Job Requirements
Santa Rita, GU
Top Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
The Cybersecurity Analyst will provide hands-on cybersecurity support across NAVFAC Marianas Facility-Related Control Systems (FRCS) environments, helping protect the confidentiality, integrity, and availability of systems, networks, and data. The role supports the planning, implementation, documentation, maintenance, and improvement of cybersecurity programs, policies, procedures, and tools.
This position works closely with system owners, independent validators, the Information Systems Security Manager (ISSM), NAVFAC CIO personnel, and other government stakeholders. The analyst will also support cybersecurity incident response as a member of the MAR Cyber Emergency Response Team (CERT), participate in on-call rotations, and independently drive RMF and cybersecurity activities with minimal supervision.
The successful candidate will manage the full Risk Management Framework (RMF) lifecycle, Steps 1–6, in accordance with Department of the Navy and NAVFAC Echelon II guidance. The candidate will be capable of independently driving cybersecurity and RMF activities with minimal supervision, supporting systems throughout the full RMF lifecycle, maintaining Authorities to Operate (ATOs), conducting vulnerability and compliance assessments, and providing continuous monitoring and incident response support.
Essential Duties & Responsibilities:
Execute the end-to-end RMF lifecycle (Steps 1–6) and ensure required artifacts meet DoN and NAVFAC requirements and are properly uploaded and maintained within eMASS.
Support the attainment, maintenance, and tracking of Authorities to Operate (ATOs) for Facility-Related Control Systems.
Facilitate annual security reviews and develop Memorandums for Record associated withsystem baseline changes.
Develop and maintain cybersecurity policies, Standard Operating Procedures (SOPs), and implementation plans aligned with NIST SP 800-53 security control families and NAVFAC/DoN cybersecurity requirements.
Develop and execute a comprehensive vulnerability management strategy.
Perform vulnerability and compliance assessments using approved tools such as ACAS, SCAP, and Evaluate STIG.
Perform manual STIG and Security Requirements Guide (SRG) validations and maintain required checklists.
Generate Security Center and eMASSter reports and ensure vulnerability results are accurately maintained in the Vulnerability Remediation Asset Management (VRAM) database.
Conduct System-Level Continuous Monitoring (SLCM), including recurring vulnerability scanning, security control reviews, audit log analysis, vulnerability remediation/mitigation, and quarterly Plan of Action and Milestones (POA&M) updates.
Provide on-site validation and technical testing support for RMF Step 4 activities.
Coordinate with system owners and independent validators during site assessments and technical evidence collection.
Serve as a technical representative and/or Configuration Management Officer on the Configuration Control Board (CCB) and provide security impact analyses and risk assessments for proposed FRCS changes.
Support cybersecurity incident response operations as a member of the MAR Cyber Emergency Response Team (CERT) and participate in required on-call rotations.
Prepare incident response reports and operational documentation following cybersecurity events.
Provide bi-weekly RMF status reporting to the ISSM and maintain FRCS RMF project records in Maximo and/or eProjects.
Prepare recurring project, cybersecurity, continuous monitoring, and ATO milestone reporting in support of NAVFAC CIO priorities.
Required Qualifications:
U.S. Citizenship is required.
Minimum of five (5) years of Risk Management Framework (RMF) experience.
Minimum of one (1) year of specialized experience supporting Facility-Related Control Systems (FRCS) while performing RMF and cybersecurity engineering activities.
Must be fully qualified in accordance with DoDM 8140.03, Cyber Workforce Work Role 461 – Systems Security Analyst, at the Intermediate or Advanced proficiency level prior to onboarding.
Must possess and maintain an approved cybersecurity certification. Intermediate-level certifications include CCSP, Cloud+, GICSP, GISF, GSEC, or Security+. Advanced certifications identified include RCCE Level 1, CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, or GSNA.
Must maintain required certification status and complete at least 20 hours annually of Continuous Professional Development (CPD), or the minimum required to maintain the applicable commercial certification, whichever is greater.
Demonstrated ability to independently perform technical cybersecurity work with minimal government supervision.
Demonstrated experience developing comprehensive technical reports, cybersecurity policies, procedures, and related security documentation.
Ability to communicate effectively with government personnel, system owners, technical stakeholders, and Information Systems Security Managers.
Ability to communicate fluently and effectively in English, both verbally and in writing.
Ability to work in mechanical and facility environments and lift or move equipment weighing up to 25 pounds.
Security clearance requirements:
Must possess an active Tier 5 (T5) Top Secret security clearance or be able to obtain an interim T5 clearance prior to onboarding and the start of performance.
