Sr. Security Risk Management SME/ Sr. Vulnerability Threat Asses with Security Clearance
1 week ago
Job Description ECS is seeking a Sr. Security Risk Management SME/ Sr. Vulnerability Threat Assessment Analyst to work in our Washington, DC office. Overview ECS is seeking a Security Risk Management Subject Matter Expert (SME) to provide strategic technical advisory services for the Department of State (DOS) Bureau of Diplomatic Technology (DT). This senior role supports the Independent Security Control Assessment (ISCA) program and the Risk and Vulnerability Assessment (RVA) portfolio. The ideal candidate will effectively serve as a senior analyst responsible for Ongoing Risk Determination , Threat Analysis, and the management of the Issue Resolution Process. You will act as a key advisor to Authorizing Officials (AOs), translating complex vulnerability data into actionable "Risk Acceptance Recommendation Reports" and driving risk-based decision-making for High Value Assets (HVAs). Key Responsibilities
- Strategic Risk Management & Issue Resolution:
- Lead the Issue Resolution Process to communicate identified risks to key stakeholders and document risk-based decisions, including risk acceptance and remediation strategies.
- Analyze the security status of information systems to determine if the risk to organizational operations and assets remains acceptable.
- Develop and present Risk Acceptance Recommendation Reports and Residual Risk Statements to the Authorizing Official (AO) to facilitate informed authorization decisions.
- Vulnerability & Threat Assessment:
- Analyze security tool reports and vulnerability scan data to differentiate false positives from valid findings, ensuring accurate risk characterization before assigning vulnerabilities.
- Conduct Security Impact Analyses of changes to the environment to ensure continued compliance and security stability.
- Review and analyze Assessment & Authorization (A&A) packages, including System Security Plans (SSP) and Plans of Action and Milestones (POA&Ms), for completeness and effectiveness of controls.
- RMF SME & Advisory:
- Provide expert guidance on NIST SP Rev. 5 control implementation and NIST SP Rev. 2 workflows.
- Oversee the development of Security Assessment Reports (SARs), ensuring findings are concise, system-specific, and mapped to the correct risk categorization.
- Support Continuous Monitoring strategies by defining monitoring frequencies and assessing a subset of controls annually.
- Reporting & Leadership:
- Prepare and deliver Executive Summary Briefings for senior government leadership.
- Mentor junior analysts and assessors on advanced assessment techniques and risk analysis methodologies. Salary Range: $115,000 - $140,000 Required Skills
- Clearance: Active Secret Security Clearance (Required).
- Experience: 8+ years of progressive Information Security experience, with a specific focus on Risk Management, Threat Assessment, or Security Control Assessment (SME level).
- Risk Analysis: Demonstrated expertise in calculating residual risk, developing risk acceptance justifications, and managing POA&Ms for complex federal systems.
- Frameworks: Mastery of NIST SP Rev. 5, NIST RMF (SP , and NIST SP Risk Assessment).
- Tooling: Advanced proficiency with eGRC tools (e.g., CSAM, Xacta, Archer) and vulnerability analysis tools (e.g., Tenable Nessus, Splunk).
- Communication: Elite written and verbal communication skills, with the ability to defend risk recommendations to Authorizing Officials and executive stakeholders. Desired Skills
- Certifications: Advanced certifications such as CISSP (Certified Information Systems Security Professional), CRISC (Certified in Risk and Information Systems Control), or CISM (Certified Information Security Manager).
- Domain Expertise: Prior experience supporting Department of State (DOS) and High Value Asset (HVA) programs.
- Cloud Security: Experience assessing and analyzing risks in AWS and Azure cloud environments. #ECS1 ECS is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. ECS is a leading mid-sized provider of technology services to the United States Federal Government. We are focused on people, values and purpose. Every day, our 3300+ employees focus on providing their technical talent to support the Federal Agencies and Departments of the US Government to serve, protect and defend the American People.
-
Washington, Washington, D.C., United States ECS Tech Inc Full time $115,000 - $140,000ECS is seeking a Sr. Security Risk Management SME/ Sr. Vulnerability Threat Assessment Analyst to work in our Washington, DC office. OverviewECS is seeking a Security Risk Management Subject Matter Expert (SME) to provide strategic technical advisory services for the Department of State (DOS) Bureau of Diplomatic Technology (DT). This senior role supports...
-
Sr. Security Engineer
6 days ago
Washington, Washington, D.C., United States Dynanet Corporation Full time:Position Details:Job Title: Sr. Security EngineerJob Type: Full-timeLocation: Remote, DCDynanet Corporation Overview:Dynanet started with a focus on IT infrastructure and operations, helping organizations enhance their networks and overcome the limitations of 1990s technology. From strengthening communication channels to introducing innovative ways to...
-
Sr. Cloud Security and Delivery SME
2 weeks ago
Washington, Washington, D.C., United States ALTA IT Services, LLC Full timeJob Title: Sr. Cloud Security and Delivery SMELocation: Washington, District Of ColumbiaType: ContractCompensation: $84.75 hourlyContractor Work Model: Hybrid (1 day a week in office) Security Clearance: Must be able to obtain Public Trust ClearanceALTA IT Services is searching for a Senior Security Architect and Solutions Delivery Subject Matter Expert...
-
Technical Program Manager, Security
2 weeks ago
Washington, Washington, D.C., United States Meta Full time $160,000 - $223,000The Security, Risk & Assurance (SR&A) team proactively identifies, assesses, and mitigates security, risk, and compliance challenges across Security, Integrity, Investigations (SI2) personnel, tools, operations, and vendors. Our mission is to ensure the integrity, privacy, and resilience of systems and processes, ultimately increasing user safety and legal...
-
Sr. Information Assurance/Security SME
2 days ago
Washington, Washington, D.C., United States Amyx Full timeOverviewAmyx is seeking a Sr. Information Assurance/Security SME for our DOD client in the greater National Capitol Region.Responsibilitiescomprehensive multi-disciplinary leadership and IA related support for DoD. Must have the ability to communicate accurate informationQualificationsIt is required that the SIAS SME has the following qualifications:A...
-
Washington, Washington, D.C., United States Watermark Risk Management International Full timeCome make your mark with Watermark FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business.SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to...
-
Sr. Cloud Security and Delivery SME
4 days ago
Washington, Washington, D.C., United States Apex Systems Full timeJob#: Job Description:Apex Systems is seeking a Sr. Cloud Security and Delivery SME who can work onsite in Washington, D.C. for 1 day per week.Summary:The SME will design and oversee the implementation of security solutions to protect cloud-hosted operating environments using Zero Trust and defense-in-depth strategies. The SME will conduct Cloud Application...
-
Threat Management Specialist
6 days ago
Washington, Washington, D.C., United States Watermark Risk Management International Full timeCome make your mark with Watermark FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business.SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to...
-
Sr. Cyber Capability Developer
6 days ago
Washington, Washington, D.C., United States Seneca Resources Company, LLC Full timePosition Title:Sr. Cyber Capability DeveloperLocation:Washington, DC (Mostly Remote – must reside in the DC Metro area and be available for on-site meetings as needed)Clearance Requirements:Active Top Secret (TS) clearance with SCI eligibilityPosition Status:Long-Term ContractWork Authorization:U.S. Citizenship RequiredPay Rate:$70 - $90/hr.Position...
-
Information Security Risk Specialist, Lead
2 weeks ago
Washington, Washington, D.C., United States Booz Allen Hamilton Full timeJob Number: R0231500Information Security Risk Specialist, LeadThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming. In all of this "cyber noise," how can our clients understand their risks and how to mitigate them? The answer is you—a lead information security risk...