IT Risk Assessment Auditor

2 weeks ago


Lexington, United States MIT Lincoln Laboratory Full time

The Security Services Department’s overall mission is to identify and counter security threats to the MIT Lincoln Laboratory’s mission of development of game-changing technology in support of National Security, including guarding against compromise by foreign intelligence agencies and insider threats. To accomplish this mission, this department formulates and implements policies, plans, and actions designed to protect facilities against threats of vandalism, accidental destruction, and sabotage; and safeguards personnel, classified and unclassified information systems, personal identifiable information, property, and other assets from exploitation and recruitment by foreign intelligence agencies.

We foster a diverse and inclusive culture where security professionals from a wide range of backgrounds are empowered to solve complex security problems in close collaboration with Laboratory research teams and Government counterparts. Our people are our most important resource, and we encourage a casual and flexible opportunity-filled working environment that is technology-focused. Where mission needs can be met, the Security Services Department encourages flexible schedules and hybrid remote work arrangements

Who are we?

MIT Lincoln Laboratory is a Federally Funded Research and Development Center (FFRDC) whose mission is research in support of National Security.

* Mission - The Security Services Department’s (SSD) overall mission is to identify and counter security threats to the MIT Lincoln Laboratory’s mission of development of game-changing technology in support of national security, including guarding against compromise by foreign intelligence agencies and insider threats
* Culture – We foster an inclusive, opportunity-filled environment of empowered team members from diverse backgrounds

What will you do?

The IT Security Risk Auditor position performs audits of classified Information Systems (IS) to ensure that they are being maintained in a compliant manner and are following applicable laws and government regulations, such as National Industrial Security Program Operation Manual (NISPOM) guidelines regarding the protection of classified information systems, National Institute of Standards and Technology (NIST) standards and special publications, and Laboratory Information System Security Procedures. The candidate must be knowledgeable in fundamental computer security principles and policies: Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), Joint SAP Implementation Guide (JSIG), Intelligence Community Directive (ICD) 503, CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4. 


General: The IT Security Risk Auditor is responsible for maintaining and auditing programs to validate compliance with various government regulations and Laboratory Information Security policies. The position is responsible for conducting comprehensive assessments of the management, operation, monitoring and technical security controls employed within or inherited by Information Systems to determine the overall effectiveness of the controls (i.e. the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome) with respect to meeting the security requirements of the Authorization to Operate (ATO) for the system and for the ability to conduct open source and internal research to identify current threat indicators, exploits, and vulnerabilities.

* Materials Control & Accountability: Will help maintain an audit program to validate compliance with various government regulations and Laboratory Information security policies
* Personnel Security: Will assist and serve as a subject matter expert for all Laboratory inspection and compliance by following the DCSA and DoD system of record for clearance process and reporting
* Security Education, Training and Awareness: Will assist and maintain any new/updated government security regulations and requirements as it relates to classified and unclassified information protection

How will you grow?

You will find significant opportunities to do meaningful work in an environment intentionally designed to be one where you will learn, thrive and belong.
* Leadership: Room to advance on your team or to lead cross-functional projects.
* Growth Opportunities: Potential for lateral and vertical movement.
* Education/Training: Management training, mentorship, in-house and external courses.
* Exposure: Engagement with sponsors, stakeholders, Laboratory leadership and other Departments and Divisions.
* Community: Participation is encouraged for Laboratory social events, Employee Resource Groups (ERGs), clubs and study groups, volunteering and community service projects

What you need:

For this position, you must meet these basic requirements.
* Bachelor’s degree in Computer Science, Information Technology, Computer Information Systems, or related field is required with a minimum of seven (7) years’ experience conducting risk assessments within Special Access and Sensitive Compartmented Information Programs. 
* Information Assurance Certifications preferred (CISSP/CISA, Security+, GSEC, CRISC or equivalent).
* Advanced academic degrees and/or certifications in information Assurance, Information Security or IT certifications may be considered substitutes for DoD experience. 
* Experience in compliance auditing, security reviews, or vulnerability assessments.
* Technical experience and skills, course work completed toward a degree, and industry IT certifications (i.e. CISSP, CISA) may be considered substitutes for education and experience. 
* Candidate must possess an in-depth knowledge of information security principles and policies such as Risk Management Framework (RMF) as presented by the National Institute of Standards and Technology (NIST), Joint Special Access Program (SAP) Implementation Guide (JSIG), Intelligence Community Directive 503 (ICD-503), and all applicable Security Technical Implementation Guides (STIGs). 
* DoD 85770 IAM Level I Baseline Certification required. 
* Working experience directly related to Assessment and Authorization using any of the following: 
o NIST 800-53/Risk Management Framework (RMF)
o Joint SAP Implementation Guide (JSIG)
o Intelligence Community Directive (ICD) 503
o National Industrial Security Program Operating Manual (NISPOM) Chapter 8 
* Must be able to obtain and maintain a Top-Secret level DoD security clearance

Regulatory compliance experience: The ability to read, understand and apply government regulation, policies and procedure National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, computer security principles and policies, to include, Security Technical Implementation Guides (STIGs) and NIST 800-53 / Risk Management Framework (RMF).

