Job Closed

This listing is no longer active.

Arlo Solutions logo
Arlo Solutions

Where Technology and Simplicity Connect

Security Control Assessor

Security AnalystSecurity AnalystOtherRemoteMid LevelTeam 51-200H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

93 days ago

Salary

0

Seniority

Mid Level

No structured requirement data.

Job Description

Security Control Assessor

Arlo Solutions

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Department of War’s (DoW) Office of the Undersecretary of War for Research and Engineering (OUSW (R&E)) is at the forefront of supporting the DoW with the adoption of innovative technologies such as data, analytics, and artificial intelligence to help accelerate predictions, forecasts, and interpretations for both strategic and tactical decisions across the enterprise. These ground-breaking endeavors bring new challenges to the assessment of DoW IT systems that previously did not exist. The Security Control Assessor (SCA) plays a pivotal role in comprehensively understanding the cybersecurity posture of a given capability within OUSW (R&E). SCAs must go beyond a mere compliance focus on controls to articulate the inherent risks of systems. Success in this position requires expertise in statutory guidance such as: - NIST 800 series - DoWI 8500.01 - DoW 8140.03 - ISO 27001 - COBIT - DoW RMF - Operation Vulcan Logic (OVL) The SCA provides authoritative risk determinations and recommendations critical for the Authorizing Official (AO) to grant an Authority to Operate (ATO). Their assessments integrate technical rigor with regulatory compliance, ensuring a robust security posture and informing strategic decision-making. Job Responsibilities - Provide the AO with an independent risk assessment of assigned systems and authorization. - Advise Program Managers on AO determination utilizing OVL documentation. - Provide senior advisory support to OUSW (R&E) AO regarding authorizations of OUSW (R&E) capabilities. - Utilize expert knowledge and experience regarding risk management strategies in support of a major DoW program. - Providing support regarding the agile authorization and OVL processes. - Provide independent risk analysis and recommendation. - Collaborate between the AO and the program as well as Program leadership. - Identify the security baseline based on the mission and security impacts to the system. - Determine assessment criteria, develop, review, and create a plan to assess the security requirements. - Assess the security requirements in accordance with the assessment procedures defined in the Security Assessment Plan (SAP). - Prepare the Security Assessment Report (SAR). - Monitor POAM actions based on findings and reassess remediated risk(s) as appropriate. - Develop the Risk Recommendation and AO Determination Brief. - Develop a system-level continuous monitoring strategy. - Author and present briefs regarding status of authorizations to AO and other senior Government officials. - Provides security architecture and DoW compliance advisory support. Qualifications - Must have an active Top-Secret Clearance SCI eligible. - Bachelor’s degree in computer science/information technology, or other related degree fields (master’s degree is preferred or at least 5 years of related experience). - At least 5+ years of cybersecurity experience including a senior technical or management role, Project or Program Management experience a plus. - At least one IAT/IAM or equivalent security certifications e.g. Sec+, CISSP, CCSP, CISM, CISA, or CASP. - Experience working with OSD leadership or Military component or branch. - Understanding of NIST 800 series guidelines, DoWI 8500.01, DoW 8140.03, ISO 27001, COBIT, DoW RMF, OVL, and current cybersecurity best practices. - Excellent communication/presentation skills briefing senior military and government civilian leadership. - Experienced with writing standard operating procedures. - Experience in hands-on with eMASS, Xacta and/or other GRC tools. - Experience with Federal and FedRamp A&A Processes. Success Factors - Have a strong background in risk management, and governance, risk and compliance (GRC). - Strong client focus and commitment to continuous improvement, ability to proactively network and establish relationships. - Manage multiple priorities in a high-paced and fast-changing environment. - Perform other duties as assigned or required. AAP Statement We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.

Job Requirements

  • Must have an active Top-Secret Clearance SCI eligible.
  • Bachelor’s degree in computer science/information technology, or other related degree fields (master’s degree is preferred or at least 5 years of related experience).
  • At least 5+ years of cybersecurity experience including a senior technical or management role, Project or Program Management experience a plus.
  • At least one IAT/IAM or equivalent security certifications e.g. Sec+, CISSP, CCSP, CISM, CISA, or CASP.
  • Experience working with OSD leadership or Military component or branch.
  • Understanding of NIST 800 series guidelines, DoWI 8500.01, DoW 8140.03, ISO 27001, COBIT, DoW RMF, OVL, and current cybersecurity best practices.
  • Excellent communication/presentation skills briefing senior military and government civilian leadership.
  • Experienced with writing standard operating procedures.
  • Experience in hands-on with eMASS, Xacta and/or other GRC tools.
  • Experience with Federal and FedRamp A&A Processes.
  • Success Factors
  • Have a strong background in risk management, and governance, risk and compliance (GRC).
  • Strong client focus and commitment to continuous improvement, ability to proactively network and establish relationships.
  • Manage multiple priorities in a high-paced and fast-changing environment.
  • Perform other duties as assigned or required.
  • AAP Statement
  • We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.

