Job Requirements
Jbsa Lackland, TX
Top Secret/SCI Polygraph Unspecified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Information Assurance/ACAS Engineer – TS/SCI Clearance Required – JBSA Lackland - San Antonio, TX
Job Description
IPSecure is seeking an experienced Information Assurance (IA)/Risk Management Framework Analyst to support Department of Defense and U.S. Air Force cybersecurity operations. The successful candidate will have hands-on experience executing the Risk Management Framework (RMF) and supporting systems throughout the Assessment and Authorization (A&A) lifecycle.
The ideal candidate will be highly proficient with Assured Compliance Assessment Solution (ACAS) and experienced in vulnerability management, security control implementation and assessment, remediation tracking, and maintaining cybersecurity authorization documentation.
Job Responsibilities
Basic Qualifications
Security Clearance: Active TS/SCI
Education: Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Engineering, or related discipline. Equivalent experience may be substituted.
Certification: Candidate must meet applicable DoD 8140 cybersecurity workforce qualification requirements for the assigned position.
Experience:
Preferred Qualifications
Certifications: CISSP, GSLC, GIAC certifications or other applicable DoD 8140 qualifications, or CCSP certification
Benefits
Medical, Dental, Vision, Unlimited Vacation, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid Legal Plan and Identity Protection Plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.
EEOC Statement
IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Job Description
IPSecure is seeking an experienced Information Assurance (IA)/Risk Management Framework Analyst to support Department of Defense and U.S. Air Force cybersecurity operations. The successful candidate will have hands-on experience executing the Risk Management Framework (RMF) and supporting systems throughout the Assessment and Authorization (A&A) lifecycle.
The ideal candidate will be highly proficient with Assured Compliance Assessment Solution (ACAS) and experienced in vulnerability management, security control implementation and assessment, remediation tracking, and maintaining cybersecurity authorization documentation.
Job Responsibilities
- Execute and support the DoD Risk Management Framework (RMF) process throughout the system authorization lifecycle.
- Develop, review, and maintain RMF and Assessment & Authorization documentation and artifacts.
- Support the development and maintenance of System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Risk Assessment Reports, and supporting evidence.
- Implement, assess, and document applicable NIST SP 800-53 security controls.
- Perform continuous monitoring activities to maintain system cybersecurity posture and authorization.
- Operate and maintain ACAS, including Nessus scanners, Security Center/Tenable.sc, repositories, scan zones, policies, and credentials as applicable.
- Configure and execute authenticated and unauthenticated vulnerability scans across Windows, Linux, network devices, and other supported infrastructure.
- Analyze ACAS vulnerability scan results to identify vulnerabilities, configuration deficiencies, false positives, and remediation requirements.
- Work with system administrators, network engineers, and system owners to develop and track vulnerability remediation activities.
- Review vulnerability findings and assist with determining operational and mission risk.
- Track remediation activities and validate corrective actions through rescanning and supporting evidence.
- Support STIG/SRG compliance, security configuration assessments, and vulnerability management activities.
- Review and respond to applicable cybersecurity directives, vulnerability notifications, and compliance requirements.
- Prepare cybersecurity documentation and evidence for security control assessments, authorization decisions, inspections, and audits.
- Coordinate with ISSM, Security Control Assessors (SCAs), system owners, engineers, and government cybersecurity personnel.
- Maintain accurate cybersecurity records and provide status reporting on vulnerabilities, POA&Ms, compliance, and authorization activities.
Basic Qualifications
Security Clearance: Active TS/SCI
Education: Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Engineering, or related discipline. Equivalent experience may be substituted.
Certification: Candidate must meet applicable DoD 8140 cybersecurity workforce qualification requirements for the assigned position.
Experience:
- 3+ years of Information Assurance, cybersecurity, or RMF experience supporting DoD or federal information systems.
- Demonstrated hands-on experience with the DoD Risk Management Framework (RMF).
- Proven working knowledge of NIST SP 800-53 security controls and RMF documentation requirements.
- Proficiency with ACAS/Tenable, including vulnerability scanning, analysis, reporting, and remediation validation.
- Experience with STIGs, SCAP, vulnerability management, and security compliance assessments.
- Experience developing or maintaining RMF authorization packages and supporting artifacts.
- Ability to analyze technical vulnerability findings and communicate remediation requirements to system administrators and engineers.
- Experience supporting Windows, Linux, network, or enterprise infrastructure environments.
- Proven written and verbal communication skills.
- Ability to work collaboratively within a government/contractor integrated team environment.
Preferred Qualifications
Certifications: CISSP, GSLC, GIAC certifications or other applicable DoD 8140 qualifications, or CCSP certification
Benefits
Medical, Dental, Vision, Unlimited Vacation, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid Legal Plan and Identity Protection Plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.
EEOC Statement
IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
group id: 10230535