Ideally, you will have:

 The Laboratory values experiences from diverse backgrounds and occupations. The most successful candidates will have the following skills and qualifications.

* Valued competencies: Interpersonal, organizational, written and verbal communication skills.
* Computer skills: Familiarity with security management software, such as SIMS and government databases such as DISS (Defense Information Security System). Knowledge of business software: Excel, Word, PowerPoint, Office, etc.
* Flexibility: Comfortable responding to off-hours emergencies and local/overnight travel as needed (infrequent, but a possibility)

At MIT Lincoln Laboratory, our exceptional career opportunities include many outstanding benefits to help you stay healthy, feel supported, and enjoy a fulfilling work-life balance. Benefits offered to employees include:
• Comprehensive health, dental, and vision plans
• MIT-funded pension
• Matching 401K
• Paid leave (including vacation, sick, parental, military, etc.)
• Tuition reimbursement and continuing education programs
• Mentorship programs
• A range of work-life balance options
• ... and much more

Please visit our Benefits page for more information. As an employee of MIT, you can also take advantage of other voluntary benefits, discounts, and perks.


  • Senior Auditor

    6 days ago


    Lexington, United States First Community Full time

    This position is responsible for performing all aspects of audits which includes planning, fieldwork, resolution of audit findings, and report writing. This position will also be responsible for conducting a full range of financial, compliance, and operational audits to ensure the bank’s operations and business processes comply with company policies and...

  • Senior Auditor

    1 week ago


    Lexington, United States First Community Full time

    Position Summary Thisposition is responsible for performing all aspects of audits which includesplanning, fieldwork, resolution of audit findings, and report writing. Thisposition will also be responsible for conducting a full range of financial,compliance, and operational audits to ensure the bank's operations and businessprocesses comply with company...


  • Lexington, United States ABHS Full time

    Job DescriptionJob DescriptionJob Purpose Summary: Overview of Intake and Assessment Clinician job functions which include providing direct clinical service and administrative assistance to clients: Obtaining Informed Consent Facilitate acceptance of client Informed Consent documents from patient portal. Ensure all documentation is properly completed prior...


  • Lexington, United States Peoples Bancorp, Inc. Full time

    This position will be responsible for measuring and monitoring operational risk within Bank to prevent risk and fraud. Will be responsible for the Third Party (i.e. vendor) Risk Program. Will identify and implement a comprehensive risk assessments an Risk Officer, Risk, Officer, Senior, VP, Operation, Banking


  • Lexington, United States Marsh McLennan Companies Full time

    Description: Sr. Risk Control Consultant Provide quality risk consulting services to MMA clients. Responsibilities include performing assessments, providing employee training, developing risk management strategies, developing written policies, assisting in the sales process, presenting loss control proposals and maintaining a valued partnership...


  • Lexington, VA 24450, USA, United States The Kendal Corporation Full time

    Overview: A highly skilled and dedicated Infection Prevention and Risk Management Nurse on Kendal at Lexington's health services team. This critical role combines expertise in infection control, risk management, organizational education, and resident assessment to ensure the highest standards of health and safety for both residents and staff. The ideal...

  • ISSO Specialist

    2 weeks ago


    Lexington, United States Softworld Inc Full time

    Job Title: ISSO Specialist Job Location - Lexington MA 02420 Onsite Requirements: NIST 800-53 Current DoD 8570 IAT Level II Certification (GSEC, Security+ CE, SSCP, CCNA-Security) Prior ISSO experience Job Description: This role is supporting Air Force Programs and Client prefers candidates with mid-level experience: Assist and support necessary...

  • ISSO Specialist

    1 week ago


    Lexington, United States John Galt Staffing Full time

    The team is in need of an additional ISSO candidate to continue work within the Cyber Security TeamThis role is supporting Air Force Programs and MIT LL prefers candidates with mid-level experience:Assist and Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring...

