Location: Sacramento, CA
Duration: 1+ Year
Required Qualifications
Education
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Security, Risk Management, or related discipline, or equivalent relevant professional experience.
Professional Experience
5+ years of relevant information security, security assessment, privacy assessment, audit, compliance, or cybersecurity experience.
Demonstrated experience performing security-control assessments.
Experience assessing cloud-based systems and environments.
Experience working with sensitive or confidential information.
Experience with control testing and evidence validation.
Experience identifying security weaknesses and vulnerabilities.
Experience developing security findings and remediation recommendations.
Experience with security assessment documentation and reporting.
Experience supporting regulated environments preferred.
Experience with healthcare, health exchange, public-sector, or other highly regulated environments desirable.
Required Technical Knowledge
The consultant should demonstrate working knowledge of:
ARC-AMPE
NIST SP 800-53 Rev. 5
Security control assessment
Privacy control assessment
Cloud security
Security architecture
Network security
Endpoint security
IAM
Vulnerability management
Application security
Security monitoring
Incident response
Data protection
DLP
Encryption
Access controls
Risk assessment
Security findings
Corrective-action planning
Preferred Certifications:
CISA- Security assessment and audit
CISSP- Broad cybersecurity expertise
CAP- Security authorization and assessment
CGRC- Governance, risk and compliance
Cloud Security Certification- Cloud assessment capability