it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

3 jobs found

Email me jobs like this
Refine Search
Current Search
incident response expert iii
Medtronic
Sr DevSecOps Engineer
Medtronic Lafayette, Colorado
We anticipate the application window for this opening will close on - 29 Sep 2026 Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first - developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life The Sr DevSecOps Engineer defines, implements, and governs secure embedded software platform practices for regulated medical device programs. This role provides technical leadership across CI/CD automation, embedded Linux security, software supply chain controls, vulnerability management, cybersecurity risk analysis, and release evidence generation to support safe, secure, and compliant medical device development. Overview The Sr DevSecOps Engineer will join the Embedded OS Platforms and DevOps Team to implement secure embedded platform DevOps workflows for new and existing medical device development programs. The Embedded OS Platforms and DevOps Team delivers the software infrastructure and foundational system components that enable operation of product application software. This role is responsible for advancing reusable DevSecOps frameworks, secure CI/D pipelines and software supply chain practices, embedded Linux security capabilities, and cybersecurity lifecycle processes across multiple products. The successful candidate will serve as a technical lead who partners with OS and application software developers, systems, product security, quality, regulatory, and program teams to deliver secure, maintainable, and compliant platform solutions. Key Responsibilities Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including secure CI/CD pipelines, build infrastructure, security automation, and release evidence. Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows. Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness. Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations. Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams. Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns. Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows. Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed. Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations. Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches. Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices. Technologies & Tools AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS Yocto-based embedded Linux package development Embedded hypervisors, Linux device drivers, BSPs, and boot flows Custom build systems and CI/CD pipelines Docker, Snyk, SonarQube, and software composition analysis tools Static analysis, software composition analysis, artifact signing, and vulnerability management tools Python, Bash, and Go Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence GitHub and GitLab Networking security, secure boot, firmware signing, and secure update technologies Preferred Qualifications Hands-on experience with cloud infrastructure (AWS or similar) and modern DevOps practices. Proficiency with infrastructure-as-code and secure CI/CD tooling. Familiarity with monitoring, observability, and incident management. Experience with security technologies and practices including certificates, secrets management, and compliance support. Experience developing DevSecOps workflows in regulated safety-critical environments such as aerospace, medical, automotive, or industrial controls. Understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation. Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting. Experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews. Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders. Strong debugging, problem-solving, and root-cause analysis skills. Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions. TECHNICAL SPECIALIST CAREER STREAM: An individual contributor with responsibility in technical functions to advance existing technology or introduce new technology and therapies. Formulates, delivers, and manages projects assigned, and works with stakeholders to achieve desired results. May act as a mentor to colleagues or direct the work of other professionals. The majority of time is spent delivering R&D, systems, or initiatives related to new technologies or therapies from design to implementation while adhering to policies and using specialized knowledge and skills. For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. 214.2(h)(4)(iii)(A) is required. Physical Job Requirements The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. U.S. Work Authorization & Sponsorship At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment. Recruitment Fraud Alert We are aware of phishing scams targeting job seekers. Please keep the following in mind: Apply only through official Medtronic channels. All legitimate Medtronic recruiting communications come from approved Medtronic platforms and email addresses. Medtronic will never ask for payment or sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such requests are not legitimate. If you receive a suspicious message claiming to be from Medtronic, do not respond, click links, or open attachments. If you have any questions, concerns regarding the authenticity of a communication alleged to have been made by or on behalf of Medtronic, please contact us immediately at . Benefits & Compensation Medtronic offers a competitive Salary and flexible Benefits Package A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. Salary ranges for U.S (excl . click apply for full job details
