Conduct risk and vulnerability assessments and inspections of planned and installed information ... Perform security impact analysis on any system change and appropriately prepare letters of ...
Conduct risk and vulnerability assessments and inspections of planned and installed information ... Perform security impact analysis on any system change and appropriately prepare letters of ...
Conduct risk and vulnerability assessments and inspections of planned and installed information ... Perform security impact analysis on any system change and appropriately prepare letters of ...
Conduct risk and vulnerability assessments and inspections of planned and installed information ... Perform security impact analysis on any system change and appropriately prepare letters of ...
Risk Management Co-op
Boston, MA · On-site
Risk Assessments, Emergency Preparedness, Business Continuity, Business, Information Technology, and/or Information Security * Experience with project and/or program management, whether business ...
Risk Management Co-op
Boston, MA · On-site
Risk Assessments, Emergency Preparedness, Business Continuity, Business, Information Technology, and/or Information Security * Experience with project and/or program management, whether business ...
Information Security Analyst
Boston, MA · On-site
Responsibilities : • Participates in the development, risk assessment, communications, status ... SourcePro Search provides direct hire, temporary, temp-to-hire, and executive recruitment and ...
Information Security Analyst
Boston, MA · On-site
Responsibilities : • Participates in the development, risk assessment, communications, status ... SourcePro Search provides direct hire, temporary, temp-to-hire, and executive recruitment and ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
Compliance Risk Analyst
Marlborough, MA · On-site
$70K - $91K/yr
You will own the intake, assessment, and monitoring lifecycle, translating complex technical risks ... For temporary assignments lasting 13 weeks or longer, AllSTEM Connections is pleased to offer major ...
Compliance Risk Analyst
Marlborough, MA · On-site
$70K - $91K/yr
You will own the intake, assessment, and monitoring lifecycle, translating complex technical risks ... For temporary assignments lasting 13 weeks or longer, AllSTEM Connections is pleased to offer major ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
... Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus ... assessments to enhance internal controls - Conducting compliance audits and reviews to confirm ...
New
... Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus ... assessments to enhance internal controls - Conducting compliance audits and reviews to confirm ...
New
Principal Enterprise Risk Management Analyst
Marlborough, MA · Hybrid
$146K - $176K/yr
Lead complex risk assessments for significant initiatives, including technology implementations ... Partner with Technology, Information Security, Compliance, Business Continuity, Internal Audit, and ...
Principal Enterprise Risk Management Analyst
Marlborough, MA · Hybrid
$146K - $176K/yr
Lead complex risk assessments for significant initiatives, including technology implementations ... Partner with Technology, Information Security, Compliance, Business Continuity, Internal Audit, and ...
These teams work continuously to engage and assess member firm and market risk. * Intelligence ... Deep understanding of securities markets, broker-dealer operations, and regulatory frameworks
These teams work continuously to engage and assess member firm and market risk. * Intelligence ... Deep understanding of securities markets, broker-dealer operations, and regulatory frameworks
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
This colleague will be focused on the information security and technology space. Primary ... Activities include Risk and Control Self-Assessments, Issues Management, Material Risk ...
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
This colleague will be focused on the information security and technology space. Primary ... Activities include Risk and Control Self-Assessments, Issues Management, Material Risk ...
The incumbent evaluates and monitors vendor security practices, conducting risk assessments, and cross-functional collaboration with business units and IT to ensure proficient cybersecurity posture.
The incumbent evaluates and monitors vendor security practices, conducting risk assessments, and cross-functional collaboration with business units and IT to ensure proficient cybersecurity posture.
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
This colleague will be focused on the information security and technology space. Primary ... Activities include Risk and Control Self-Assessments, Issues Management, Material Risk ...
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
This colleague will be focused on the information security and technology space. Primary ... Activities include Risk and Control Self-Assessments, Issues Management, Material Risk ...
Cloud Security Engineer
Waltham, MA · On-site
Additionally, the Cloud Security Engineer assists in the development of cyber security requirements, conducts security risk assessments, evaluates security services and technologies, and reviews and ...
Cloud Security Engineer
Waltham, MA · On-site
Additionally, the Cloud Security Engineer assists in the development of cyber security requirements, conducts security risk assessments, evaluates security services and technologies, and reviews and ...
Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC ...
Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC ...
