DIMONDALE, MI, USA
3 days ago
IT Security Auditor
Job Seekers, Please send resumes to resumes@hireitpeople.com Short Description:  This position functions as a team member, reviewing the FedRAMP requirements and determining the process for collecting and evaluating the current SOM policies, processes and procedures, enabling the creation of the required FedRAMP documentation.
Complete Description:  This position will work on the CTO’s team to develop, enhance and maintain documentation required for the FedRAMP certification and continuous monitoring process.  This individual will be working with Infrastructure and Operation’s (I & O) Audit and Compliance unit to review and interpret FedRAMP controls, enhance existing—and develop new—standards, policies, and procedures, that meet FedRAMP program requirements.  This process includes the collection all information needed to achieve initial accreditation, as well as continuous maintenance of required documentation, ensuring the information remains current and is aligned with both the SOM cloud environment, and FedRAMP program.  This will include but is not limited to researching and reviewing, establishing best practices, writing documentation and other manuals and materials, and outlining roles and responsibilities required for the broader FedRAMP readiness process.
This individual will be working with DTMB technical staff throughout I & O, Cyber Security, Enterprise Architecture and other technical teams, to transfer their systems drawings, runbooks and technical documents into FedRAMP appropriate formats.  Overseeing the writing, editing, publishing and distribution of FedRAMP specific audit documents, documenting compliance processes, audit team roles and responsibilities, and audit policies needed to operationalize the FedRAMP continuous monitoring documenting compliance processes, audit team roles and responsibilities, and audit policies needed to operationalize the FedRAMP continuous monitoring. Ensuring timely completion and consistent formatting of these documents will be a primary function of the position.  The resource will be required to participate in weekly technical workshops, project team meetings and 1x1 meetings with team members.
Resources are required to familiarize themselves with both the FedRAMP program, and the types of documentation required for FedRAMP readiness before starting the work at State office. This overview is critical to the candidate’s ability to establish realistic expectations of the scope and type of documentation and work which accompanies the FedRAMP accreditation process. 

SkillRequired / DesiredAmountof ExperienceExperience with performing IT security auditsRequired15YearsExperience in regulatory compliance auditsRequired10YearsAdvanced knowledge of security standards and regulatory compliance auditingRequired10YearsExperience in technical writing for IT Infrastructure projects and programsRequired8YearsAdvance knowledge and understanding of Cloud InfrastructureRequired8YearsAdvanced knowledge of NIST Special Publication 800-53 R4 and all NIST family replies, particularly those pertaining to continuous monitoringRequired8YearsCapabilities in teaching new concepts to individuals that have limited familiarity with the subject matterRequired8YearsCapabilities of reading and analyzing technical and architectural Visio drawings to produce written documentation in support of the SSPRequired2YearsFamiliarity with typical FISMA and FedRAMP appendicesDesired2YearsWorking knowledge of System Security Plans for FISMA or FedRAMPDesired2Years



Confirm your E-mail: Send Email