Information Security Specialist 2West Sacramento, CA36+ monthsMandatory Qualifications:Minimum of five (5) years of experience applying security policies, standards, testing, modification and implementation.At least three (3) years of that experience must be in information security analysis.Bachelor’s Degree in an IT-related or Engineering field. Additional qualifying experience may be substituted for the required education on a year-for-year basis.Minimum of one (1) year of experience reviewing compliance with HIPAA security standards and alignment with Health Care Industry Security Approaches pursuant to Cybersecurity Act of 2015, Section 405(d).Minimum of one (1) year of experience reviewing compliance with the most current NIST SP 800-53, “Security and Privacy Controls for Federal Information Systems and Organizations” and/or NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”.Minimum of one (1) year of experience reviewing compliance with the Open Web Application Security Project (OWASP).Minimum of one (1) year of experience assessing AWS and Azure systems and environments.Desirable Qualifications:The MES assessor should possess a combination of privacy and security experience and relevant assessment certifications. Examples of acceptable privacy and security experience may include, but are not limited to:Reviewing compliance with the Federal Information Security Management Act.Participating in the Federal Risk and Authorization Management Program (FedRAMP)-certified third-party assessment organization.Experience assessing the implementation of the Center for Internet Security (CIS) benchmarks.The assessor organization should have relevant security and privacy accreditations, and the assessor’s team leads should have relevant security and privacy certifications.
Examples of relevant auditing certifications are:Certified Information Privacy ProfessionalCertified Information Privacy ManagerCertified Information Systems Security ProfessionalFellow of Information PrivacyHealthCare Information Security and Privacy PractitionerCertified Internal AuditorCertified Risk Management ProfessionalCertified Information Systems AuditorCertified Government Auditing ProfessionalCertified Expert HIPAA ProfessionalAWS Certified Cloud PractitionerAWS Certified Security SpecialistMore than one (1) year experience reviewing compliance with the following:HIPAA security standards and alignment with Health Care Industry Security Approaches pursuant to Cybersecurity Act of 2015, Section 405(d).NIST SP 800-53, “Security and Privacy Controls for Federal Information Systems and Organizations” (most current) and/or NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”.OWASP.More than one (1) year assessing AWS and Azure systems and environments.Education: Bachelor’s Degree in an IT-related or Engineering field. Additional qualifying experience may be substituted for the required education on a year-for-year basis.RegardsNaresh DamagallaWest Advanced Technologies, Inc