Requisition Number: 30426
Required Travel: 11 - 25%
Employment Type: Full Time/Salaried/Exempt
Anticipated Salary Range: $74,074.00 - $105,820.00
Security Clearance: Secret
Level of Experience: Mid
SummaryHII's Mission Technologies division is currently seeking a Information Assurance Compliance Analyst to support Naval Surface Warfare Center Dahlgren Division (NSWCDD) Dam Neck Activity (DNA) cybersecurity programs for Shore-Based Training Systems. This position will provide compliance and auditor support for Risk Management Framework (RMF) Assessment & Authorization (A&A) processes supporting approximately 80 cloud and shore-based training systems across PMS339, DRPM SUBS (SEA07TR), and RRL sponsors.
Key Job Responsibilities- Oversee, evaluate, and support documentation, validation, and accreditation processes necessary to ensure Information Technology (IT) systems meet the organization's information assurance (IA) and security requirements.
- Provide Auditor support for RMF packages and continuous monitoring purposes as needed in RMF Steps 0-6. Provide security controls risk assessments and validations.
- Assist in performing annual security reviews and annual testing of security controls.
- Assess quality of security control implementation against requirements using NIST SP 800-53 and Navy cybersecurity guidelines.
- Review and validate security artifacts including System Security Plans (SSP), Security Assessment Plans (SAP), Security Assessment Reports (SAR), and Plan of Action and Milestones (POA&M).
- Support preparation and maintenance of RMF documentation including objective quality evidence (OQE) for security control validation.
- Conduct reviews of Security Technical Implementation Guide (STIG) compliance results and Assured Compliance Assessment Solution (ACAS) vulnerability scan outputs; validate remediation activities.
- Assist in tracking POA&M entries and ensuring vulnerabilities are properly documented, tracked, and resolved.
- Support continuous monitoring activities by reviewing security control compliance status and identifying gaps or deficiencies.
- Participate in coordination efforts with Information System Security Managers (ISSM), Technical Area Experts (TAE), Security Control Assessors (SCA), and Authorizing Officials (AO).
- Review technical documentation including engineering change proposals, baseline descriptions, and configuration management artifacts for security compliance.
- Assist in preparation of briefing materials for TAE, SCA, and AO checkpoint meetings.
- Support development of security policies, procedures, and compliance reports.
- Ensure appropriate treatment of risk, compliance, and monitoring assurance from internal and external perspectives.
- Maintain knowledge of current Navy cybersecurity policies, instructions, and RMF guidance.
- Utilize Enterprise Mission Assurance Support Service (eMASS) to track authorization packages and upload compliance artifacts.
- Support cross-sponsor activities for PMS339, SUBS, and RRL programs as workload demands.
- Attend DOW, Navy Authorizing Official (NAO), and PAE Maritime RMF meetings to stay current on RMF processes and procedures.
- Utilize SIPRnet access 25-60% of the time depending on specific work assignments.
- Expected travel up to 10-15% of time for approximately one week per trip to support authorization briefings or stakeholder coordination.
What you must have- 2 years relevant experience with Bachelors in related field; 0 years experience with Masters in related field; or High School Diploma or equivalent and 6 years relevant experience.
- Demonstrated foundational experience in Information Assurance compliance
- Knowledge of RMF processes and A & A procedures.
- Experience working with Information Assurance tools such as eMASS and ACAS.
- DoD 8140 (formerly 8570) IAT Level II certification such as CCNA, CAP, Security+ CE, or ENSA required.
- Current or active DoD Secret clearance.
- Ability to work onsite at Dam Neck, Virginia Beach, VA hybrid schedule. Remote/telework is at the discretion of the government.
Preferred Qualifications- Experience supporting Navy shore-based training systems or cloud-based environments.
- Knowledge of Navy cybersecurity policies, Federal Information Security Modernization Act (FISMA) reporting, and continuous monitoring requirements.
- Familiarity with NIST SP 800-53 security controls and assessment procedures.
- Experience with STIG compliance validation and vulnerability remediation tracking.
- Strong analytical and documentation skills.
- U.S. Navy background with information assurance or cybersecurity experience.
- Ability to communicate effectively with technical and non-technical audiences.
- Attention to detail and commitment to compliance accuracy.
Physical RequirementsMay require working in an office, industrial, shipboard, or laboratory environment. Capable of climbing ladders and tolerating confined spaces and extreme temperature variances.
The listed salary range for this role is intended as a good faith estimate based on the role's location, expectations, and responsibilities. When extending an offer, HII's Mission Technologies division takes a variety of factors into consideration which include, but are not limited to, the role's function and a candidate's education or training, work experience, and key skills.
To learn more about Mission Technologies, click here for a short video: https://vimeo.com/[redacted]
HII is more than a job - it's an opportunity to build a new future. We offer competitive benefits such as best-in-class medical, dental and vision plan choices; wellness resources; employee assistance programs; Savings Plan Options (401(k)); financial planning tools, life insurance; employee discounts; paid holidays and paid time off; tuition reimbursement; as well as early childhood and post-secondary education scholarships. Bonus/other non-recurrent compensation is occasionally offered for qualified positions, and if applicable to this role will be addressed by the recruiter at the screening phase of application.