09/23/2026
Full time
We anticipate the application window for this opening will close on - 29 Sep 2026 Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first - developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life The Sr DevSecOps Engineer defines, implements, and governs secure embedded software platform practices for regulated medical device programs. This role provides technical leadership across CI/CD automation, embedded Linux security, software supply chain controls, vulnerability management, cybersecurity risk analysis, and release evidence generation to support safe, secure, and compliant medical device development. Overview The Sr DevSecOps Engineer will join the Embedded OS Platforms and DevOps Team to implement secure embedded platform DevOps workflows for new and existing medical device development programs. The Embedded OS Platforms and DevOps Team delivers the software infrastructure and foundational system components that enable operation of product application software. This role is responsible for advancing reusable DevSecOps frameworks, secure CI/D pipelines and software supply chain practices, embedded Linux security capabilities, and cybersecurity lifecycle processes across multiple products. The successful candidate will serve as a technical lead who partners with OS and application software developers, systems, product security, quality, regulatory, and program teams to deliver secure, maintainable, and compliant platform solutions. Key Responsibilities Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including secure CI/CD pipelines, build infrastructure, security automation, and release evidence. Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows. Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness. Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations. Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams. Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns. Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows. Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed. Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations. Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches. Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices. Technologies & Tools AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS Yocto-based embedded Linux package development Embedded hypervisors, Linux device drivers, BSPs, and boot flows Custom build systems and CI/CD pipelines Docker, Snyk, SonarQube, and software composition analysis tools Static analysis, software composition analysis, artifact signing, and vulnerability management tools Python, Bash, and Go Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence GitHub and GitLab Networking security, secure boot, firmware signing, and secure update technologies Preferred Qualifications Hands-on experience with cloud infrastructure (AWS or similar) and modern DevOps practices. Proficiency with infrastructure-as-code and secure CI/CD tooling. Familiarity with monitoring, observability, and incident management. Experience with security technologies and practices including certificates, secrets management, and compliance support. Experience developing DevSecOps workflows in regulated safety-critical environments such as aerospace, medical, automotive, or industrial controls. Understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation. Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting. Experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews. Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders. Strong debugging, problem-solving, and root-cause analysis skills. Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions. TECHNICAL SPECIALIST CAREER STREAM: An individual contributor with responsibility in technical functions to advance existing technology or introduce new technology and therapies. Formulates, delivers, and manages projects assigned, and works with stakeholders to achieve desired results. May act as a mentor to colleagues or direct the work of other professionals. The majority of time is spent delivering R&D, systems, or initiatives related to new technologies or therapies from design to implementation while adhering to policies and using specialized knowledge and skills. For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. 214.2(h)(4)(iii)(A) is required. Physical Job Requirements The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. U.S. Work Authorization & Sponsorship At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment. Recruitment Fraud Alert We are aware of phishing scams targeting job seekers. Please keep the following in mind: Apply only through official Medtronic channels. All legitimate Medtronic recruiting communications come from approved Medtronic platforms and email addresses. Medtronic will never ask for payment or sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such requests are not legitimate. If you receive a suspicious message claiming to be from Medtronic, do not respond, click links, or open attachments. If you have any questions, concerns regarding the authenticity of a communication alleged to have been made by or on behalf of Medtronic, please contact us immediately at . Benefits & Compensation Medtronic offers a competitive Salary and flexible Benefits Package A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. Salary ranges for U.S (excl . click apply for full job details
Information Systems Security Manager / Specialist
Node.Digital Arlington, Virginia
