drjobs Cybersecurity GRC Engineer ONSITE

Cybersecurity GRC Engineer ONSITE

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Dallas - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Work Location: ONSITE Dallas TX

Engineer GRC & Assessments (ANSP Program)

FOCUS
Ensure secure aircraft ground and communications systems relied upon for our ANSP Program with concentrated attention towards risk governance vulnerability management policies and standards.

RESPONSIBILITIES
Develop and implement security policies and standards ensuring compliance with industry regulations and best practices.
Conduct risk assessments and vulnerability assessments to identify1 and mitigate security risks.
Manage the vulnerability management program including vulnerability scanning penetration testing and remediation.
Develop and deliver security awareness training programs.
Collaborate with stakeholders to integrate security considerations into the design and development of new aviation systems.
Stay informed about emerging threats and vulnerabilities in the aviation industry.

TOP SKILLS:

Minimum 3 years handson experience on below stack:

1. Risk Management Frameworks: (e.g. NIST RMF NIST CSF ISO 27005)
2. Risk Assessment Methodologies: (e.g. NIST 80030 Threat Modeling)
3. GRC Platforms: (e.g. ServiceNow GRC RSA Archer)
4. Vulnerability Management Tools: (e.g. Tenable Nessus Tanium)

SKILLS:
Cybersecurity Risk & Governance Expertise: Requires 35 years of progressive cybersecurity engineering experience with a deep understanding of risk management frameworks (NIST SP 80037 ISO 27005) governance principles vulnerability management and security policy development.
Risk Assessment & Mitigation: Proven experience conducting risk assessments (NIST 80030 NIST CSF) identifying vulnerabilities analyzing threats and developing effective mitigation strategies.
Vulnerability Management Program Expertise: Expertise in vulnerability management tools and processes including vulnerability scanning penetration testing coordination vulnerability prioritization and remediation tracking.
Policy & Standard Development & Implementation: Strong ability to develop document and implement security policies standards and procedures that align with industry best practices regulatory requirements and risk tolerance
Communication & Stakeholder Collaboration: Excellent communication (written and verbal) and interpersonal skills to effectively communicate security risks governance strategies and policy recommendations to diverse stakeholders including technical teams management and external partners.

PREFERRED CERTIFICATIONS:
CISSP (Certified Information Systems Security Professional)
CISM (Certified Information Security Manager)
CISA (Certified Information Systems Auditor)
CRISC (Certified in Risk and Information Systems Control)
CompTIA Security

TOOLS AND TECHNOLOGIES:

Risk Management Frameworks: (e.g. NIST RMF NIST CSF ISO 27005)
Risk Assessment Methodologies: (e.g. NIST 80030 Threat Modeling)
GRC Platforms: (e.g. ServiceNow GRC RSA Archer)
Vulnerability Management Tools: (e.g. Tenable Nessus Tanium)
Penetration Testing Understanding: (Familiarity with tools & methodologies for report interpretation)
Policy & Collaboration Tools: (e.g. SharePoint Microsoft Teams Policy Management Platforms)

Required Skills : Network Security

Basic Qualification :

Additional Skills :

Background Check : No

Drug Screen : No

Employment Type

Full Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.