Cybersecurity Risk Assessment Specialist
The Opportunity: As an information security risk specialist on our team, you'll use your experience to work with military agencies to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You'll review technical and personnel details from system and mission owners to assess the entire threat landscape. Then, you'll guide your client through a plan of action with presentations, whitepapers, and milestones.
You'll work with your client to translate security concepts, so they can make the best decisions to secure their critical mission data and supporting networks. This is your opportunity to act as an information security subject matter expert while broadening your skills in cross-domain data transfer systems, securing environmental intelligence, and managing cyber risk across all classification levels for DoD data and systems.
Work with us as we protect complex DoD mission data systems.
Join us. The world can't wait.
You Have: - 5+ years of experience supporting cybersecurity accreditation, authorization, or compliance activities for federal or classified environments
- 5+ years of experience with Xacta governance, risk, and compliance (GRC) tools such as Xacta 360 or legacy Xacta IA Manager, including development or maintenance of RMF or authorization packages
- Experience supporting the full RMF lifecycle, including categorization, control selection and documentation, assessment support, authorization, and continuous monitoring
- Experience developing and maintaining cybersecurity documentation such as SSPs, control narratives, POA&Ms, contingency documentation, and configuration management documentation
- Experience working with vulnerability data, compliance results, or evidence to support ongoing authorization and monitoring activities
- Knowledge of NIST SP 800-53 Rev. 4 or Rev. 5 and general federal cybersecurity control implementation practices
- Ability to translate technical system architecture, infrastructure design, and operational details into clear compliance documentation
- Top Secret clearance
- HS diploma or GED
- DoD IAT or IAM II Cybersecurity Workforce Certification such as CompTIA Security+ Certification
Nice If You Have: - Experience processing RMF packages in Xacta GRC tools for Department of Navy information systems
- Experience with cross domain solution (CDS) technologies, configurations, and security mechanisms
- Experience with Everfox CDS technologies and related authorization or security mechanisms
- Experience supporting Navy-specific cybersecurity policies, training requirements, systems, or workflows
- Experience supporting classified cybersecurity documentation in SCI or SCIF environments
- Knowledge of JWICS security requirements and IC overlay requirements
- Knowledge of Apache NiFi, including relevant components and configuration considerations
- Knowledge of NAVINTEL assessment and authorization processes, business rules, or CDS overlay requirements
- TS/SCI clearance
- Bachelor's degree in Cybersecurity, Information Systems, CS, Engineering, or a related field
Clearance:Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required.
CompensationSalary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Work ModelOur people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
- Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.