The required security clearance must be maintained in active and good standing throughout the period of contract performance.
Personnel must comply with all applicable DoD, Department of the Navy, NAVFAC, and site-specific information security and safeguarding requirements
This position works closely with system owners, independent validators, the Information Systems Security Manager (ISSM), NAVFAC CIO personnel, and other government stakeholders. The analyst will also support cybersecurity incident response as a member of the MAR Cyber Emergency Response Team (CERT), participate in on-call rotations, and independently drive RMF and cybersecurity activities with minimal supervision.
The successful candidate will manage the full Risk Management Framework (RMF) lifecycle, Steps 1–6, in accordance with Department of the Navy and NAVFAC Echelon II guidance. The candidate will be capable of independently driving cybersecurity and RMF activities with minimal supervision, supporting systems throughout the full RMF lifecycle, maintaining Authorities to Operate (ATOs), conducting vulnerability and compliance assessments, and providing continuous monitoring and incident response support.
Essential Duties & Responsibilities:
Execute the end-to-end RMF lifecycle (Steps 1–6) and ensure required artifacts meet DoN and NAVFAC requirements and are properly uploaded and maintained within eMASS.
Support the attainment, maintenance, and tracking of Authorities to Operate (ATOs) for Facility-Related Control Systems.
Facilitate annual security reviews and develop Memorandums for Record associated withsystem baseline changes.
Develop and maintain cybersecurity policies, Standard Operating Procedures (SOPs), and implementation plans aligned with NIST SP 800-53 security control families and NAVFAC/DoN cybersecurity requirements.
Develop and execute a comprehensive vulnerability management strategy.
Perform vulnerability and compliance assessments using approved tools such as ACAS, SCAP, and Evaluate STIG.
Perform manual STIG and Security Requirements Guide (SRG) validations and maintain required checklists.
Generate Security Center and eMASSter reports and ensure vulnerability results are accurately maintained in the Vulnerability Remediation Asset Management (VRAM) database.
Conduct System-Level Continuous Monitoring (SLCM), including recurring vulnerability scanning, security control reviews, audit log analysis, vulnerability remediation/mitigation, and quarterly Plan of Action and Milestones (POA&M) updates.
Provide on-site validation and technical testing support for RMF Step 4 activities.
Coordinate with system owners and independent validators during site assessments and technical evidence collection.
Serve as a technical representative and/or Configuration Management Officer on the Configuration Control Board (CCB) and provide security impact analyses and risk assessments for proposed FRCS changes.
Support cybersecurity incident response operations as a member of the MAR Cyber Emergency Response Team (CERT) and participate in required on-call rotations.
Prepare incident response reports and operational documentation following cybersecurity events.
Provide bi-weekly RMF status reporting to the ISSM and maintain FRCS RMF project records in Maximo and/or eProjects.
Prepare recurring project, cybersecurity, continuous monitoring, and ATO milestone reporting in support of NAVFAC CIO priorities.
Required Qualifications:
U.S. Citizenship is required.
Minimum of five (5) years of Risk Management Framework (RMF) experience.
Minimum of one (1) year of specialized experience supporting Facility-Related Control Systems (FRCS) while performing RMF and cybersecurity engineering activities.
Must be fully qualified in accordance with DoDM 8140.03, Cyber Workforce Work Role 461 – Systems Security Analyst, at the Intermediate or Advanced proficiency level prior to onboarding.
Must possess and maintain an approved cybersecurity certification. Intermediate-level certifications include CCSP, Cloud+, GICSP, GISF, GSEC, or Security+. Advanced certifications identified include RCCE Level 1, CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, or GSNA.
Must maintain required certification status and complete at least 20 hours annually of Continuous Professional Development (CPD), or the minimum required to maintain the applicable commercial certification, whichever is greater.
Demonstrated ability to independently perform technical cybersecurity work with minimal government supervision.
Demonstrated experience developing comprehensive technical reports, cybersecurity policies, procedures, and related security documentation.
Ability to communicate effectively with government personnel, system owners, technical stakeholders, and Information Systems Security Managers.
Ability to communicate fluently and effectively in English, both verbally and in writing.
Ability to work in mechanical and facility environments and lift or move equipment weighing up to 25 pounds.
Security clearance requirements:
Must possess an active Tier 5 (T5) Top Secret security clearance or be able to obtain an interim T5 clearance prior to onboarding and the start of performance.
The required security clearance must be maintained in active and good standing throughout the period of contract performance.
Personnel must comply with all applicable DoD, Department of the Navy, NAVFAC, and site-specific information security and safeguarding requirements
group id: 91142803