Job Description
About Fortreum
Fortreum is a cybersecurity advisory and assessment consulting firm that specializes in solving compliance-related hurdles for both Commercial and Federal customers. We are a startup organization that has a simple mission – enable our customers with the right tools and insight, business understanding, and capabilities to sell their products or services in regulated markets. To do this, we focus on 4 core values:
1. Quality matters most
2. Customer-driven mindset
3. Autonomy to do your job
4. Personal accountability/stewardship
While we may be small, we truly are experts in what we do, and it shows in the quality of the work we perform for our customers. You will get to work with some of the largest organizations in the world, who just happen to be clients of ours. We are growing rapidly and are looking for an Analyst to support our team.
The Opportunity
On our team, you will have the opportunity to work with the best and brightest in the field. Fortreum team members have supported the biggest cloud providers in the world, and you will have the opportunity to learn from the best. We are growing rapidly and are looking for candidates with a background in performing security assessments in support of FedRAMP and NIST-based frameworks to support our growing customer base.
Key Responsibilities
This role will specialize in FedRAMP, HIPAA, and other NIST-based assessment activities. Specifically, you would:
-Work closely with all members of the team supporting one or all of the following work activities:
· Developing security assessment plans (SAPs)
· Conducting interviews of key stakeholders and technical personnel
· Performing technical tests alongside security engineers
· Recording meeting minutes and maintain work papers
· Performing vulnerability scans of operating systems, network devices, web applications, and databases
· Developing security assessment reports (SARs)
-Maintain a consistent writing style and approach to documenting the results of the security assessment
-Collaborate with delivery team members to drive customer satisfaction and meet project deliverables
-Ensure quality products and services are delivered on time and within allotted hours
-Establish and maintain positive collaborative relationships with clients and stakeholders
-Continuous professional development in pursuing industry specific certifications
-Consistently work to improve assessment interviewing techniques to establish efficiencies in gathering required information
-Prepare deliverables and conduct peer-review of team member’s deliverables
-Perform project outbriefs with clients to notify them of the outcome of their compliance activities
-Manage priorities, tasks, and assigned hours on projects to achieve delivery utilization targets
This is a customer facing role. You may be required to travel to client locations and deliver professional services when needed.
Basic Qualifications
-Bachelor’s Degree or equivalent job experience
-Proficient in Microsoft 365 product suite
-Basic knowledge of NIST SP 800-53 framework
-Basic understanding of cloud infrastructure services
-An interest in cloud security and cyber security domains
Preferred Skills
-Ability to quickly take on new technologies and concepts
-Ability to manage multiple priorities simultaneously
-Proven analytical and problem-solving skills
-Ability to develop and maintain strong relationships with team members and clients
-Comfortable supporting fast-paced team environments
-Advanced technical certifications, such as:
· AWS solutions architect
· Google cloud engineer
· Microsoft solutions architect
-Ready to have some fun!
** Position only open to US Citizens due to contractual requirements
**Ability to obtain and maintain a US Security Clearance if needed.
What Fortreum Offers
We offer a competitive compensation package, where you will be rewarded based on your performance/outcomes and recognized for the value you bring to our business. You will be a part of something special as we continue to grow. The founders have a proven track record of successful company acquisitions/exit of both small and mid-market cybersecurity organizations. Our benefits package includes medical insurance, dental insurance, vision insurance, 401(k), short-term disability, long-term disability, AD&D, flex time off, annual bonuses, training stipends, certification reimbursements, and eleven paid holidays.