Job Requirements
Remote
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization
(A&A) of information systems and all associated cybersecurity policies and procedures.
Key Responsibilities
- Executes DoW/DLA cybersecurity processes to authorize information systems, maintain authorization of information systems, or serves as a Subject Matter Expert (SME) for systems undergoing the authorization process.
- Possess an understanding of how security controls identified in the NIST 800-53 apply to the process of
assessing and authorizing a large organization’s IT infrastructure such as DLA, in which there is a
compilation of large and small enclaves, Cloud Hosted Services, Operational Technology, AIS applications
and outsourced IT processes.
- Determines the residual risk of an identified vulnerability (e.g., non-compliant
security control) and determines the possible ramifications on the system’s current or future authorization.
- Briefs senior management on the progress or results of an information system undergoing the Risk
Management Framework (RMF) process.
Requirements
- Five (5) years of relevant C&A experience; Risk Management Framework (RMF) and
NIST C&A experience; DOD cybersecurity experience
- Experience in assessing security controls and conducting authorization reviews for large,
complex organizations
- Investigative Requirement: Must possess a Moderate Risk, Non-Critical Sensitive, Tier 3
(T3)/NACLC/ANACI
- Clearance: Secret
- 8570/8140: DoD Approved 8570 Baseline Certification: Category IAM Level III - candidate must possess one of the following certifications: CISM, CISSP, GSLC, CCISO
(A&A) of information systems and all associated cybersecurity policies and procedures.
Key Responsibilities
- Executes DoW/DLA cybersecurity processes to authorize information systems, maintain authorization of information systems, or serves as a Subject Matter Expert (SME) for systems undergoing the authorization process.
- Possess an understanding of how security controls identified in the NIST 800-53 apply to the process of
assessing and authorizing a large organization’s IT infrastructure such as DLA, in which there is a
compilation of large and small enclaves, Cloud Hosted Services, Operational Technology, AIS applications
and outsourced IT processes.
- Determines the residual risk of an identified vulnerability (e.g., non-compliant
security control) and determines the possible ramifications on the system’s current or future authorization.
- Briefs senior management on the progress or results of an information system undergoing the Risk
Management Framework (RMF) process.
Requirements
- Five (5) years of relevant C&A experience; Risk Management Framework (RMF) and
NIST C&A experience; DOD cybersecurity experience
- Experience in assessing security controls and conducting authorization reviews for large,
complex organizations
- Investigative Requirement: Must possess a Moderate Risk, Non-Critical Sensitive, Tier 3
(T3)/NACLC/ANACI
- Clearance: Secret
- 8570/8140: DoD Approved 8570 Baseline Certification: Category IAM Level III - candidate must possess one of the following certifications: CISM, CISSP, GSLC, CCISO
group id: 10280020