Job Description
Job Description
Job Description
Salary:
Responsibilities:
- Support the Information System Security Manager (ISSM) and Program Manager (PM)/Information System Owner (ISO) in developing project requirements and plans to ensure project success, and will work collaboratively with other ISSOs/ISSEs and IT SMEs to conduct analysis/mitigation/remediation/monitoring, ensuring compliance with NIST/CNSS guidance
- Provide Risk Management Framework (RMF) products that document the information system's adherence to the security controls applied.
- Monitor, coordinate, and conduct System Security evaluations, audits, and reviews; coordinate and direct Command Information Assurance Vulnerability Management (IAVM) and Computer Task Order (CTO) Programs.
- Ensures the appropriate operational security posture is maintained for specific information systems to include Wide Area Networks (WANs), Local Area Networks (LANs), Cross Domain Solutions (CDSs), and standalone; developing and updating system security plans; managing and controlling changes to specific systems and assessing the security impact of those changes; incident handling; and development of information system security documentation, policies, and procedures.
- Report compliance and metrics for information systems identified by stakeholders.
- Support the generation and review of Security Technical Implementation Guide (STIG) checklists, Nessus scans, and SCAP results to effectively determine risk
- Assist the Program create and maintain Plan of Action and Milestone (POA&M) items via eMass
- Monitor and report POA&M remediation activities.
- Ensure traceability of all vulnerabilities from raw assessment results to approved POA&M items
- Conduct vulnerability and risk analysis in support of residual risk determination
- Develop and support the continuous monitoring requirements via the Information System Continuous Monitoring (ISCM) plan
- Coordinate with operations and maintenance (O&M) teams to drive compliance with security controls and requirements.
- Serve as a Point of Contact for cyber security questions.
Qualifications:
- A bachelor’s degree with at least ten (10) years of related experience supporting the DoD
- Five (5) years of IT work experience with a preference for cybersecurity experience.
- Prior experience in information security/information assurance roles in may be substituted for education requirements (e.g., examples of experience with implementing and managing FISMA, FedRAMP, DoDI 8500.2, HIPAA, or PCI requirements)
- DoD 8570 IAT Level II and/or IAT Level III (i.e., CISSP) certification
- Experience with NIST SP 800-53, Risk Management Framework (RMF), and security assessment tools
Clearance:
- Active Secret with the ability to upgrade to a Top-Secret
Place of Performance:
- Hybrid/ Remote; Hanover, MD
remote work
Job Tags
Work experience placement, Local area, Remote job, Work alone,