VIATEQ Corporation
Washington, Washington DC
Job Description Job Description VIATEQ Corporation is looking for a Scrum Master to support agile delivery teams responsible for operating and maintaining cloud environments across Azure, AWS, and Google Cloud Platform (GCP). The ideal candidate is an energetic, servant-leader who is passionate about agile principles and practices, with a strong understanding of cloud operations and infrastructure delivery. The ability to obtain or maintain an active Secret clearance is required to support our government customer. The Scrum Master will play a critical role in facilitating agile ceremonies, removing impediments, and enabling high-performing delivery teams responsible for operating and maintaining cloud environments across Azure, AWS, and GCP. The Scrum Master will work closely with Product Owners, engineers, security engineers, and program leadership to ensure teams remain focused, aligned, and continuously improving. This individual will support multiple small, focused teams managing cloud service offerings at varying FISMA compliance levels. Responsibilities: Serve as a servant-leader and coach for one or more agile delivery teams, championing Scrum values, principles, and practices across the organization. Facilitate all Scrum ceremonies including Sprint Planning, Daily Standups, Sprint Reviews, Sprint Retrospectives, and Backlog Refinement sessions. Work closely with Product Owners to ensure the product backlog is well-maintained, clearly prioritized, and that user stories are clearly defined with actionable acceptance criteria. Identify, track, and actively work to remove impediments and blockers that hinder team progress, escalating issues to program leadership when appropriate. Foster a culture of collaboration, transparency, continuous improvement, and accountability across cloud engineering and operations teams. Support and coordinate delivery activities across teams responsible for Azure, AWS, and GCP cloud environments, ensuring alignment with program goals and customer requirements. Facilitate cross-team coordination and dependency management to ensure smooth delivery across multiple cloud platforms. Partner with engineering leads and security engineers to ensure that compliance, security, and operational requirements are accounted for in sprint planning and backlog management. Track and communicate team velocity, sprint progress, and delivery metrics to stakeholders and program leadership. Support teams in the adoption and continuous refinement of DevOps and CI/CD practices as they relate to cloud infrastructure delivery. Assist teams in maintaining documentation, operational plans, and implementation records for cloud solutions across Azure, AWS, and GCP environments. Promote a culture of automation, operational excellence, and process improvement within and across delivery teams. Participate in program-level Agile ceremonies and contribute to broader Agile transformation efforts across the organization. Support teams operating at FISMA Moderate and FISMA High compliance levels, ensuring sprint activities account for regulatory and security requirements. Required Education and Experience: Bachelor's degree in computer science, Business Administration, Information Technology, Project Management, or a related field from an accredited college or university. 5+ years of experience as a Scrum Master, with demonstrated experience supporting technical engineering or cloud infrastructure teams. Certified Scrum Master (CSM) or Professional Scrum Master (PSM I) certification required. Demonstrated experience working with teams that develop, operate, or maintain cloud environments in one or more of the following platforms: Azure, AWS, or GCP. Experience supporting teams within a federal government IT environment. Experience supporting teams operating within FISMA Moderate and/or FISMA High compliance environments. Required Skills and Competencies: Exceptional communication skills in English, both written and oral, with the ability to communicate effectively with both technical and non-technical stakeholders, including executive leadership. Strong understanding of Agile and Scrum principles, values, and practices, with the ability to coach teams at varying levels of Agile maturity. Ability to facilitate productive, focused Scrum ceremonies and drive meaningful outcomes. Experience working with and supporting cloud infrastructure or cloud operations teams in Azure, AWS, and/or GCP environments. Proficiency with Agile project management and collaboration tools such as Jira, Confluence, Azure DevOps, or similar platforms. Strong understanding of the DevOps lifecycle, CI/CD practices, and how they intersect with cloud infrastructure delivery. Demonstrated ability to identify and remove impediments, manage risks, and escalate issues appropriately. Ability to track and report on team velocity, sprint metrics, and delivery progress in a clear and concise manner. Experience managing cross-team dependencies and coordinating delivery across multiple concurrent workstreams. Strong organizational skills with the ability to manage multiple priorities simultaneously in a fast-paced environment. Commitment to building and sustaining a culture of collaboration, transparency, and continuous improvement. Ability to obtain and maintain a government security clearance. Preferred Skills and Competencies: Advanced Agile certifications such as Advanced Certified Scrum Master (A-CSM), SAFe Scrum Master (SSM), or Professional Scrum Master II (PSM II). Familiarity with Scaled Agile Framework (SAFe). Experience with Kanban methodology and familiarity with hybrid Agile delivery approaches. Working knowledge of cloud platforms including Azure, AWS, and GCP, including familiarity with common cloud services, IaaS/PaaS offerings, and cloud operations concepts. Familiarity with FISMA compliance frameworks and FedRAMP authorization processes. Experience supporting teams responsible for Infrastructure as Code (IaC) delivery using tools such as Terraform, Ansible, or similar. Knowledge of cloud security best practices and how security requirements are incorporated into agile delivery workflows. Familiarity with Zero Trust architecture principles and their implications for cloud operations teams. Compensation Range: $90,000 - 140,000. This represents the typical compensation range for this position based on experience, location, and other factors. About VIATEQ VIATEQ is a proactive provider of collaborative solutions for federal government agencies. Our collaborative service framework and flexibility allow employees, customers, and business partners to work together successfully anywhere, anytime. VIATEQ's service areas also allow government agencies to respond to competitive pressures and achieve new performance levels. VIATEQ offers competitive compensation and a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan, paid time off, 12 paid federal holidays, flexible spending accounts, and a professional development reimbursement. Equal Opportunity Statement: VIATEQ provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination, harassment, and retaliation in accordance with applicable federal, state, and local laws. This policy applies to all terms and conditions of employment including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Job Description Job Description