  • ISSO Specialist

    1 week ago


    Lexington, United States John Galt Staffing Full time

    The team is in need of an additional ISSO candidate to continue work within the Cyber Security TeamThis role is supporting Air Force Programs and MIT LL prefers candidates with mid-level experience:Assist and Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring...

  • ISSO Specialist

    3 weeks ago


    Lexington, United States Softworld, a Kelly Company Full time

    Job Title: ISSO SpecialistJob Location - Lexington MA 02420Onsite Requirements:NIST 800-53 Current DoD 8570 IAT Level II Certification (GSEC, Security+ CE, SSCP, CCNA-Security) Prior ISSO experience Job Description:This role is supporting Air Force Programs and Client prefers candidates with mid-level experience:Assist and support necessary compliance...

  • ISSO Specialist

    3 weeks ago


    Lexington, United States Softworld, a Kelly Company Full time

    Job Title: ISSO SpecialistJob Location - Lexington MA 02420Onsite Requirements:NIST 800-53 Current DoD 8570 IAT Level II Certification (GSEC, Security+ CE, SSCP, CCNA-Security) Prior ISSO experience Job Description:This role is supporting Air Force Programs and Client prefers candidates with mid-level experience:Assist and support necessary compliance...

  • ISSO Specialist

    3 weeks ago


    Lexington, United States Softworld, a Kelly Company Full time

    Job Title: ISSO SpecialistJob Location - Lexington MA 02420Onsite Requirements:NIST 800-53 Current DoD 8570 IAT Level II Certification (GSEC, Security+ CE, SSCP, CCNA-Security) Prior ISSO experience Job Description:This role is supporting Air Force Programs and Client prefers candidates with mid-level experience:Assist and support necessary compliance...


  • Lexington, United States a Medical Device Equipment located in near Lexington, MA Full time

    Job Duties : Manage start-up, commissioning, qualification, validation, and revalidation projects for various processes including facility, equipment, critical utility, automation/computer systems, cleaning, sterilization, medical devices, and drug product manufacturing. Oversee the delivery of validation in complex, capital projects, ensuring adherence to...


  • Lexington, United States Schneider Electric USA, Inc Full time

    What will you do? Draft quality assurance policies and procedures Interpret and implement quality assurance standards Evaluate adequacy of quality assurance standards Devise sampling procedures and directions for recording and reporting quality data Review the implementation and efficiency of quality and inspection systems Plan, conduct and monitor testing...


  • Lexington, United States First Bank Online Full time

    This position is NOT remote eligible. This position will work in the Nashville, Franklin, Knoxville, or Lexington, TN FirstBank office. Summary: The First Line Compliance Manager is responsible for leading the bank's First Line of Defense for compliance. The First Line Compliance Manager will partner with all segments of the bank to help with the...


  • Lexington, United States a Medical Device Equipment located in near Lexington, MA Full time

    Job Duties:Manage start-up, commissioning, qualification, validation, and revalidation projects for various processes including facility, equipment, critical utility, automation/computer systems, cleaning, sterilization, medical devices, and drug product manufacturing.Oversee the delivery of validation in complex, capital projects, ensuring adherence to...


  • Lexington, United States a Medical Device Equipment located in near Lexington, MA Full time

    Job Duties:Manage start-up, commissioning, qualification, validation, and revalidation projects for various processes including facility, equipment, critical utility, automation/computer systems, cleaning, sterilization, medical devices, and drug product manufacturing.Oversee the delivery of validation in complex, capital projects, ensuring adherence to...


  • Lexington, United States a Medical Device Equipment located in near Lexington, MA Full time

    Job Duties: Manage start-up, commissioning, qualification, validation, and revalidation projects for various processes including facility, equipment, critical utility, automation/computer systems, cleaning, sterilization, medical devices, and drug product manufacturing. Oversee the delivery of validation in complex, capital projects, ensuring adherence to...


  • Lexington, United States a Medical Device Equipment located in near Lexington, MA Full time

    Job Duties:Manage start-up, commissioning, qualification, validation, and revalidation projects for various processes including facility, equipment, critical utility, automation/computer systems, cleaning, sterilization, medical devices, and drug product manufacturing.Oversee the delivery of validation in complex, capital projects, ensuring adherence to...


  • Lexington, United States a Medical Device Equipment located in near Lexington, MA Full time

    Job Duties:Manage start-up, commissioning, qualification, validation, and revalidation projects for various processes including facility, equipment, critical utility, automation/computer systems, cleaning, sterilization, medical devices, and drug product manufacturing.Oversee the delivery of validation in complex, capital projects, ensuring adherence to...