The National Science Foundation Cyber Security and Privacy (CS&P) Services contract team supports a layered, defense-in-depth cyber security environment that provides successive cyber security controls for approximately 2,500 employees at the Alexandria, Virginia Headquarters and additional employees at other locations. The CS&P Services Team is responsible for a comprehensive, agency-wide Cyber Security Program that encompasses all aspects of cyber security. Strategic objectives for the CS&P Services contract are: data loss prevention; improve network and system security; risk based management; security incident management; and cyber security training and awareness.
Criterion Systems has a position for a mid-level to senior Assessment and Authorization (A&A) analyst at a federal client site in Alexandria, Virginia. This position is responsible for leading A&A duties in compliance with guidance from the National Institute of Standards and Technology (NIST), Office of Management and Budget (OMB), General Accountability Office (GAO), and other federal requirements.
- Solid understanding of current computer technologies and technical security requirements as applied to the design, development, evaluation, and integration of computer systems and networks.
- Understanding of the NIST Risk Management Framework, FISMA, FedRAMP, FIPS 199 and NIST Special Publications.
- Understanding of security concepts and process implementation and experience with security-related tools and applications.
- Lead cybersecurity assessments and continuous monitoring of information systems in compliance with federal requirements and client direction.
- Create, manage, maintain, and improve A&A documentation and processes:
- System security plans for major applications
- FISMA inventories
- Security Assessment Reports
- Memoranda of Understanding (MOU) and/or Interconnection Security Agreement (ISA) tracking
- External services and cloud services tracking
- Privacy Threshold Analyses (PTA) and Privacy Impact Analyses (PIA)
- Perform research on systems security techniques and methodologies. Perform security requirements and development and risk analysis.
- Prepare streamlined task schedules and manage and report progress, both verbally and in writing.
- Draft policies, plans, procedures, and other documentation to demonstrate compliance with federal requirements and policies.
- Track record of logical and critical thinking, sophisticated writing skills, superior organizational skills, and excellent planning and time management skills. Communicate effectively both orally and in writing. Regularly achieve milestones and deadlines.
- Identify and implement strategies for cross-training. Work with other contract team members to identify security requirements.
- Familiar with the Department of Justice Cyber Security Assessment and Management (CSAM) tool.
- Degree in Computer Science or 4 years of equivalent expertise in cybersecurity field
- 5 years in cyber security and prefer within A&A field
- Security + certification or similar
- Experience using CSAM tool
- US citizen
- Ability to obtain and be eligible for a NACI/Public Trust clearance
- Certified Authorization Professional (CAP)
- PMI-certified PMP
- A + Certification
- Network + Certification
- Certified Ethical Hacker
- Certified Information System Security Professional (CISSP)
- Certified Information System Auditor (CISA)