VIATEQ Corporation is looking for a Scrum Master to support agile delivery teams responsible for operating and maintaining cloud environments across Azure, AWS, and Google Cloud Platform (GCP). The ideal candidate is an energetic, servant-leader who is passionate about agile principles and practices, with a strong understanding of cloud operations and infrastructure delivery. The ability to obtain or maintain an active Secret clearance is required to support our government customer. The Scrum Master will play a critical role in facilitating agile ceremonies, removing impediments, and enabling high-performing delivery teams responsible for operating and maintaining cloud environments across Azure, AWS, and GCP. The Scrum Master will work closely with Product Owners, engineers, security engineers, and program leadership to ensure teams remain focused, aligned, and continuously improving. This individual will support multiple small, focused teams managing cloud service offerings at varying FISMA compliance levels. Responsibilities: Serve as a servant-leader and coach for one or more agile delivery teams, championing Scrum values, principles, and practices across the organization. Facilitate all Scrum ceremonies including Sprint Planning, Daily Standups, Sprint Reviews, Sprint Retrospectives, and Backlog Refinement sessions. Work closely with Product Owners to ensure the product backlog is well-maintained, clearly prioritized, and that user stories are clearly defined with actionable acceptance criteria. Identify, track, and actively work to remove impediments and blockers that hinder team progress, escalating issues to program leadership when appropriate. Foster a culture of collaboration, transparency, continuous improvement, and accountability across cloud engineering and operations teams. Support and coordinate delivery activities across teams responsible for Azure, AWS, and GCP cloud environments, ensuring alignment with program goals and customer requirements. Facilitate cross-team coordination and dependency management to ensure smooth delivery across multiple cloud platforms. Partner with engineering leads and security engineers to ensure that compliance, security, and operational requirements are accounted for in sprint planning and backlog management. Track and communicate team velocity, sprint progress, and delivery metrics to stakeholders and program leadership. Support teams in the adoption and continuous refinement of DevOps and CI/CD practices as they relate to cloud infrastructure delivery. Assist teams in maintaining documentation, operational plans, and implementation records for cloud solutions across Azure, AWS, and GCP environments. Promote a culture of automation, operational excellence, and process improvement within and across delivery teams. Participate in program-level Agile ceremonies and contribute to broader Agile transformation efforts across the organization. Support teams operating at FISMA Moderate and FISMA High compliance levels, ensuring sprint activities account for regulatory and security requirements. Required Education and Experience: Bachelor's degree in computer science, Business Administration, Information Technology, Project Management, or a related field from an accredited college or university. 5+ years of experience as a Scrum Master, with demonstrated experience supporting technical engineering or cloud infrastructure teams. Certified Scrum Master (CSM) or Professional Scrum Master (PSM I) certification required. Demonstrated experience working with teams that develop, operate, or maintain cloud environments in one or more of the following platforms: Azure, AWS, or GCP. Experience supporting teams within a federal government IT environment. Experience supporting teams operating within FISMA Moderate and/or FISMA High compliance environments. Required Skills and Competencies: Exceptional communication skills in English, both written and oral, with the ability to communicate effectively with both technical and non-technical stakeholders, including executive leadership. Strong understanding of Agile and Scrum principles, values, and practices, with the ability to coach teams at varying levels of Agile maturity. Ability to facilitate productive, focused Scrum ceremonies and drive meaningful outcomes. Experience working with and supporting cloud infrastructure or cloud operations teams in Azure, AWS, and/or GCP environments. Proficiency with Agile project management and collaboration tools such as Jira, Confluence, Azure DevOps, or similar platforms. Strong understanding of the DevOps lifecycle, CI/CD practices, and how they intersect with cloud infrastructure delivery. Demonstrated ability to identify and remove impediments, manage risks, and escalate issues appropriately. Ability to track and report on team velocity, sprint metrics, and delivery progress in a clear and concise manner. Experience managing cross-team dependencies and coordinating delivery across multiple concurrent workstreams. Strong organizational skills with the ability to manage multiple priorities simultaneously in a fast-paced environment. Commitment to building and sustaining a culture of collaboration, transparency, and continuous improvement. Ability to obtain and maintain a government security clearance. Preferred Skills and Competencies: Advanced Agile certifications such as Advanced Certified Scrum Master (A-CSM), SAFe Scrum Master (SSM), or Professional Scrum Master II (PSM II). Familiarity with Scaled Agile Framework (SAFe). Experience with Kanban methodology and familiarity with hybrid Agile delivery approaches. Working knowledge of cloud platforms including Azure, AWS, and GCP, including familiarity with common cloud services, IaaS/PaaS offerings, and cloud operations concepts. Familiarity with FISMA compliance frameworks and FedRAMP authorization processes. Experience supporting teams responsible for Infrastructure as Code (IaC) delivery using tools such as Terraform, Ansible, or similar. Knowledge of cloud security best practices and how security requirements are incorporated into agile delivery workflows. Familiarity with Zero Trust architecture principles and their implications for cloud operations teams. Compensation Range: $90,000 - 140,000. This represents the typical compensation range for this position based on experience, location, and other factors. About VIATEQ VIATEQ is a proactive provider of collaborative solutions for federal government agencies. Our collaborative service framework and flexibility allow employees, customers, and business partners to work together successfully anywhere, anytime. VIATEQ's service areas also allow government agencies to respond to competitive pressures and achieve new performance levels. VIATEQ offers competitive compensation and a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan, paid time off, 12 paid federal holidays, flexible spending accounts, and a professional development reimbursement. Equal Opportunity Statement: VIATEQ provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination, harassment, and retaliation in accordance with applicable federal, state, and local laws. This policy applies to all terms and conditions of employment including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
VIATEQ Corporation
Washington, Washington DC
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details