Job Title
CYBER SEC SPECIALIST RMF SME
Location
ESN CHESAPEAKE OFFICE - VA US (Primary)
Job Description
We are seeking a
Cybersecurity Specialist.
Located on-site in
Chesapeake, VA.
ESN is seeking an experienced Cybersecurity Specialist focus to support a contract with Naval Information Warfare Center (NIWC), Atlantic, in Norfolk, VA. The contract to support NIWC LANT consists of Independent Validation & Verification, Operations, Sustainment, and Installation support. The Maintenance Figure of Merit (MFOM) systems provides near real-time material-based readiness reporting to the Defense Readiness Reporting System-Navy (DRRS-N) and provides three additional primary capabilities to the Fleet including Ashore and Afloat systems. This support includes manual and automation of software testing, Scrum Master, transitioning to Cloud, management of JIRA/JAMA/Confluence, and project support.
Principal Duties/Responsibilities:The candidate will be part of a group working IT services on unclassified and classified networks. The primary focus of this role is building and supporting an HBSS test environment and policy tuning for recurring integration and regression testing of GOTS and COTS operating systems and software. Additionally:
- A qualified candidate will have experience with building, updating, and maintaining an HBSS test environment, policy tuning, development, and maintenance of a Policy Layout Guide (PLG) within the Navy.
- Secondary responsibilities will include supporting the DoD Assessment and Authorization (A&A) processes and have experience implementing the Navy's Risk Management Framework (RMF) authorization process and artifact development from start to finish.
- Candidates should be able to demonstrate an in-depth understanding of DoDI 8510.01 implementation and have experience in creating entirely new RMF packages and documentation.
- This position will be responsible for managing the A&A process, creating all required documentation, and working with a team of technical individuals to provide accurate data and artifacts for multiple package(s).
- The desired candidate will be responsible for managing the package(s) throughout the system lifecycle, ensuring all periodic reviews are updated, and tracking remediation efforts through the POA&M.
- The desired candidate will be responsible for briefing progress and risk to both technical and management.
- The ideal candidate will be able to work independently, within a team setting, and be able to take on tasks quickly with minimal direction.
- Strong organizational, analytical, and troubleshooting skills with a high level of attention to detail are required to succeed in this diverse environment.
- Customer relationship management.
- Evaluating operating systems, government provided COTS and GOTS solutions, and enhancements via the new RMF A&A process.
- Evaluating providing documents such as Security Plan of Actions and Milestones (POA&M), actual validation results, artifacts associated with implementation of IA controls, etc., required for the RMF package requirements.
- Validating assigned IA Controls including execution of the accreditation, conducting validation activities, and compiling the status of the validation results in accordance with RMF Writing and updating Security POA&Ms.
- Tracking the implementation and execute validation of assigned RMF security controls. Supporting the preparation, execution, and documentation of Cybersecurity assessments/validations of the systems and assets for all RMF specified security and/or certification visits.
- Utilizing automated validation capabilities of the eMass for updating the RMF Package.
- Creating Package Evaluation Comments Resolution Matrix.
- Providing System Security Validation/Scan Results.
Skills and Abilities:- The candidate should be experienced with the eMass application.
- Completed DoD HBSS training
- 6 years of Navy HBSS administration, policy tuning and Policy Layout Guide (PLG) development.
- A minimum DoD 8570 IAT Level II certification. Additional certifications in specialization may be substituted for 1 year of experience.
- Security+ certification.
- CISSP or equivalent preferred.
Security Clearance:- Applicant must hold an active Department of Defense (DoD) SECRET personnel security clearance.
Job Requirements
Clearance Requirement