Senior CyberSecurity Engineer with Security Clearance
Bedford, MA · On-site
$170K - $180K/yr
Conduct risk and vulnerability assessments; recommend security policies, contingency plans, and disaster recovery procedures. * Participate in system/network design to ensure alignment with security ...
Senior CyberSecurity Engineer with Security Clearance
Bedford, MA · On-site
$170K - $180K/yr
Conduct risk and vulnerability assessments; recommend security policies, contingency plans, and disaster recovery procedures. * Participate in system/network design to ensure alignment with security ...
Insider Risk Investigator
Boston, MA · On-site
$245K - $305K/yr
The Insider Risk Team works cross-functionally to deter, identify, investigate and mitigate risks ... Provide rapid-turnaround security assessments to support business operations * Support education ...
New
Insider Risk Investigator
Boston, MA · On-site
$245K - $305K/yr
The Insider Risk Team works cross-functionally to deter, identify, investigate and mitigate risks ... Provide rapid-turnaround security assessments to support business operations * Support education ...
New
Fractional CISO Consultant
Boston, MA · On-site
Experience conducting security due diligence and risk assessments for acquisitions. * Strong communication skills with the ability to train and educate stakeholders on compliance and risk management.
Fractional CISO Consultant
Boston, MA · On-site
Experience conducting security due diligence and risk assessments for acquisitions. * Strong communication skills with the ability to train and educate stakeholders on compliance and risk management.
... risk assessment, ongoing monitoring, issue management, resilience planning, testing, governance ... for temporary provider disruptions and Exit Plans (EPs) for permanent provider transitions.
... risk assessment, ongoing monitoring, issue management, resilience planning, testing, governance ... for temporary provider disruptions and Exit Plans (EPs) for permanent provider transitions.
Cloud Security Analyst 2
Tewksbury, MA · On-site
$68/hr
Cloud Security Analyst 2 - Secret Clearance Location: Concord or Tewksbury, MA Duration: 6 months ... risk assessment and provides recommendations for application design for cloud based solutions.
Cloud Security Analyst 2
Tewksbury, MA · On-site
$68/hr
Cloud Security Analyst 2 - Secret Clearance Location: Concord or Tewksbury, MA Duration: 6 months ... risk assessment and provides recommendations for application design for cloud based solutions.
Temporary Security Risk Assessment information
What is the difference between Temporary Security Risk Assessment vs Security Analyst?
| Aspect | Temporary Security Risk Assessment | Security Analyst |
|---|---|---|
| Credentials | Certifications like CISSP, CISA often preferred | Same certifications typically required |
| Work Environment | Project-based, short-term assessments | Ongoing security monitoring and analysis |
| Industry Usage | Used during specific projects or audits | Continuous security operations in organizations |
| Search & Comparison Intent | Focus on temporary assessments and risk evaluations | Focus on ongoing security analysis roles |
The main difference is that a Temporary Security Risk Assessment is a short-term, project-specific evaluation of security risks, often used during audits or specific initiatives. In contrast, a Security Analyst performs ongoing security monitoring and analysis within an organization. Both roles require similar certifications and work in security-focused environments, but their scope and duration differ significantly.
Other
Medical, Dental, Life, Retirement, PTO
Re-posted 14 days ago
Job description
Abacus Technology is seeking an Information System Security Manager (ISSM) to ensure system and application deliverables meet all required cyber security policies and regulations for the Technical Advisory and Assistance Services (TAAS) program at Hanscom AFB. This is a full-time position.
Responsibilities
- Support system/application Assessment and Authorization (A&A) efforts, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing National, DoD, and Department of the Air Force policies (i.e., RMF).
- Recommend policies and procedures to ensure the reliability of and accessibility to information systems and to prevent and defend against unauthorized access to systems, networks, and data.
- Conduct risk and vulnerability assessments and inspections of planned and installed information systems to identify vulnerabilities, risks, and protection needs.
- Evaluate threats and vulnerabilities to information systems to ascertain the need for additional safeguards.
- Evaluate system sources of changes such as Deficiency Reports (DRs), Problem Reports (PRs), Change Requests/Proposals (CRs/CPs), and AF Form 1067s; provide inputs to the root cause analysis reporting and the formulation of recommended solution from alternatives; determine the security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and if any, document in written reports the changes/revisions to the system's RMF artifacts.
- Review and provide inputs to modification packages, program/system documents and support agreements updates, and communications and network infrastructure upgrades to ensure proper cybersecurity configuration modification management; implementation of technical, managerial, operational requirements; and support requirements (e.g. planning, testing, test infrastructure, documentation, training, etc.) are identified.
