5 years of relevant Certification & Accreditation (C&A) experience
Familiarity with Risk Management Framework (RMF) and NIST C&A processes
Experience with large, complex organizational cybersecurity assessments
Active security clearance required
DOD Approved 8570 Baseline Certification: Category IAM Level III
Responsibilities
Serve as a Subject Matter Expert (SME) for cybersecurity Assessment and Authorization (A&A) processes
Execute DoW/DLA cybersecurity processes for information system authorization
Understand NIST 800-53 security controls in relation to large organization IT infrastructures
Determine residual risks from identified vulnerabilities
Brief senior management on Risk Management Framework (RMF) updates for information systems
Benefits
Opportunity to work on pivotal cybersecurity initiatives
Engagement with high-level stakeholders and senior management
Focus on compliance and risk management within the DOD framework
Involvement in the evolving field of cybersecurity and risk assessment
Potential for professional development and training in cybersecurity areas
Full Job Description
Cybersecurity SME
Fort Belvoir, VA
Responsibilities:
Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures
Executes DoW/DLA cybersecurity processes to authorize information systems, maintain authorization of information systems, or serves as a Subject Matter Expert (SME) for systems undergoing the authorization process
Possess an understanding of how security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization's IT infrastructure such as DLA, in which there is a compilation of large and small enclaves, Cloud Hosted Services, Operational Technology, AIS applications and outsourced IT processes
Determines the residual risk of an identified vulnerability (e.g., non-compliant security control) and determines the possible ramifications on the system's current or future authorization
Briefs senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process
Requirements:
Five (5) years of relevant C&A experience; Risk Management Framework (RMF) and NIST C&A experience; DOD cybersecurity experience
Experience in assessing security controls and conducting authorization reviews for large, complex organizations
Active security clearance
DoD Approved 8570 Baseline Certification: Category IAM Level III