Related Job Pages

More Security Analyst Jobs

OtherRemoteTeam 1,001-5,000Since 1996H1B No Sponsor

The HIPAA Subject Matter Expert supports the Health and Human Services (HHS), Office for Civil Rights (OCR) promoting the right to access health information and protection of the privacy and security of this information. These highly trained and highly skilled consultants and analysts are integral to the success and performance of OCR and to further OCR’s mission. Chickasaw Nation Industries, Inc. serves as a holding company with multiple subsidiaries engaged in several lines of business (Technology, Infrastructure & Engineering, Health, Manufacturing, Public Safety, Consulting, and Transportation) for the federal government and commercial enterprises. A portion of our profits is used to support Chickasaw citizens. We are proud to support the economic development and long-term viability of the Chickasaw Nation and its people. CNI offers premium benefits eligible on the first day of hire to full time employees; (Medical - Dental – Vision), Company Life Insurance, Short-Term and Long-Term Disability Insurance, 401(K) Immediate Vesting, Professional Development Assistance, Legal Aid Assistance Program, Family Planning / Fertility Assistance, Personal Time Off, and Observance of Federal Holidays. As a federal contractor, CNI is a drug-free workplace and adheres to the Federal Controlled Substance Act. ESSENTIAL REQUIREMENTS - Preference will be given to candidates with relevant industry certifications from CISSP, CISM, CIPP/CIPT/CIPT. - Ten (10) years of relevant cybersecurity experience is preferred. - Experience in auditing and generating audit reports is required. - Fundamental knowledge of basic systems analysis. - Knowledge of a broad range of relevant computer systems, applications, and/or related equipment. - Knowledge of computer security procedures and protocol. - Basic knowledge of advanced operating system, network, or application management tasks. - Knowledge of current technological developments/trends in area of expertise. - Knowledge of federal copyright laws as they pertain to the use of computer software. - Ability to integrate emerging technologies and applications into current environment and to identify technical specifications to meet user needs including operating system and network or application configuration. - Ability to identify technical specifications to meet user needs including operating system and network or application configuration. - Skills in planning, organizing, and adapting within a multi-tasking environment. - Strong interpersonal skills, flexibility, and customer service orientation. - Ability to gather facts and data for technical proposals and to expand upon them or develop alternatives and to evaluate emerging technologies and identify their potential impact within the existing environment. - Ability to evaluate emerging technologies and identify their potential impact within the existing environment. - Ability to analyze complex computer problems and provide solutions. - Ability to communicate effectively, both orally and in writing. - Ability to communicate technical information to non-technical personnel. - Ability to develop and deliver presentations. KEY DUTIES AND RESPONSIBILITIES Essential duties and responsibilities include the following. Other duties may be assigned. - Reviews security and privacy complaints, data breach notification and cybersecurity incident reports and other correspondence and evidence to determine whether complaints, self-reported breaches or breach notification reports indicate non-compliance with the HIPAA Security Rule. Reviews data provided by the healthcare organizations across the nation to assess the overall impact of security and privacy incidents. - Evaluates and determines the technical sufficiency of submissions from HIPAA covered entities and business associates in response to data and documentation requests (i.e. Assessing reports related to security baselines, penetration tests, vulnerability assessments, and digital forensics). - Documents processes, standard operating procedures and system requirements; develops reports summarizing the analysis along with formulating recommendations for OCR to consider for future action. - Develops written reports with technical security analyses, summaries, and recommendations for action, reports on root causes of problems, efficiency, and support needs. - Provides expertise in the development and evaluation of health information privacy policies and technologies, specifically regarding protected health information; deidentified/re-identified health information; limited data sets. - Provides subject matter expert analysis, evaluation, and recommendations based on national security standards (NIST), industry best practices from the International Organization for Standardization and implementation specifications of the HIPAA - Security Rule. - Provides DIN designing, implementing, and managing information security, data protection, and risk management programs, including policies, procedures, and controls for protected health information based on HIPAA requirements. - Provides advisory expertise in the areas of risk analyses, vulnerability assessments, incident response, security architecture, physical security, business continuity and disaster recovery, enterprise mobility, threat intelligence and analysis, security awareness and - online safety, and resolution of highly complex security projects and issues. - Works well with programmers, developers, content managers, and other key personnel in an interactive development situation. EDUCATION/EXPERIENCE Minimum educational experience is a Bachelor’s degree from an accredited university with the focus on Cybersecurity, Computer Science, Information Sciences, or other comparable fields of Study. PHYSICAL DEMANDS Work is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects and operate tools, computer, and/or controls. Required to speak and hear. Occasionally required to stand, walk and stoop, kneel, crouch, or crawl. Must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus. Exposed to general office noise with computers printers and light traffic. The physical demands described here are representative of those that must be met by an employee to perform successfully the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this job. EOE including disability/vet. The estimated pay range for this role is $125K to $135K, with the final offer contingent on location, skillset, and experience. CNI offers a comprehensive benefits package that includes: - Medical - Dental - Vision - 401(k) - Family Planning/Fertility Assistance - STD/LTD/Basic Life/AD&D - Legal-Aid Program - Employee Assistance Program (EAP) - Paid Time Off (PTO) – (11) Federal Holidays - Training and Development Opportunities Your application submission will be considered for all potential employment opportunities with Chickasaw Nation Industries (CNI).

