigations for failing requirements are identified and discussed to ensure a plan is established to meet all requirements defined.

Provide monthly reports with action items for stakeholders and leadership.

  • Create briefings and reports, as required for, but not limited to the following items : high valued assets, ISVMs, POA&Ms, system scores (FISMA & ISCM).
  • Provide input into the GRC presentations for monthly ISSO Townhall training, as required by management or the Communications & Training Team Lead.
  • Provide updates and input to the GRC SharePoint sites to include document uploads, page updates, access requests, permissions, etc. on an ongoing basis.
  • Create or update existing templates for memos, risk assessments, disposal packages, to standardize and simplify the process.
  • Conduct system compliance assessment to identify progress on ATO conditions, develop extension packages as required annotating analysis of system data / progress.
  • Conduct POA&M management activities, to include processing, reviewing, verifying, and validating creation and closures.
  • Report on expiring and overdue POA&Ms and ensure compliance with all DHS POA&M metrics and requirements as outlined in agency policy and the DHS ISPP.
  • Review waiver and risk acceptance requests for compliance with the Agency's Policies and Procedures.
  • Provide Quality Reviews of security documentation to ensure accuracy and compliance throughout the RMF process.
  • Support systems of responsibility to ensure all Ongoing Authorization (OA), requirements are met and any deficiencies are identified and tracked.

Monitor activities and ensure all deficiencies exceeding 30 days are identified as requiring a POA&M.

  • Assist with conducting review and analysis of Requests for Change (RFC) and providing recommendations to conduct risk assessment (as applicable) based on the change and / or Security Impact Assessment (SIA).
  • Support Security Control Assessors (SCAs) as required for assigned systems.
  • Provide input and assist with all audits, data calls, and queries relating to assigned systems.
  • Stay current with the latest developments in cybersecurity, information assurance, GRC, and related cybersecurity trends.
  • Create or update existing templates such as memos, risk assessments, disposal packages, to standardize and simplify GRC processes.
  • Assist in completing customer's Management Control Objectives Program (MCOP) reporting requirements.
  • Provide Weekly status reporting to leadership
  • Assist and support other team members as required by the Program Manager.

Qualifications :

  • Experience and expert knowledge on NIST guidelines, FISMA, Cybersecurity principles and methodologies, Executive Orders (EO's), Office of Management and Budget (OMB) Memorandums, Federal, DoD and CISA Technical Reference Architectures, Maturity Models, Risk Management Framework (RMF), Cybersecurity Framework (CSF), technical knowledge of IT systems, and cloud security (is preferred).
  • Knowledge of and experience using relevant cybersecurity and analysis tools such as Archer, Nessus Security Center, Splunk, etc.
  • Experience with cloud-based environments and technologies is preferred.
  • Knowledge of cybersecurity threats, risks, and vulnerabilities and how to mitigate them.
  • Excellent communication skills (written and verbal), with the ability to explain complex concepts in a clear, concise manner.
  • Strong problem-solving skills, proactive, ability to adapt to changes in priorities, attention to detail and organization skills, and possesses good problem solving and decision- making skills.
  • Must be able to conduct system analysis and quality reviews to detect performance issues.
  • Well versed in developing compliance solutions to resolve weaknesses or challenges.
  • Ability to work independently and as part of a team.
  • An analytical mind with excellent problem-solving ability is required.
  • Apply an enterprise-wide set of disciplines for the planning, analysis, design and construction of information systems on an enterprise-wide basis or across a major sector of the enterprise.
  • Develop analytical and computational techniques and methodology for problem solutions.
  • Perform enterprise wide strategic systems planning, business information planning, business and analysis.
  • Perform process and data modeling in support of the planning and analysis efforts using both manual and automated tools;

such as Integrated Computer-Aided Software Engineering tools.

  • Apply reverse engineering and re-engineering disciplines to develop migration strategic and planning documents.
  • Provide technical guidance in software engineering techniques and automated support tools.
  • Provide daily supervision and direction to staff.

Education :

  • Minimum of a Bachelor of Science (or higher) in one of the following : computer engineering, computer science, IT, cyber security, or a related field and 5 years of IT cybersecurity experience including direct support for the US Government and 4 years acting as an ISSO, Assessor, or Compliance Analyst
  • Without a B.S. degree, a minimum of 7 years of IT cybersecurity experience including direct support for the US Government will be accepted

Certifications :

A minimum of at least one of the following certifications is required : Certified Authorization Professional (CAP), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Chief Information Security Officer (CCISO) OR equivalent according to the DOD 8570 approved certification list.

Clearance level :

Minimum of an active Secret Clearance.

Work Location :

Primarily Remote (Onsite work in Arlington, VA or in the United States may be occasionally required).

Hours of Operation :

  • Business Hours : 8 : 00 am EST - 4 : 30 pm EST.
  • 30+ days ago
Related jobs
Promoted
Peraton
McLean, Virginia

Human resources information system proficiency. Peraton offers enhanced benefits to employees working on this critical National Security program, which include heavily subsidized employee benefits coverage for you and your dependents, 25 days of PTO accrued annually up to a generous PTO cap and elig...

Promoted
ManTech
McLean, Virginia

Enterprise IT Support Officer (EITSO) – Location Support Team. Security Clearance Requirements:. ...

Promoted
ASRC Federal
McLean, Virginia

ASRC Federal Business Innovation, a subsidiary of ASRC Federal, is seeking a .ACC IBS Exec Support Program on site at Langley AFB.Analyze science, engineering, business, and other data processing problems to develop and implement solutions to complex applications problems, system administration issu...

Promoted
National Geospatial-Intelligence Agency (NGA)
Springfield, Virginia

We analyze imagery and data from many sources and incorporate it into visual displays of essential information for use in national defense, homeland security, and safety of navigation. Central to the success of our mission are the extraordinary talents and skills of our teams of analysts and other p...

Promoted
SAIC
McLean, Virginia

SAIC is looking for a candidate to provide Financial Reporting and Analysis, Strategic Financial Planning, Business Process Improvement, Benchmarking and Program Metrics support in a fast-paced and dynamic customer environment with broad impact to the customer’s mission.This position supports the cu...

Promoted
Nightwing
Arlington, Virginia

As a prospective employee of Nightwing, you’ll have the chance to contribute to our continued success and shape the future of our cybersecurity, intelligence, and services offerings. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous tec...

Promoted
Accenture Federal Services
Fort Belvoir, Virginia

Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations. ...

Promoted
Amentum
Vienna, Virginia

Conduct Cyber target development, such as identification of cyber-enabled crime networks that include actors and techniques that may represent a cyber threat to systemically important financial institutions and associated infrastructure. Amentum is seeking a Cyber Forensic Analyst to support the Int...

Promoted
MITRE
McLean, Virginia

MITRE's Information Services department seeks an experienced researcher, information professional, or librarian to support our team as a Senior Information Research Analyst. As an information services professional, this key team member will need an in-depth understanding of conducting research using...

Promoted
Office of The Chief Financial Officer
Alexandria, Virginia

The Office of the Chief Financial Officer (OCFO) whose mission is to enhance the fiscal and financial stability, accountability and integrity of the Government of the District of Columbia is in search of a Audit and Compliance Officer. The incumbent is responsible for administering the OLG's regulat...