Requires technical skills to describe threats and vulnerabilities, measure risk, and provide recommendations for control implementation. Execute threat identification, vulnerability identification, control analysis, methods and recommendations, likelihood determination, impact analysis, and risk determination. The deliverable for this task will be a classified Risk Assessment based on the "NIST SP800-30 Risk Management Guide for Information Technology Systems". The personnel for this task will require access to the SIPRNet and the ability to produce, store and transport classified documents. Knowledge of LANs, WANs, VPNs, routers, firewalls, network protocols, and other security and network operations and monitoring, vulnerability analysis, PKI, data encryption, as well as knowledge of physical security. Must have the following: US Citizenship * Bachelor's Degree or equivalent experience plus at least 3 years of directly related technical experience. * Must be certified as CISSP * Experienced in threat identification, vulnerability identification, control analysis, methods and recommendations, likelihood determination, impact analysis, and risk determination. * Demonstrated experience in analytical problem solving of work flows, organization and planning. * Demonstrated experience with IA products and systems * Must posses knowledge of the "NIST SP800-30 Risk Management Guide for Information Technology Systems"
Required 15+ Years with BS or 13+ Years with MS or 10+ Years with PhD