Systems and Information Security Specialist
OVERVIEW
Hendall is currently seeking a Systems and Information Security Specialist experienced with the Federal Information Security Management Act (FISMA), U.S. Department of Health and Human Services (HHS), Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST) regulations, policies, and guidelines.
DUTIES
The Systems and Information Security Specialist analyzes, defines, implements, and maintains all required procedures and security controls in accordance with Federal, and HHS regulations, policies, and guidelines. Specifically:
- Conduct Security Assessment and Authorization (SA&A) processes and procedures to attain Authorization To Operate (ATO) for supported information systems
- Remediate security weaknesses through the implementation of Plan of Actions & Milestones (POA&Ms)
- Perform risk analyses which also includes risk assessment, mitigation and contingency planning.
- Develop and maintain information security policies, procedures and control techniques in accordance with FISMA and NIST Special Publications 800 Series
- Develop and maintain BHSIS Information System Security Plan and IT Plan
- Assist with the preparation and maintenance of OMB required forms and other paperwork for major IT investments
- Perform periodic reviews to ensure compliance with existing information security and privacy requirements.
- Continuously monitor system(s) security controls and operational environment
- Complete annual system self-assessments, and support quarterly and annual FISMA reporting requirements
- Conduct monthly Database, Application and Operating System vulnerability scans and report outcomes to clients' Chief Information System Officer (CISO)
- Perform annual penetration testing on client systems and provide test reports to clients
- Act as liaison between clients' CISO and Hendall
MINIMUM QUALIFICATIONS
- Bachelor's degree in computer science, information systems or information technology
- 3-5 years of professional experience in Federal IT Security
- Certified Information Systems Security Professional (CISSP) certification or similar (Preferred)
- Experience working in a Federal Information Processing Standard (FIP) 199 Moderate categorized system environment
- Strong verbal and written communication skills
- Highly organized and detail oriented
- Ability to maintain and manage ATO-related controls and other information security artifacts
PREFERRED QUALIFICATIONS
- Experience performing information security services within the Department of Health and Human Services and its operating divisions.
Salary Range: $90,000/year to $110,000/year
For a complete listing of benefits, please visit our careers page at
Hendall Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.