Perform risk assessments, audit reviews, generate findings reports, and make appropriate recommendations for improvement and track outcomes from those activities for DES reporting requirements.
Develop and formulate comprehensive reports detailing the findings, areas of non-compliance, required POA&Ms (Plan of Action and Milestones), environmental observations, and incident reports.
Review, update, and manage security related audit plans, security plans and risk plan documentation for accuracy and consistency, proactively solves problems.
Evaluate data and formulate comprehensive reports detailing the findings, areas of non-compliance, required action plans, and environmental observations.
Generates incident reports and investigates suspicious network activity.
Preparing audit documentation that supports audit results, drafting and editing audit findings to adhere to the standards and the agency's writing style.
Research agency and industry IT security practices standards, best practices, laws and regulations, and other applicable resources, ensures compliance with standards