Ir al contenido
Aramis:Insight

Roles

Evaluador CMMC

Determina, con base en evidencia, si una organización cumple con CMMC y lo hace constar en una forma en la que el Departamento pueda confiar.

Áreas de competencia

  • Cyber Resiliency (43)
  • Cryptography (36)
  • DevSecOps (32)
  • Artificial Intelligence (AI) Security (24)
Mídase contra este rol

Plantillas de descripción de puesto

Tres borradores listos para editar, pensados para gerentes de contratación y reclutadores: copie uno, reemplace las líneas entre corchetes y publíquelo. Las responsabilidades y los requisitos provienen de los mismos enunciados NICE contra los que se mide este rol.

Los enunciados se muestran en su redacción oficial del marco NICE, que se mantiene en inglés.

Evaluador CMMC: Junior

Buscamos un Evaluador CMMC junior. Trabajará con la guía de colegas senior, se hará cargo de tareas bien delimitadas y crecerá hasta cubrir el rol completo. Determina, con base en evidencia, si una organización cumple con CMMC y lo hace constar en una forma en la que el Departamento pueda confiar.

[Empresa] se dedica a [lo que hacen]. La función de seguridad es [tamaño y estructura: p. ej., un equipo de cinco personas que reporta al CTO]. Reemplace este párrafo con el suyo.

Responsabilidades

  • Assess the effectiveness of security controls
  • Scope analysis reports to various audiences that accounts for data sharing classification restrictions
  • Perform security reviews
  • Plan security authorization reviews for system and network installations
  • Conduct security authorization reviews for system and network installations
  • Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
  • Conduct technology program and project audits
  • Document software, network, and system deviations from implemented security postures
  • Trabajar en pareja con colegas senior y crecer mediante retroalimentación estructurada.
  • Documentar su trabajo para que el equipo aprenda con usted.

Conocimientos requeridos

  • Security Assessment and Authorization (SA&A) processes
  • Risk Management Framework (RMF) requirements
  • Supply chain risk management principles and practices
  • Process maturity models and frameworks
  • The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
  • Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
  • The C3PAO's quality assurance review, results submission to the CMMC instantiation of eMASS, and the organization's appeal path
  • The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped

Habilidades

  • Evaluating regulations
  • Creating technical documentation
  • Preparing reports
  • Auditing technical systems
  • Reviewing logs

Cómo usar esta plantilla

Copie el borrador, reemplace cada línea entre corchetes, elimine los enunciados que no apliquen a su vacante y agregue rango de compensación y política de ubicación. Las listas de enunciados provienen del marco NICE v2.2.0 del NIST, de modo que los candidatos pueden evaluarse contra los mismos enunciados con Aramis:Insight.

Evaluador CMMC: Nivel medio

Buscamos un Evaluador CMMC. Será responsable de este trabajo en el día a día, colaborará con toda la función de seguridad y elevará el estándar de cómo se hace. Determina, con base en evidencia, si una organización cumple con CMMC y lo hace constar en una forma en la que el Departamento pueda confiar.

[Empresa] se dedica a [lo que hacen]. La función de seguridad es [tamaño y estructura: p. ej., un equipo de cinco personas que reporta al CTO]. Reemplace este párrafo con el suyo.

Responsabilidades

  • Assess the effectiveness of security controls
  • Scope analysis reports to various audiences that accounts for data sharing classification restrictions
  • Perform security reviews
  • Plan security authorization reviews for system and network installations
  • Conduct security authorization reviews for system and network installations
  • Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
  • Conduct technology program and project audits
  • Document software, network, and system deviations from implemented security postures
  • Determine if procurement activities sufficiently address supply chain risks
  • Determine if vulnerability remediation plans are in place
  • Develop independent cybersecurity audit processes for application software, networks, and systems
  • Implement independent cybersecurity audit processes for application software, networks, and systems

Conocimientos requeridos

  • Security Assessment and Authorization (SA&A) processes
  • Risk Management Framework (RMF) requirements
  • Supply chain risk management principles and practices
  • Process maturity models and frameworks
  • The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
  • Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
  • The C3PAO's quality assurance review, results submission to the CMMC instantiation of eMASS, and the organization's appeal path
  • The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped
  • Conditional CMMC status, the 180-day closeout window, the closeout assessment, and the consequence of missing it
  • The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
  • The CMMC ecosystem's organizations and individual credentials, their authorities, and their limits (Cyber AB, CAICO, C3PAO, RPO, DIBCAC; RP, CCP, CCA, Lead CCA, CCI)
  • The difference between NIST SP 800-171 Rev 2 as pinned by the DoD class deviation and Rev 3 as published, and why an assessment is conducted against the pinned revision

Habilidades

  • Evaluating regulations
  • Creating technical documentation
  • Preparing reports
  • Auditing technical systems
  • Reviewing logs
  • Conducting system reviews
  • Assessing security controls
  • Performing risk assessments

Cómo usar esta plantilla

Copie el borrador, reemplace cada línea entre corchetes, elimine los enunciados que no apliquen a su vacante y agregue rango de compensación y política de ubicación. Las listas de enunciados provienen del marco NICE v2.2.0 del NIST, de modo que los candidatos pueden evaluarse contra los mismos enunciados con Aramis:Insight.

