Job ID: VA-632667 (98090713)
Security Analyst with governance/compliance, risk management, ITRM, NIST, eGRCS Archer and analytical tools experience
Location: Richmond VA (VITA)
Duration: 6+ months
Skill Required / Desired Amount of Experience Expertise Rating
Considerable experience and knowledge in IT security governance/compliance, risk management Required 10 Years
Specifically commonwealth ITRM security standards, policies (ITRM SEC501, SEC525, NIST800-53), procedures and controls. Required 8 Years
Working experience using analytical tools, developing spreadsheets, documentation, and security reports Required 10 Years
Individual shall work directly with CISS Director and Team to support ongoing Risk Assessment, Business Impact Analysis, governance, and reporting metrics as they relate to the information security program. Must be able to work independently on multiple tasks performing complex analysis of risk/governance data. Individual will be generating final work products using information from agency personnel, eGRCS (Archer), security architects and must perform this within the CSRM environment. Development of risk assessments / system security plans and analysis of governance data will be a primary function.
Performing and documenting business impact analysis, risk assessments, risk treatment plans working with client team.
Development of security documentation such as System Security Plans from artifacts and assessments provided by third parties.