IAT Level III certifications (CISSP, CISM, CASP, etc.) required.
Active DoD Secret clearance necessary.
5+ years in DoD/DoN Cybersecurity, Engineering, or A&A.
Expertise in assessing compliance with DoN and Navy RMF standards.
Knowledge of DoD Cybersecurity policies and NIST SP 800-53.
Experience in analyzing and reporting security vulnerabilities.
Self-motivated with strong communication and collaboration skills.
Familiarity with DoD tools for vulnerability assessments (eMASS, ACAS, etc.).
Responsibilities
Review A&A package submissions for compliance with security requirements.
Conduct compliance assessments for Naval networks and legacy systems.
Assist in developing and updating A&A and CS documentation.
Support A&A workflow processes and accreditation decision milestones.
Create training materials and documentation for A&A and CS functions.
Develop and maintain SOPs and checklists for A&A processes.
Support Risk Assessment tasks and provide guidance to subordinate commands.
Collaboratively monitor and report on security posture of critical systems.
Benefits
Opportunity to work with a highly motivated team.
Engagement in mission-critical cybersecurity initiatives.
Access to ongoing training and professional development.
Contributions to national security through Navy cybersecurity efforts.
Full Job Description
Overview
The Cyber Security Analyst will support the USFF N6 Directorate Fleet Enterprise Support Team, Package Submitting Office (PSO) in the end-to-end Risk Management Framework (RMF) Assessment & Authorization (A&A) process for Navy shore commands, providing overarching expertise for the A&A process. This effort will highlight and track significant physical, policy and or network security issues, improving network security and awareness on Naval networks world-wide.
Responsibilities
Review A&A package submissions to ensure system/network architectures and technical / non-technical operating features adequately protect and defend against unauthorized access, ensure systems availability, and meet DoD/Navy Cybersecurity (CS) implementation policy requirements and data protection safeguards.
Conduct CS compliance and A&A documentation validation assessments for Naval networks, legacy applications, and systems.
Assist in the development or updates to existing, A&A and CS documentation to ensure complete documentation in accordance with DoD A&A and CS policy.
Assist in the development procedures to support A&A workflow processes, criteria needed to facilitate processes and Navy Authorizing Official (NAO) accreditation decision milestones.
Assist in the development of trainings, presentations, briefings, and other forms of written documentation on an as needed basis to support A&A and CS functions.
Assist in the development of Standard Operating Procedures (SOPs), checklists, workflow process charts and other documentation needed to support NAO processes and related A&A functions and keep it up to date.
Support USFF subordinate commands with Risk Assessment related tasks such: as discussing assessment results, documenting vulnerability status, providing guidance and training relating to various RMF topics.
Work with highly motivated teammates that will support you and expect reciprocal support.
Collaboratively monitor and report the security posture for mission critical systems, including communicating risk and recommended mitigations.
Qualifications
Required:
Information Assurance Technician (IAT) Level III qualifications (CISSP, CISM, CASP, etc.)
Active DoD Secret clearance.
Minimum 5 years of experience in DoW/DoN Cybersecurity, Engineering, Test & Evaluation or Assessment & Authorization (A&A)
Ability to provide technical support and apply expertise in assessing information system compliance with DoN and Navy RMF standards and review, verify, and validate required DoD RMF documentation and artifacts in accordance with DoD Instruction 8510.01, Navy SCA Risk Assessment Guide (RAG), and the Navy RMF Process Guide (RPG)
Demonstrated knowledge of DoD Cybersecurity policies, procedures, and practices (including RMF and NIST SP 800-53 publications) to achieve and maintain system accreditation and authorization.
Experience analyzing, summarizing, and reporting security vulnerabilities and weaknesses verbally and in writing to the appropriate level of leadership.
Be self-motivated and possess understanding of technical concepts, have good communication skills, and able and willing to collaborate on technical items with the larger team.
Knowledge and experience using DoD tools and capabilities for vulnerability assessments and compliance reporting (eMASS, ACAS, STIGs, SRGs, SCAP, etc.)
Demonstrated knowledge of Cybersecurity, Information Technology and Network Architecture. This includes understanding of computers, operating systems (Linux and Windows-based), networks, network devices, deployment environments (e.g., data center, cloud, etc.), systems and application security threats and vulnerabilities.
Ability to perform quality assurance reviews for required content in all packages in the A&A process IAW provided SOPs and Checklists.
Proficient with Microsoft Office (Word, Excel, and PowerPoint)
Preferred:
BS Degree in Computer Science, Cyber Security, or related technical field
Minimum of 3 years of experience as a Navy Qualified Validator (NQV)
Experience training or instructing a small group with varied levels of experience
Experience supporting information assurance for US Navy systems.
Experience performing information assurance for cloud environments (and/or cloud-related certification).
Pay Range
$130,000-$140,000
About Falconwood, Incorporated
Falconwood, Incorporated is a management consulting firm that provides services to government agencies and commercial clients. The company was founded in 2006 and is headquartered in McLean, Virginia. They offer services such as program management, financial management, and information technology services. Falconwood serves clients in various industries, including defense, healthcare, and finance.