Full Job Description
CALIBRE is seeking a Cybersecurity Assessment and Authorization (A&A) Subject Matter Expert (SME) to support the Defense Logistics Agency (DLA). The Cybersecurity A&A SME will provide subject-matter expertise related to the assessment and authorization of information systems and associated cybersecurity policies and procedures.
The selected candidate will execute DoW/DLA cybersecurity processes to authorize information systems, maintain existing system authorizations, and support systems undergoing the authorization process.
Responsibilities
• Serve as a cybersecurity subject matter expert for the assessment and authorization of information systems.
• Execute DoW/DLA cybersecurity processes supporting initial and ongoing system authorization.
• Support information systems throughout the Risk Management Framework (RMF) process.
• Assess security controls identified in NIST Special Publication 800-53.
• Conduct security-control assessments and authorization reviews for large, complex enterprise environments.
• Support the assessment and authorization of large and small enclaves, cloud-hosted services, Operational Technology (OT), Automated Information System (AIS) applications, and outsourced IT processes.
• Evaluate identified vulnerabilities and noncompliant security controls.
• Determine the residual risk associated with identified vulnerabilities.
• Assess the potential impact of cybersecurity vulnerabilities on a system's current or future authorization.
• Brief senior management on the progress, findings, and results of information systems undergoing the RMF process.
Required Skills
• Knowledge of the Risk Management Framework.
• Knowledge of NIST Special Publication 800-53 security controls.
• Knowledge of DoD and DLA cybersecurity policies and procedures.
• Ability to assess security controls and conduct authorization reviews.
• Ability to evaluate cybersecurity vulnerabilities and determine residual risk.
• Ability to assess the impact of security-control deficiencies on system authorizations.
• Ability to support the authorization of complex enterprise IT environments.
• Strong analytical, risk-assessment, written communication, and presentation skills.
• Ability to brief senior management on RMF activities and authorization decisions.
• Active Secret security clearance.
• DoD-approved 8570/8140 IAM Level III baseline certification.
• Moderate Risk, Non-Critical Sensitive Tier 3 (T3), NACLC, or ANACI investigation at the time of proposal submission.
Required Experience
• Minimum of five years of relevant Certification and Accreditation or Assessment and Authorization experience.
• Experience applying the RMF and NIST assessment and authorization processes.
• DoD cybersecurity experience.
• Experience assessing security controls.
• Experience conducting authorization reviews for large, complex organizations.
• Experience supporting cybersecurity authorization activities for enterprise information systems.