Job Description Job Description Information Systems Security Manager / Specialist Location: Arlington, VA Must have an active Top Secret Clearance Node provides HIRT remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis capabilities. Node is seeking an Information Systems Security Specialist to support this critical customer mission. Responsibilities: -Work as part of a team of Information Assurance professionals to manage the full Risk Management Framework lifecycle for Information Technology systems -Assisting technical/management leadership on major tasks or technology assignments -Establishing goals and plans that meet project objectives -Assisting in direction and control activities, having overall responsibility for security management, methods, and staffing to ensure that technical requirements are met -Participating in client negotiations and interfacing with senior management -Supporting decision making and domain knowledge that may have a critical impact on overall project implementation -Providing support to plan, coordinate, and implement a cybersecurity lab's information security -Providing support for facilitating and helping the lab identify its current security infrastructure and define future programs, design and implementation of security related to lab systems -Assisting the efforts of security staff to design, develop, engineer and implement solutions to security requirements -Implementing and development of the DHS IT security standards -Gathering and organizing technical information about the lab's mission goals and needs, existing security products, and ongoing programs -Performing risk analyses which also includes risk assessment -Planning and leading major technology assignments -Evaluating performance results and recommends major changes affecting short-term project growth and success -Functioning as a cyber technical expert across multiple project assignments -Working closely with ISSM and CISO to respond to Data Calls and satisfy requirements of ATOs Requirements Required Skills: - U.S. Citizenship - Must have an active TS/SCI clearance - Must be able to obtain DHS Suitability - 5+ years of directly relevant experience in information security management - Hands on experience with Linux operating systems or Amazon Web Services - Experience supporting the NIST Risk Management Framework (RMF) process and contributing to a full ATO effort from initiation through authorization, including development of security documentation, control implementation statements, supporting assessment (audit) activities, and performing full POA&M management - Beginning to end Knowledge of RMF and Assessment and Authorization (A&A) documentation to include SSP, Contingency, Incident & Configuration Mgmt planning and execution - Experience working on multiple complex assignments which are broad in nature, requiring originality and innovation in determining how to accomplish tasks - Ability to apply a comprehensive knowledge across key tasks and high impact assignments - Knowledge of Computer Network Defense (CND) policies, procedures & regulations - Knowledge of defense-in-depth principles and network security architecture - Knowledge of ATO requirements and strong experience with POAMs. - Knowledge and experience with full range of Microsoft Office products (Word, Excel, Powerpoint, and Visio) - Knowledge of boundary protection and network segmentation - Knowledge of authentication and access management techniques - Experience with implementing and assessing security controls for hardware, software, and network deployments - Must be able to work collaboratively with internal and external stakeholders across physical locations Desired Skills: - Experience with Risk Management Framework software (CSAM, Xacta, Archer, RegScale) - Experience with host and network scanning software (Nessus, Security Center, Tenable Vulnerability Management, nmap, Wiz, burp) - Experience with Endpoint Protection tools like CrowdStrike or CarbonBlack - Working knowledge of SIEM tools like Splunk, SOAR, or ELK - Familiarity with role-based account processing operations - Familiarity with zero trust architectures - Familiarity with scripting languages (python, AWS CLI, Lambda, bash, powershell) Required Education: BS Information Management, Cybersecurity, Computer Science or related degree, or High School Diploma and 7+ years of information security management experience. Desired Certifications: - DoD 8140.01 IAT Level III, CISSP, AWS, Cisco, Microsoft Benefits Medical Dental Vision Basic Life Health Saving Account 401K Matching Three weeks of PTO/Sick 11 Paid Holidays Pre-Approved Online Training
09/23/2026
Full time
Job Description Job Description Information Systems Security Manager / Specialist Location: Arlington, VA Must have an active Top Secret Clearance Node provides HIRT remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis capabilities. Node is seeking an Information Systems Security Specialist to support this critical customer mission. Responsibilities: -Work as part of a team of Information Assurance professionals to manage the full Risk Management Framework lifecycle for Information Technology systems -Assisting technical/management leadership on major tasks or technology assignments -Establishing goals and plans that meet project objectives -Assisting in direction and control activities, having overall responsibility for security management, methods, and staffing to ensure that technical requirements are met -Participating in client negotiations and interfacing with senior