GovCIO is looking for a Software Assurance Cybersecurity Specialist (Zero Trust/AI) with a TS/SCI clearance in Washington, DC. This is a hybrid schedule, 2-3 days onsite weekly.
Responsibilities
Function as the Supply Chain Risk Management (SCRM) point of contact
Develop SCRM implementation roadmaps with built-in Zero Trust and Enterprise Audit related actions included
Conduct software source code reviews using automated tools and manual processes and provide recommended changes for mitigating any anticipated vulnerabilities to DHS IE system owners
Develop and implement plans to include continuous monitoring within SCRM that include Zero Trust security solutions
Work to infuse software assurance practices and Zero Trust design principles across all pillars in a Zero Trust model (e.g. Users, Devices, Networks, Applications, Data, etc)
Produce and deliver software assurance reports on individual and enterprise software and supply chain actions
Identify and address security implications during software acceptance activities, including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing
Identify, track and monitor AI generated code and associated vulnerabilities
Work with system owners to secure systems within built-in AI code
Research and develop reports on tools to secure AI based code and systems
Apply defense functions (e.g., encryption, access control, identity management) to reduce exploitation opportunities due to potential supply chain vulnerabilities
Document technical processes and procedures and provide revisions of support documents as necessary
Develop, design, and maintain dashboards and analytics with CyberArk and integrate with existing governance, risk, and compliance (GRC) tools (currently Archer) to collect, refine, and prepare data for analytics and visualization
Requirements
Bachelor's with 8+ years (or commensurate experience) of software assurance experience
Minimum of 8 years of experience in software assurance, engineering, implementation, and integrations
Hands on knowledge of Zero Trust technologies covering IAM, User devices, software, and Encryption
Knowledge of AI tools such as Chatgpt
Experience working with cloud-based network infrastructures such as AWS or Azure or Google Cloud