United States
$125K - $135K / year
Job Closed

Cybersecurity Administrative Intern

Mosaic Life Care

Founded in 1982 and headquartered in St. Joseph, Missouri, Mosaic Life Care is a physician-led health system dedicated to its mission of improving the health of individuals and com

Security Analyst93 days ago

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This position will focus on learning how the organization operates and is expected to gain valuable insight that can further the chosen career field. This position reports to the Manager or Director of the department and is employed by Mosaic Health Systems. - Support cybersecurity risk assessments - Support cybersecurity metrics and reporting - Support the cybersecurity awareness and training program - Support access reviews - Support cybersecurity projects as needed - Other duties as assigned Qualifications - High School diploma required. Junior or Senior college level student preferred. - Computer knowledge required. Familiar with a variety of software programs, including Word, Excel, Access, PowerPoint is required. Requirements - Remote - Cybersecurity Administrative Intern - Part Time Status - Day Shift - Pay: Starting at $15.38 / hour - Candidates residing in the following states will be considered for remote employment: Alabama, Colorado, Florida, Georgia, Idaho, Indiana, Iowa, Kansas, Kentucky, Minnesota, Missouri, Mississippi, Nebraska, North Carolina, Oklahoma, Texas, Utah, and Virginia. - Remote work will not be permitted from any other state at this time. Company Description