management -Supporting decision making and domain knowledge that may have a critical impact on overall project implementation -Providing support to plan, coordinate, and implement a cybersecurity lab's information security -Providing support for facilitating and helping the lab identify its current security infrastructure and define future programs, design and implementation of security related to lab systems -Assisting the efforts of security staff to design, develop, engineer and implement solutions to security requirements -Implementing and development of the DHS IT security standards -Gathering and organizing technical information about the lab's mission goals and needs, existing security products, and ongoing programs -Performing risk analyses which also includes risk assessment -Planning and leading major technology assignments -Evaluating performance results and recommends major changes affecting short-term project growth and success -Functioning as a cyber technical expert across multiple project assignments -Working closely with ISSM and CISO to respond to Data Calls and satisfy requirements of ATOs Requirements Required Skills: - U.S. Citizenship - Must have an active TS/SCI clearance - Must be able to obtain DHS Suitability - 5+ years of directly relevant experience in information security management - Hands on experience with Linux operating systems or Amazon Web Services - Experience supporting the NIST Risk Management Framework (RMF) process and contributing to a full ATO effort from initiation through authorization, including development of security documentation, control implementation statements, supporting assessment (audit) activities, and performing full POA&M management - Beginning to end Knowledge of RMF and Assessment and Authorization (A&A) documentation to include SSP, Contingency, Incident & Configuration Mgmt planning and execution - Experience working on multiple complex assignments which are broad in nature, requiring originality and innovation in determining how to accomplish tasks - Ability to apply a comprehensive knowledge across key tasks and high impact assignments - Knowledge of Computer Network Defense (CND) policies, procedures & regulations - Knowledge of defense-in-depth principles and network security architecture - Knowledge of ATO requirements and strong experience with POAMs. - Knowledge and experience with full range of Microsoft Office products (Word, Excel, Powerpoint, and Visio) - Knowledge of boundary protection and network segmentation - Knowledge of authentication and access management techniques - Experience with implementing and assessing security controls for hardware, software, and network deployments - Must be able to work collaboratively with internal and external stakeholders across physical locations Desired Skills: - Experience with Risk Management Framework software (CSAM, Xacta, Archer, RegScale) - Experience with host and network scanning software (Nessus, Security Center, Tenable Vulnerability Management, nmap, Wiz, burp) - Experience with Endpoint Protection tools like CrowdStrike or CarbonBlack - Working knowledge of SIEM tools like Splunk, SOAR, or ELK - Familiarity with role-based account processing operations - Familiarity with zero trust architectures - Familiarity with scripting languages (python, AWS CLI, Lambda, bash, powershell) Required Education: BS Information Management, Cybersecurity, Computer Science or related degree, or High School Diploma and 7+ years of information security management experience. Desired Certifications: - DoD 8140.01 IAT Level III, CISSP, AWS, Cisco, Microsoft Benefits Medical Dental Vision Basic Life Health Saving Account 401K Matching Three weeks of PTO/Sick 11 Paid Holidays Pre-Approved Online Training
DHS Security Control Assessor III
OneZero Solutions Washington, Washington DC
Job Description Job Description We are an employee-centric company that truly appreciates our team members and their value to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and fostering teams that are and continue to be technically proficient and technically capable across a comprehensive range of cyber mission areas. OneZero full-time employees receive an extremely competitive benefits package that includes health/dental/vision/life insurance plans, 401K with company matching, PTO & paid holidays, employee referral program, and educational assistance. Additional details can be found on our website at: Title: DHS Security Control Assessor IIILocation: NCRClearance: TS/SCIOneZero Solutions is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) security authorizations, and deliver cyber security compliance for DHS operational mission systems. We are looking for personnel to support our DHS customer in achieving its mission of providing division-wide cyber security support for operational mission systems and assisting programs as they navigate the ATO process. The result of these efforts will be that the systems meet all the requirements for ATO approval before they are officially submitted to the Office of Chief Information Officer (OCIO).Qualified Parking Allowance: Employer may provide a monthly stipend or cover the cost of parking for employees who commute to government site by car.Job SummaryConduct independent assessments of the management, operational, and technical security controls employed within various DHS systems and networks.Evaluate the effectiveness of implemented controls in mitigating identified risks and protecting sensitive data and systems.Identify and document control