IT-II security clearance or equivalent NACLC required
5+ years of relevant C&A experience
IAM Level III certification mandatory
Experience with Risk Management Framework (RMF) and NIST C&A
DOD cybersecurity experience essential
Experience with security control assessment for large organizations
Knowledge of cybersecurity in emerging technologies like Cloud and Industrial Control Systems
Responsibilities
Serve as cybersecurity SME for A&A of information systems
Execute DLA cybersecurity processes for system authorization
Assess and apply NIST 800-53 security controls to IT infrastructure
Analyze residual risks from identified vulnerabilities
Brief senior management on RMF process outcomes
Maintain compliance with cybersecurity policies and procedures
Support DOD's cybersecurity policy and procedures implementation
Benefits
Four Medical/Vision plans including HSA
Dental and Orthodontia coverage
Vision Materials benefits
Paid Life and Disability Insurance
401K Retirement Program with employer contribution
Paid time off including holidays and sick leave
Semi-monthly pay cycle
Full Job Description
Summary:
Client Agency is Defense Logistics Agency
Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization
(A&A) of information systems and all associated cybersecurity policies and procedures.
Executes DoW/DLA cybersecurity processes to authorize information systems, maintain authorization of information systems, or serves as a Subject Matter Expert (SME) for systems undergoing the authorization process.
Possess an understanding of how security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization's IT infrastructure such as DLA, in which there is a compilation of large and small enclaves, Cloud Hosted Services, Operational Technology, AIS applications and outsourced IT processes.
Determines the residual risk of an identified vulnerability (e.g., non-compliant security control) and determines the possible ramifications on the system's current or future authorization.
Briefs senior management on the progress or results of an information system undergoing the Risk
Management Framework (RMF) process.
Requirements:
Must possess IT-II security clearance or have a current National Agency Check with Local Agency Check and Credit Check (NACLC). (Basic Federal Clearance requirements are U.S. Citizenship, clear criminal history check, no recent or pending bankruptcies)
Five (5) years of relevant C&A experience.
Must have an IAM Level III certification.
Must have Risk Management Framework (RMF) and NIST C&A experience.
Must have DOD cybersecurity experience.
Experience in assessing security controls and conducting authorization reviews for large, complex organizations.
Experienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes.
Knowledgeable in the cybersecurity of emerging technology areas such as Cloud and Industrial Control Systems (ICSs), warehouse execution systems and Operational Technology (OT) infrastructures.
Excellent oral and written communication skills.
Benefits We Offer:
Four Medical/Vision options including an HSA plan
Dental and Orthodontia plan
Vision Materials plan
Paid Life, Short-Term Disability, and Long-Term Disability