What are the responsibilities and job description for the Cloud Based Security Control Assessor (SCA) position at QinetiQ?
Company Overview
We are a world-class team of professionals who deliver next generation technology and products in robotic and autonomous platforms, ground, soldier, and maritime systems in 50 locations world-wide. Much of our work contributes to innovative research in the fields of sensor science, signal processing, data fusion, artificial intelligence (AI), machine learning (ML), and augmented reality (AR).
QinetiQ US’s dedicated experts in defense, aerospace, security, and related fields all work together to explore new ways of protecting the American Warfighter, Security Forces, and Allies. Being a part of QinetiQ US means being central to the safety and security of the world around us. Partnering with our customers, we help save lives; reduce risks to society; and maintain the global infrastructure on which we all depend.
Why Join QinetiQ US?
If you have the courage to take on a wide variety of complex challenges, then you will experience a unique working environment where innovative teams blend different perspectives, disciplines, and technologies to discover new ways of solving complex problems. In our diverse and inclusive environment, you can be authentic, feel valued, be respected, and realize your full potential. QinetiQ US will support you with workplace flexibility, a commitment to the health and well-being of you and your family and provide opportunities to work with a purpose. We are committed to supporting your success in both your professional and personal lives.
Position Overview
QinetiQ US is looking for a Security Control Assessor with cloud based experience to support a dynamic DoD client in the Chantilly, VA area. Candidates are expected to leverage their past experience and knowledege to help deliver superior support to a rapid prototyping office and should have experience in supporting various cloud based platforms such as Amazon Web Services, Azure, Microsoft Google etc.
Responsibilities
- Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems.
- Ensure security assessments are completed for each IS.
- Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR.
- Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO.
- Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization.
- Serve as a cybersecurity technical advisor to the CISO and AO under their purview.
- Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies.
- Determine and document in the SAR a risk level for every noncompliant security control in the system baseline.
- Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation.
- Develop a continuous monitoring plan specific to the information system.
- Other duties as assigned.
Required Qualifications
Preferred Qualifications
Company EEO Statement