Job Requirements
Huntsville, AL
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Ampersand Solutions Group (AMPERSAND) has a requirement for a mid- to senior-level System Security Analyst who will perform the duties of a third-party Information System Security Officer (ISSO), responsible for supporting the identification of system vulnerabilities and determining appropriate security controls to mitigate or eliminate risk associated with the uncovered vulnerabilities. The Security Analyst must possess strong knowledge of the process for developing Risk Management Framework (RMF) packages from the beginning through the award of the Authority to Operate (ATO). Additionally, the Security Analyst must have a thorough understanding of the Enterprise Mission Assurance Support Service (eMASS) system and should be well-versed in eMASS management, including entering data, maintaining records, and navigating the system.
SCOPE
The candidate will be responsible for assisting in the development of RMF certification and accreditation documentation, standard operating procedures, and security policies and instructions for both networked and stand-alone systems. The candidate will be responsible for providing accurate technical evaluations of software applications, systems, and networks, documenting the security posture, capabilities, and vulnerabilities against applicable National Institute of Standards and Technology (NIST) 800-53 security controls.
TECHNICAL REQUIREMENTS
System Security Analyst Duties and Responsibilities:
SCOPE
The candidate will be responsible for assisting in the development of RMF certification and accreditation documentation, standard operating procedures, and security policies and instructions for both networked and stand-alone systems. The candidate will be responsible for providing accurate technical evaluations of software applications, systems, and networks, documenting the security posture, capabilities, and vulnerabilities against applicable National Institute of Standards and Technology (NIST) 800-53 security controls.
TECHNICAL REQUIREMENTS
System Security Analyst Duties and Responsibilities:
- Develop security artifacts to support the Information Assurance program, including System Security Plans (SSP), Plan of Action and Milestones (POA&M), System Diagrams, System User Guides, Privileged User Guides, and other documentation as needed.
- Perform self-assessments of systems and networks within the environment, using passive evaluation audit tools such as STIG Viewer, SCAP Compliance Checker (SCC), and active evaluations through ACAS/NESSUS.
- Track enterprise reporting and efficiencies through automatic generation of required security compliance reports, integration of security tools, system documentation, and other artifacts utilizing the Enterprise Mission Assurance Support Service (eMASS).
- Track security updates for Windows and Linux-based operating systems , VMWare-based products, and associated software applications to ensure compliance.
- Periodically conduct a review of system audits, monitor corrective actions until all actions are closed, and identify deficiencies during RMF assessment activities.
group id: 91136341