What are the responsibilities and job description for the SVVP Security Development Consultant position at V Group Inc.?
End Client: New York City Department of Social Services
Job Title: SVVP Security Development Consultant
Duration: 36 - 60 Months
Start Date: ASAP
Location: 505 Clermont Ave, 3rd Floor, Brooklyn NY 11238
Position Type: Contract
Interview Type: Webcam
PROJECT NAME: The Data Center Colocation and Migration
Project Overview : NYC DSS is undertaking a large-scale Data Center Co-location and Migration Project to modernize its IT infrastructure. Approximately 90% of current data center infrastructure is reaching End-of-Life (EOL) / End-of-Support (EOS)Migration from 15 MetroTech Center to 11 MetroTech (Brooklyn, NY) Consolidation of multiple data centers into a single co-location facility
Objective:
- Responsible for developing and executing the Security Verification and Validation Program (SVVP).
Scope:
- Leads the architecture and design of SVVP across the organization. Sets foundational processes, tools, and frameworks to ensure all future security controls can be validated consistently.
Development of SVVP Framework:
- Develop and structure the SVVP framework for evaluating security controls across the full scope of the migration.
- Create guidelines for the verification and validation process to ensure security measures align with City-wide, State, and Federal standards.
- Identify all agency critical data assets, categorize data sensitivity levels for all the agency applications.
Application of SOC 2 Readiness Criteria:
- Incorporate SOC 2 trust service criteria (security, availability, confidentiality, processing integrity, privacy) into the SVVP to ensure compliance during migration.
- Design and develop action plans to address SOC 2 gaps, ensuring adherence to security standards before, during, and after migration.
Security Protocols and Mitigation Strategy:
- Develop protocols for evaluating network security, data protection, access controls, and incident response measures.
- Identify vulnerabilities and design mitigation strategies to address risks during migration phases.
Launch and Execution of Validation Plan:
- Launch the SVVP execution phase, ensuring that security validation occurs at each migration stage.
- Activate validation checkpoints across planning, design, implementation, testing, and operational readiness.
Required Skills :
- 5 years of experience in Development of Security Patterns and Frameworks
- 7 years of Cybersecurity experience
- 7 years of hands-on security control validation/testing/design/operational readiness
- 7 years of experience supporting infrastructure and data center migration
- 7 years of experience conducting vulnerability assessments
- 7 years of experience documenting validation procedures
- 7 years of experience supporting SOC 2 Type audits