Job Title
Cybersecurity RMF Analyst III
Job Type
Full-time
Category
Professional Services
Education
Bachelor's Degree
Location
Louisiana - LA US
Norfolk, VA US
South Carolina - SC US (Primary)
Tampa, FL US
Job Description
Scope of Work: Modus21 has recently been awarded a five year contract for the Cloud Computing Innovation, Transformation, and Integration (CLOUD CITI) and Enterprise Systems (ES) Department Information Technology Support for the Navy. Modus21, LLC and it's team of subcontractors work will encompass Information Technology (IT), network, planning, architectural analysis, evaluation, design, development, engineering, transition, cyber security, programmatic and sustainment support services to provide the Enterprise Systems (ES) Department of the Naval Information Warfare Center (NIWC) Atlantic Service Centers world-class solutions to complex IT challenges in an uninterrupted manner.
As part of the program, the Cybersecurity RMF Analyst plays a foundational role in obtaining and maintaining authorization for core infrastructure systems managed by Cloud CITI. This position requires hands-on experience with Enterprise Mission Assurance Support Services (eMASS) to capture information and artifacts necessary for authorization in accordance with the Department of the Navy (DoN) RMF Process Guide, Navy Security Control Assessor Risk Assessment Guide, and CYBERSAFE requirements. The Cybersecurity RMF Analyst will support collaboration with system owners and security personnel to identify and mitigate risks throughout the system lifecycle.
Responsibilities:- RMF Support & Documentation: Assist in the development and maintenance of RMF documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), and Plans of Action and Milestones (POA&Ms).
- Security Control Alignment: Support the determination of applicable security controls in alignment with NIST 800-53 and other agency-specific guidance.
- Testing and Monitoring: Assist in testing and monitoring security controls to ensure their continued effectiveness.
- Technical Review: Help review and assess technical test results, such as ACAS scans, Eval-STIG scans, and STIG checklists, to assist in resolving findings.
- Compliance Maintenance: Conduct routine security reviews and audits to ensure ongoing compliance.
- Record Management: Update Department of Defense Information Technology Portfolio Repository - Department of the Navy (DITPR-DON) records as required.
Requirements/Experience:- Minimum Education: Bachelor's degree in a technical or managerial related discipline or High School Diploma or GED
- Minimum Experience: Five (5) years with Bachelor's degree or seven (7) years with HS/GED of practical experience demonstrating competency in Cybersecurity, Engineering, Test & Evaluation (T&E) or Assessment & Authorization (A&A)/ Certification & Accreditation (C&A) related field.
- RMF Knowledge: Individual shall demonstrate a working knowledge of the Risk Management Framework (RMF) process.
- Tool Familiarity: Experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS) and Assured Compliance Assessment Solution (ACAS).
- Authorization Skills: Familiarity with security policies and guidance documents to assist with the preparation and maintenance of process artifacts, traceability documents, and Authority to Operate (ATO) requirements
- Must possess at least one (1) certification from each of the following categories:
- Cybersecurity Foundational: CompTIA Security+ or completion of a vendor/platform-specific training.
- Ability to obtain a Department of Defense (DoD) TOP SECRET Security Clearance.
- U.S. citizenship required.
- Strong communication skills, attention to detail, and willingness to learn.
Desired Certifications:- Cybersecurity Compliance or Cloud Security Certification: ISC2 CGRC-Governance, Risk & Compliance or CCSP-Certified Cloud Security Professional
- Technical/Platform Specific: Examples include Cisco Certified Network Associate (CCNA), Microsoft role-based certifications (MCAD, MCDBA), Red Hat Certification Program (RHCP), VMware Certified Technical Associate, or Cloud certifications (e.g., AWS Architect, Developer, SysOps Associate).