deficiencies, vulnerabilities, and non-compliance with security policies, regulations, and prescribed hardening guidelines.Develop and present clear and concise findings and recommendations to stakeholders and decision-makers.Support the implementation of corrective actions to address identified deficiencies and improve overall security posture.Stay current with emerging security threats, vulnerabilities, and federal and industry best practices, standards, and policies for employed IT and its continued compliance within DHS.Contribute to the development and continual refinement of internal security assessment methodologies and procedures.Qualifications:10+ years of direct experience serving as a Security Control Assessor (SCA) within the DoD/Federal Government. Experience within the Intelligence Community and Law Enforcement is a strong plus.Demonstrated expertise in various security control frameworks and methodologies, including NIST SP 800-53, FISMA, RMF, DISA STIGs, and DHS supplemental IA controls.Proficiency in conducting security assessments, utilizing tools and techniques for vulnerability scanning, penetration testing, and configuration review.Strong understanding of information security principles and best practices, including network security, system security, encryption, and incident response.Experience with OpenRMF is a strong plus.Excellent analytical and problem-solving skills.Exceptional written and verbal communication skills.Ability to work independently and as part of a team.EducationBachelor 's degree and/or CRISC, GISP, CASP, CISSP, or other advanced security-related certificationsAdditional relevant experience may be considered in lieu of a degree. OneZero Solutions, LLC is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access as a result of your disability.To request an accommodation, please contact us at or call . Job Posted by ApplicantPro
09/15/2026
Full time
Job Description Job Description We are an employee-centric company that truly appreciates our team members and their value to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and fostering teams that are and continue to be technically proficient and technically capable across a comprehensive range of cyber mission areas. OneZero full-time employees receive an extremely competitive benefits package that includes health/dental/vision/life insurance plans, 401K with company matching, PTO & paid holidays, employee referral program, and educational assistance. Additional details can be found on our website at: Title: DHS Security Control Assessor IIILocation: NCRClearance: TS/SCIOneZero Solutions is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) security authorizations, and deliver cyber security compliance for DHS operational mission systems. We are looking for personnel to support our DHS customer in achieving its mission of providing division-wide cyber security support for operational mission systems and assisting programs as they navigate the ATO process. The result of these efforts will be that the systems meet all the requirements for ATO approval before they are officially submitted to the Office of Chief Information Officer (OCIO).Qualified Parking Allowance: Employer may provide a monthly stipend or cover the cost of parking for employees who commute to government site by car.Job SummaryConduct independent assessments of the management, operational, and technical security controls employed within various DHS systems and networks.Evaluate the effectiveness of implemented controls in mitigating identified risks and protecting sensitive data and systems.Identify and document control deficiencies, vulnerabilities, and non-compliance with security policies, regulations, and prescribed hardening guidelines.Develop and present clear and concise findings and recommendations to stakeholders and decision-makers.Support the implementation of corrective actions to address identified deficiencies and improve overall security posture.Stay current with emerging security threats, vulnerabilities, and federal and industry best practices, standards, and policies for employed IT and its continued compliance within DHS.Contribute to the development and continual refinement of internal security assessment methodologies and procedures.Qualifications:10+ years of direct experience serving as a Security Control Assessor (SCA) within the DoD/Federal Government. Experience within the Intelligence Community and Law Enforcement is a strong plus.Demonstrated expertise in various security control frameworks and methodologies, including NIST SP 800-53, FISMA, RMF, DISA STIGs, and DHS supplemental IA controls.Proficiency in conducting security assessments, utilizing tools and techniques for vulnerability scanning, penetration testing, and configuration review.Strong understanding of information security principles and best practices, including network security, system security, encryption, and incident response.Experience with OpenRMF is a strong plus.Excellent analytical and problem-solving skills.Exceptional written and verbal communication skills.Ability to work independently and as part of a team.EducationBachelor 's degree and/or CRISC, GISP, CASP, CISSP, or other advanced security-related certificationsAdditional relevant experience may be considered in lieu of a degree. OneZero Solutions, LLC is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access as a result of your disability.To request an accommodation, please contact us at or call . Job Posted by ApplicantPro

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board