ASM Research

Cyber Risk Management Lead

ASM Research  •  Ashburn, VA (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Leads the identification, communication, and distribution of cybersecurity risks and actionable mitigations/remediations at the tactical and strategic levels across the Agency IT environment, working closely with the VAT, SOC, CTI, SCAs, ISSMs, ISSOs, and system owners.

  • reviews change requests, prioritizes vulnerability remediation, and identifies common security-gap patterns using frameworks such as MITRE ATT&CK.
  • develops Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos (CRRMs) and supports Component Cyber Acquisition Risk Management (C-CARM) through the Acquisition Lifecycle Framework.
  • Identify tactical risks by working with operational teams (VAT, SOC, CTI) to build a full picture of tactical cyber risk; review and recommend approval/denial of tactical change requests.
  • Support prioritization of vulnerability remediation and identification of common security-gap patterns using frameworks such as MITRE ATT&CK.
  • Identify strategic risks by working with SCAs, ISSMs, ISSOs, and system owners; support Component Cyber Acquisition Risk Management (C-CARM) through templates/guidance tied to Acquisition Decision Events.
  • Develop and review Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos (CRRMs).
  • Conduct Risk Assessments gathering data on incidents, vulnerabilities, POA&Ms, KEVs, loss-magnitude metrics, threat actors, and TTPs.
  • Support development of an organizational risk tolerance level and information system risk profiles aligned to the NIST Cybersecurity Framework.
  • Maintain a near-real-time holistic risk management dashboard and CSD risk register for senior management visibility.
  • Provide briefings to senior management on the Agency's cyber risk posture; support Cybersecurity Supply Chain Risk Management (C-SCRM) documentation.

Minimum Qualifications

  • Bachelor’s Degree in Information Assurance, Computer Science, or related field.
  • Minimum 7 years of professional experience in information assurance, cybersecurity, risk management, or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, 5 years of such experience
  • One of the following: CompTIA Security+; ISC2 CISSP; ISACA CISM; ISACA CRISC; GIAC GCED; CompTIA CEH
  • Candidates must be US citizens (no dual citizens) with the ability to pass a federal background investigation in order to gain access to sensitive information.

Other Job Specific Skills

  • Demonstrated knowledge/experience with: Risk Assessments; NIST SP 800-37 RMF; NIST Cybersecurity Framework; NIST SP 800-53 security controls; managing POA&Ms; reviewing vulnerability scan results; using the Enterprise Logging System for audit-log review; reviewing OS/application/database security baseline configuration; performing security impact analysis on change requests; writing security policy; and understanding of M-22-09 / Zero Trust Architecture pillars

Qualifications

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

Compensation Range

$170k - $189,500

ASM Research

About ASM Research

ASM Research, an Accenture Federal Services Company, is an information solutions integrator and a leading provider of innovative technology solutions and advanced analytical services for the Federal government. Headquartered in Fairfax, Virginia, ASM has over 30 years of experience providing application, software, system, network, database, and reporting solutions. Our extraordinary commitment and unique insight into clients’ information technology (IT), program management, security, healthcare / medical management, education and training management consistently produce extraordinary results.

We are always seeking quality individuals to join our team. We offer an employee-friendly work environment, outstanding benefits, and a level of stability rarely found in the government contracting world. We have ongoing needs for Web Applications Developers (ASP.Net), SharePoint Developers, Cyber Security Analysts, QA Analysts, Helpdesk Analysts and Oracle DBAs. You can see a full list of our current openings at http://asmr.com/Opportunities.aspx or send your resume to hr@asmr.com. You can also connect with our corporate recruiter, Chris Gibbons, http://www.linkedin.com/pub/chris-gibbons/0/635/213 or Erik Thompson, https://www.linkedin.com/in/erikthompsonitt.

Privacy Policy: https://www.asmr.com/privacy-policy/

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Fairfax, Virginia
Year Founded
1978
Website
asmr.com
Social Media