
We’re Hiring
PARS Security Control Assessor
Visual Connections, LLC seeking a PARS Security Control Assessor. As a Security Control Assessor, you will be trusted to support the delivery of our cybersecurity solutions and services. In this role, you will be a part of a security control assessment team working on the tasks outlined below:
Duties
Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37).
Plans and conducts security authorization reviews and assurance case development for initial installation of systems and networks.
Reviews authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
Verifies that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
Develops security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
Performs security reviews and identifies security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
Requirements
Bachelor's degree in computer science, electronics engineering or other engineering or technical discipline is required
Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
Knowledge of system and application security threats and vulnerabilities
Knowledge of Personally Identifiable Information (PII), Payment Card Industry (PCI), and Personal Health Information (PHI) data security standards.
Experience with Cybersecurity policy, risk management, and threat mitigation.
Experience with security control assessments within the VA using the NIST Risk Management Framework (RMF) is a plus
Certifications such as SCA and CISA are a plus
Exceptional written and verbal communication skills
Strong planning, organizational, and time management skills
Exceptional analytical and conceptual thinking skills
Ability to work collaboratively with a team of peers
Fulltime remote
Visual Connections, LLC offers a full benefits package including:
Full Medical, Dental, Prescription and Vision health care
11 Paid Holidays annually
Paid time off
Short Term, Long Term Disability and Life Insurance
Employee Assistance Program (EAP)
Training and Development opportunities including professional certification and educational reimbursement
Visual Connections, LLC provides employment opportunities for all employees and applicants in accordance with applicable federal, state and local laws. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
We are a Service-Disabled, Veteran-Owned Small Business; and a Certified Maryland Business Enterprise. We were established in 2007 to provide public and private sector clients with robust web-based applications, Health IT and Portfolio and Program Management services. We have proven ourselves to be valuable partners who can deliver both qualitative and quantitative results to our clients. Our versatile, efficient and experienced team has a stellar record of past performance, working with the Department of Defense (DoD), Department of Health and Human Services (DHHS), Veterans Health Administration (VHA), Centers for Medicare and Medicaid Services (CMS),Centers for Disease Control and Prevention (CDC) and , Blue Cross Blue Shield (BCBS). With an employee base well versed in different disciplines, we are able to deliver high quality customizable solutions.