The Security Operations Lead manages security and information assurance (IA) compliance as it applies to development, engineering, and architectural design standards for all of the Department of State (DOS or Department), Bureau of Consular Affairs' (CA) non-production and production operating environments.
Requirements
- Supports CA/CST's security architecture, while maintaining its scalability and cohesiveness, as well as its ability to adapt to new technologies and new threats.
- Review application/database scripts for security violations
- Review databases for compliant security posture and violations
- Review POA&Ms, and create remediation scripts for IVV testing and deployment
- Review roles and privileges submitted through access approval, keeping with the least privilege theory
- Participate and fulfil the needs of the Authority to Operate (ATO) process, including annual security assessments, boundaries, database security, etc.
- Resolves database-level security issues, such as POA&Ms and Cyber Incidents.
- Ensures that all database system components are operational, secure, accurate, current, and in compliance with DOS technical security foundations.
- Develop and maintain all security documentation for which the security operations team is responsible (e.g. Interconnection Security Agreements (ISA), System Security Plans (SSP), Information System Contingency Plans (ISCP), Privacy Impact Assessments (PIA), etc.).
Benefits
- Medical, Dental & Vision Insurance
- Flexible Spending Accounts
- Short-Term and Long-Term Disability Insurance
- Life Insurance
- Paid Time Off & Holidays
- Earned Bonuses & Awards
- Professional Training Reimbursement
- Paid Parking
- Employee Assistance Program