Job Requirements
Yorktown, VA
Public Trust Polygraph Unspecified
Career Level not specified
$82,000 - $112,000
Job Description
THOR Solutions is actively seeking an Assistant ISSO/RMF Cybersecurity Analyst to support a USCG information technology support services program focused on cloud data management, cybersecurity assessment and authorization (A&A), and governance in Yorktown, VA.
This position serves as an Assistant Information System Security Officer (A-ISSO), supporting the Risk Management Framework (RMF) process across assigned systems and enclaves to ensure the confidentiality, integrity, and availability of information systems to support the customer's compliance with applicable DHS, federal, and industry cybersecurity requirements and standards.
Typical Responsibilities:
Location: Full-time onsite at USCG TRACEN in Yorktown, VA.
Typical Physical Activity: Desk/computer work in an office environment. May involve: repetitive motion.
Typical Pay Range: The anticipated pay range for this position in the identified location(s) is $82,000 - 112,000. Actual compensation offered will be based upon individual factors including education, qualifications, and experience.
Existing TOP SECRET/SCI Security Clearance Required: This position requires an existing active TS/SCI security clearance prior to hire. Only U.S. citizens are eligible for a security clearance; therefore, only current U.S. citizens will be considered for this position.
Required Knowledge, Skills, and Abilities:
This position serves as an Assistant Information System Security Officer (A-ISSO), supporting the Risk Management Framework (RMF) process across assigned systems and enclaves to ensure the confidentiality, integrity, and availability of information systems to support the customer's compliance with applicable DHS, federal, and industry cybersecurity requirements and standards.
Typical Responsibilities:
- Serve as an Assistant Information System Security Officer (A-ISSO), participating in the Risk Management Framework (RMF) process for assigned programs, organizations, systems, or enclaves.
- Gather or generate, assess, and maintain RMF documentation packages tailored to specific systems, including Security Categorization Determinations, Implementation Plans, System Security Plans (SSP), Configuration Management Plans (CMP), Incident Response Plans (IRP), Contingency Plans (CP), authorization documentation, POA&Ms, Scorecards, Security Assessment Reports (SAR), Continuous Monitoring Strategies, Vulnerability Scans, Hardware/Software lists, Threat Models, Cybersecurity Strategies, Network Topology, boundary diagrams, and data flow diagrams.
- Ensure all information system cybersecurity documentation is current and accessible to properly authorized individuals.
- Interpret system designs and diagrams to identify data interconnections, interfaces, protocols, and data types, and select appropriate controls to remediate or minimize cybersecurity risk exposure.
- Develop plans and perform testing and control assessments to evaluate compliance with applicable security requirements, standards, and best practices.
- Conduct STIG/SRG assessments and Security Readiness Reviews (SRR) for operating systems and applications, leveraging automation to gain efficiencies.
- Conduct and review system scans using automated compliance assessment tools and provide documented results to appropriate stakeholders.
- Develop and conduct detailed security assessment briefs and provide cybersecurity risk recommendations to authorizing officials.
- Assist ISSOs and Information System Owners with security control implementation, policy development, and Standard Operating Procedures required for accreditation.
Location: Full-time onsite at USCG TRACEN in Yorktown, VA.
Typical Physical Activity: Desk/computer work in an office environment. May involve: repetitive motion.
Typical Pay Range: The anticipated pay range for this position in the identified location(s) is $82,000 - 112,000. Actual compensation offered will be based upon individual factors including education, qualifications, and experience.
Existing TOP SECRET/SCI Security Clearance Required: This position requires an existing active TS/SCI security clearance prior to hire. Only U.S. citizens are eligible for a security clearance; therefore, only current U.S. citizens will be considered for this position.
Required Knowledge, Skills, and Abilities:
- Bachelors degree in data science, information systems, computer science, or a related discipline.
- At least five (5) years of Information Assurance and A&A experience, including assessment of information system vulnerabilities and participation in the RMF process. Experience developing and maintaining RMF/authorization documentation packages, conducting security control assessments, and supporting continuous monitoring.
- Must possess active/current certifications to qualify as both DoD 8570/8140 IAT Level 2 and IAM Level 2.
- DoD 8570/8140 IAT Level 2 (required for systems assessment and authorization work), fulfilled by possessing ONE of the following:
- CompTIA Cybersecurity Analyst (CySA+)
- CompTIA Security+ CE (Sec+ CE)
- EC-Council Certified Network Defense (CND) v3
- Red Hat Certified System Administrator (RHCSA)
- CCNA Security
- Global Industrial Cyber Security Professional (GICSP)
- GIAC Security Essentials (GSEC)
- Systems Security Certified Practitioner (SSCP)
- CompTIA Advanced Security Practitioner (CASP)
- Cisco Certified Network Prof. Security (CCNP Security)
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified Cloud Security Professional (CCSP)
- GIAC Certified Enterprise Defender (GCED)
- GIAC Certified Incident Handler (GCIH)
- DoD 8570/8140 IAM Level 2 (required for IA program support work), fulfilled by possessing ONE of the following:
- CompTIA Advanced Security Practitioner (CASP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
- Certified Chief Information Security Officer (C-CISO)
- HealthCare Info. Security and Privacy Practitioner (HCISPP)
- Red Hat Certified System Administrator (RHCSA)
- Certified Authorization Professional (CAP)
- GIAC Security Leadership (GSLC)
- Certified Information Security Manager (CISM)
- Certified Chief Information Security Officer (C-CISO)
- GIAC Security Leadership (GSLC)
- DoD 8570/8140 IAT Level 2 (required for systems assessment and authorization work), fulfilled by possessing ONE of the following:
- Proficiency in Microsoft Office suite and SharePoint.
- Knowledge of data governance and data framework compliance.
- Strong organizational and communication skills.
group id: 10443513