Role: Senior Security Assessor -FAA
Location: Washington, D.C
Duration: 3+ years
Must also possess:
1. Direct experience in NIST security control assessments
2. Direct experience in System Security Plan (SSP) development
3. Direct experience conducting or supporting NIST-based risk assessments
4. Demonstrated success interfacing directly with system owners and executive management levels
5. Demonstrable excellence in written and verbal communications (samples may be requested)
6. A demonstrated consulting mentality, and the professional habit of treating all others as direct customers
7. Demonstrable understanding of basic Information Technology (IT) concepts (such as networking, access control, server functions), as well as cloud concepts
8. Demonstrable understanding of privacy concepts as they apply to security assessment as outlined in NIST’s appendix “J” of 800.53
9. The ability to conduct the following tasks without supervision:
• Conducting Security Control Assessments and testing
• System Security Plan (SSP) Review, Evaluation, Creation
• Plan of Action and Milestones (POA&M)
• Conducting Risk Analysis
• Conducting Risk Assessments
• Security Assessment Report (SAR)
• Risk Assessment Report (RAR)
• SA&A or Security Assessment and Authorization (or C&A)
• Contingency Plan Development or Evaluation
10. Secondary (search terms) areas of interest for this role:
• FedRamp
• CSAM
• FISMA
• NIST
• HP Webinspect
• McAfee Vulnerability Manager
• SCD
Additional InformationPlease send me your updated resume with salary expectation if you are interested in this opportunity at javed.chauhan(at)biitservices.com
Skills Required
- Direct experience in NIST security control assessments
- Direct experience in System Security Plan (SSP) development
- Direct experience conducting or supporting NIST-based risk assessments
- Demonstrated success interfacing directly with system owners and executive management levels
- Demonstrable excellence in written and verbal communications (samples may be requested)
- Demonstrated consulting mentality and professional client-service orientation
- Demonstrable understanding of basic IT concepts (networking, access control, server functions) and cloud concepts
- Demonstrable understanding of privacy concepts as they apply to NIST 800-53 Appendix J
- Ability to conduct Security Control Assessments and testing without supervision
- Ability to review, evaluate, and create System Security Plans (SSP) without supervision
- Ability to produce and manage Plan of Action and Milestones (POA&M) without supervision
- Ability to conduct Risk Analysis and Risk Assessments without supervision
- Ability to produce Security Assessment Reports (SAR) and Risk Assessment Reports (RAR) without supervision
- Experience with SA&A (Security Assessment and Authorization) or C&A processes
- Ability to develop or evaluate Contingency Plans
- Familiarity with FedRAMP
- Familiarity with CSAM
- Familiarity with FISMA
- Familiarity with HP WebInspect
- Familiarity with McAfee Vulnerability Manager
- Familiarity with SCD
What We Do
Business Integra Technology Solutions, Inc. (“BI”), is an award-winning IT government contracting company headquartered in Bethesda, MD with offices worldwide. It ranks on the Inc. 500 list and was recognized by Washington Technology as one of the fastest-growing IT companies in the area. BI is a certified woman-owned business and a certified Minority Business Enterprise (MBE) ranked as CMMI Level 5 for Services and CMMI Level 5 for Development. Our portfolio of certifications also includes AS9100D for the development of aerospace hardware; ISO 9001:2015 (Quality Management Systems); ISO 20000:2011 (IT Service Management Systems); and ISO 27001:2013 (Information Security Management Systems). Expertise: Our core IT competency areas include program and project management, Agile software development, cybersecurity, ICAM, cloud computing, and IT operations and maintenance. We have a special scientific and aeronautic engineering division that supports NASA – including the Hubble Telescope and the International Space Station – and a special mission support division that services many clients including the Department of State and NATO. Our cybersecurity team is on the cutting edge of threat intelligence, tailored threat hunting, penetration testing, and perimeter protection. BI has full competency in integrated security (physical, logical, and cyber) and serves many American facilities OCONUS. Clients: We have supported numerous federal civilian agencies including the Department of State (DOS), the Federal Aviation Administration (FAA), the Department of Labor (DOL), and the Internal Revenue Service (IRS). Our military clients include the Army, the Navy, and the Marines. We also perform work for commercial clients, non-profits, and academic institutions such as M.I.T. We don’t just land contracts: we win re-competes because of the high quality of our work. We’re known by the company we keep.