United States
$15 / hour
Job Closed
OtherRemoteTeam 10,001

Our vision is to establish HUGO BOSS as the leading premium tech-driven fashion platform worldwide and to be one of the top 100 global brands. At HUGO BOSS, we work as a team to apply our knowledge, skills and experience together and create a diversity of ideas and solutions. What unites us? We love fashion, we change fashion! At HUGO BOSS, you have the opportunity to contribute your personality, ideas and creativity — because only when we break new ground together can we create something unique. Become part of our team of more than 19.000 employees worldwide and shape your future at HUGO BOSS! In this role, the Loss Prevention Associate will assist the Loss Prevention & Inventory Control Manager in managing all aspects of inventory control for US. Please note - This role will be remote based. What you can expect: Responsibilities include, but not limited to the following: - Lead loss prevention investigations (ie: fraud, internal, external) and partner with cross functional business teams to resolve open concerns• Weekly monitoring of all sites to include alarm codes, key controls, physical security, etc. - Compile and analyze shrink results to uncover trends and create action plans to combat shortage - Partner with various internal and external business partners during investigations of inventory control to prevent further losses as well as recovery of losses. - Support all retail locations daily in inquiries about loss/damage of merchandise process, law enforcement inquiries - Locate outliers/issues and communicate that to management. - Knowledge of RFID (Radio-Frequency Identification) process in retail environment. - Compile concise actionable reports for executive management team. - Ability to travel, including some overnight travel to conduct loss prevention audits in retail locations. - Some early mornings, late nights, and some weekends - Any other ad hoc tasks or special projects related to loss prevention and inventory control. - Maintain professional liaison with law enforcement to ensure appropriate coordination of investigations and/or prosecutions to solve theft or fraud cases. - Assist with development of best practices and policies for USA and Canada, in the form of addendums to the SOM, that relate to Loss Prevention Your profile: - Bachelor’s Degree or equivalent - 3-5 years work experience in field - SAP experience is desirable - Experience implementing and curating exception based reporting - Familiarity with Business Intelligence solutions is desirable - Superior MS Excel is a must - Strong planning, critical thinking, problem-solving, and organizational skills - Maintain strict confidentiality and high level integrity - Excellent verbal and written skills - Ability to communicate effectively with Business teams - Ability to handle multiple tasks and remain fluid as the landscape is everchanging - Proven track record of managing projects independently, self-motivated - Strong planning, critical thinking, problem solving and organizational skills Your benefits: HUGO BOSS offers a comprehensive benefits package which includes: - Paid Parental Leave for FT employees - 21 paid days off (pro-rated based on first year of employment) plus your Birthday off - Generous Employee Discount Program - Paid Parental Leave for FT employees - Medical, Dental, Vision Benefits with Health Saving Account (HSA) option - SHIP (Share Investment Program) - Offers eligible employees the opportunity to become a co-owner and acquire shares in HUGO BOSS AG at special SHIP conditions. - 401(K) with company match - Flex Spending Account (FSA) - Commuter Benefits (Pre-tax) - Voluntary Benefits and Critical Illness - Company sponsored Life and Disability benefits - Employee Assistance Program (EAP) - Discounts for auto/home/pet insurance The expected base salary range for this position is from $67,000 - $72,000. It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered #LI-RM1 We are a global company with our employees representative of the world at large. Our inclusive culture embraces each person’s authenticity and individuality. We are committed to equal employment opportunity. And we believe our equitable work environment helps unleash your full potential and inspires you to thrive.

United States
$67K - $72K / year
OtherRemoteTeam 10,001+Since 1978H1B No Sponsor

With a career at The Home Depot, you can be yourself and also be part of something bigger. Position Purpose: This role is the key operational driver of risk reduction for the SaaS Security program. The CyberSecurity Analyst will be responsible for analyzing the findings from our SaaS Security tools, collaborating directly with SaaS application owners to drive the remediation of identified risks, and reporting on the overall security posture of our SaaS environment. This position acts as the crucial link between security data and tangible security improvements. Key Responsibilities: - 30% Analysis - Perform data gathering, synthesis, and develop solutions; Leverage department standards to achieve results - 30% Collaborate - Partner with teams to identify trends and resolve problems - 40% Drive Execution - Evaluate information and provide recommendations based on findings Direct Manager/Direct Reports: - This Position typically reports to Manager or Sr. Manager - This Position has 0 Direct Reports Travel Requirements: - Typically requires overnight travel less than 10% of the time. Physical Requirements: - Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions there may be a need to move or lift light articles. Working Conditions: - Located in a comfortable indoor area. Any unpleasant conditions would be infrequent and not objectionable. Minimum Qualifications: - Must be eighteen years of age or older. - Must be legally permitted to work in the United States. - 2+ years of experience in an Information Security, IT audit, or risk management role. - Excellent analytical, problem-solving, and communication skills. - Ability to translate complex technical risks into clear, business-oriented language. - Strong organizational skills and the ability to manage multiple stakeholder engagements simultaneously. Preferred Qualifications: - Bachelor's degree in a relevant field. - Experience working directly with business stakeholders to remediate security findings. - Familiarity with security frameworks (NIST, ISO 27001) and IT general controls. - Experience with ticketing systems (e.g., Jira, ServiceNow) for tracking remediation. - Security certifications such as CompTIA Security+, CISM, or CRISC. Minimum Education: - The knowledge, skills and abilities typically acquired through the completion of a bachelor's degree program or equivalent degree in a field of study related to the job. Preferred Education: - No additional education Minimum Years of Work Experience: - 0 Preferred Years of Work Experience: - No additional years of experience Minimum Leadership Experience: - None Preferred Leadership Experience: - None Certifications: - None Competencies: - Action Oriented - Collaborates - Communicates Effectively - Customer Focus - Drives Results For California, Colorado, Connecticut, Rhode Island, Nevada, New York City, Ithaca (NY), Westchester County (NY), and Washington residents: The pay range for this position is between $80,000 - $130,000

United States
$80K - $130K / year
Job Closed