Evaluador CMMC: Senior

Buscamos un Evaluador CMMC senior. Definirá la dirección de este trabajo, guiará a otros en él y responderá por sus resultados a nivel organizacional. Determina, con base en evidencia, si una organización cumple con CMMC y lo hace constar en una forma en la que el Departamento pueda confiar.

[Empresa] se dedica a [lo que hacen]. La función de seguridad es [tamaño y estructura: p. ej., un equipo de cinco personas que reporta al CTO]. Reemplace este párrafo con el suyo.

Responsabilidades

  • Assess the effectiveness of security controls
  • Scope analysis reports to various audiences that accounts for data sharing classification restrictions
  • Perform security reviews
  • Plan security authorization reviews for system and network installations
  • Conduct security authorization reviews for system and network installations
  • Determine if authorization and assurance documents identify an acceptable level of risk for software applications, systems, and networks
  • Conduct technology program and project audits
  • Document software, network, and system deviations from implemented security postures
  • Determine if procurement activities sufficiently address supply chain risks
  • Determine if vulnerability remediation plans are in place
  • Develop independent cybersecurity audit processes for application software, networks, and systems
  • Implement independent cybersecurity audit processes for application software, networks, and systems
  • Determine if cybersecurity requirements included in contracts are delivered
  • Design and execute a control test that distinguishes a design deficiency from an operating-effectiveness deficiency
  • Construct an audit workpaper documenting population, sample selection, test steps performed, and results
  • Write an audit finding that states condition, criteria, cause, and effect with an actionable recommendation
  • Guiar a los miembros junior del equipo y revisar su trabajo.
  • Representar esta función ante la dirección y ante auditores o clientes.
  • Definir estándares, seleccionar herramientas y ser dueño de la hoja de ruta de esta área.

Conocimientos requeridos

  • Security Assessment and Authorization (SA&A) processes
  • Risk Management Framework (RMF) requirements
  • Supply chain risk management principles and practices
  • Process maturity models and frameworks
  • The four phases of the CMMC Assessment Process (plan and prepare; conduct; report; close out) and the deliverables of each
  • Which assessment activities a CCP may perform on a team and which are reserved to a CCA and to the Lead CCA
  • The C3PAO's quality assurance review, results submission to the CMMC instantiation of eMASS, and the organization's appeal path
  • The readiness review a C3PAO performs before accepting an organization for assessment and the conditions under which an assessment is stopped
  • Conditional CMMC status, the 180-day closeout window, the closeout assessment, and the consequence of missing it
  • The CMMC Program's three levels, the assessment type attached to each (self-assessment, C3PAO certification, DIBCAC assessment), and the status and validity period each produces
  • The CMMC ecosystem's organizations and individual credentials, their authorities, and their limits (Cyber AB, CAICO, C3PAO, RPO, DIBCAC; RP, CCP, CCA, Lead CCA, CCI)
  • The difference between NIST SP 800-171 Rev 2 as pinned by the DoD class deviation and Rev 3 as published, and why an assessment is conducted against the pinned revision
  • The assessment objectives of NIST SP 800-171A and how each decomposes its requirement
  • The examine, interview, and test assessment methods, and the depth and coverage each provides

Habilidades

  • Evaluating regulations
  • Creating technical documentation
  • Preparing reports
  • Auditing technical systems
  • Reviewing logs
  • Conducting system reviews
  • Assessing security controls
  • Performing risk assessments
  • Producing after-action reports
  • Conducting test events

Cómo usar esta plantilla

Copie el borrador, reemplace cada línea entre corchetes, elimine los enunciados que no apliquen a su vacante y agregue rango de compensación y política de ubicación. Las listas de enunciados provienen del marco NICE v2.2.0 del NIST, de modo que los candidatos pueden evaluarse contra los mismos enunciados con Aramis:Insight.

Roles relacionados

Roles que comparten el trabajo o la etapa profesional de este. Cada uno enlaza a sus propios enunciados, preguntas de ejemplo y plantillas de descripción de puesto.