- Review system test plans and test results and if necessary, observe system testing for security control implementation in accordance with cybersecurity policies, guidance, and plan.
- Perform security impact analysis on any system change and appropriately prepare letters of assurance, security impact letters, and risk assessment letters to include exceptions, deviations, or waivers to cybersecurity requirements when applicable.
- Continuously monitor intelligence and open-source information for vulnerabilities affecting systems, assess risk, and provide POA&M recommendations.
- Promote awareness of security issues among management and ensuring sound security principles are reflected in organizations' visions and goals.
- Conduct systems security monitoring, evaluations, audits, and reviews.
- Recommend systems security contingency plans and disaster recovery procedures.
- Recommend and implementing programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures.
- Participate in network and systems (to include cryptographic) design to ensure implementation of appropriate systems security policies.
- Facilitate the gathering, analysis, and preservation of evidence used in the prosecution of computer crimes.
- Assess security events to determine impact and implementing corrective actions.
- Ensure the rigorous application of cybersecurity and cryptographic policies, principles, and practices throughout the system development lifecycle.
- Author, monitor, and record system information in applicable databases.
- Prepare and record system, security status, and portfolio management information into the Air Force Information Technology Investment Portfolio Suite (referred to as ITIPS) for FISMA; Security, Interoperability, Supportability, Sustainability, Usability (SISSU); Clinger Cohen Act; and other statutory compliance.
- Author, review, certify, and/or maintain security management plans and RMF package artifacts including but not limited to: RMF Implementation Plans, System Security Management Plans, Information Support Plans, Program Protection Plans (PPPs), Security Risk Analyses, Security Vulnerability and Countermeasure Analyses, Vulnerability Management Plans, Common Control Packages, Security Concepts of Operations, OPSEC Plans, Authority-to-Connect guest system packages, and other system/network security related documents.
- Support and assist external teams in the evaluation of systems Cybersecurity posture to include teams performing non-regular cyber tests, war-games, cyber penetration tests, and cyber studies conducted by the NSA, DISA, Air Force Audit Agency, or other organizations.
- Support the development, coordination, and implementation of cybersecurity-related special projects and taskers, e.g., Defensive Cyber Operations (DCO), Higher Headquarter requests, Notice to Airmen (NOTAMs), Technical Change Orders (TCOs), System Program Office (SPO), 16th AF, USSTRATCOM, USCYBERCOM, SAF/A6, SpOC/S6, AFGSC/A6, 460 Space Wing, and AFNWC/NC efforts.
Qualifications
5+ years experience in cyber security or information assurance. Bachelor's degree in a related field. Must hold one of the following certifications: CISSP, CISM, GSLC, or CCISO. Experience with the certification and accreditation process. Significant experience in vulnerability scanning and analysis, including the use of automated tools and vulnerability management systems. Knowledge of intrusion prevention and network access control tools/systems. Understanding of system audit principles and security risk assessment. Strong understanding of security policy advocated by the U.S. Government including the Department of Defense and appropriate civil agencies, e.g., NIST. Able to perform work that involves ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools. Knowledge of cryptography and cryptographic key management concepts. General experience includes development of both common user and special purpose command and control/information systems with increasing responsibilities in the scope and magnitude of the systems for which solutions have been implemented. Must have a solid understanding of network infrastructure and mission assurance. Familiar with Federal government and DOD standards for IA/security including DIACAP, FISMA, NIST, and OMB. Must have solid communications skills and be capable of working with all levels of an organization. Must be a US Citizen and hold a current Top Secret clearance.
The projected compensation range for this position is $175,800-$195,100. There are multiple factors that can impact a final salary, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (if remote or different from the stated location for this position), education and certifications as well as Federal Government Contract Labor categories. In addition, Abacus Technology offers a benefits package that includes: Health and Dental Insurance; 401(k) and Matching; Life Insurance; Short- and Long-Term Disability; Paid Time Off; Paid Holidays; and Professional Membership, Technical Training, Certification, and Education Assistance.
Applicants selected will be subject to a U.S. government security investigation and must meet eligibility requirements for access to classified information.
EOE/M/F/Vet/Disabled
About Abacus Technology
Sourced by ZipRecruiter
Company size
501 - 1,000 Employees
Headquarters location
Chevy Chase, MD, US
Year founded
1983