DescriptionThe selected candidate will perform day-to-day cybersecurity, RMF, vulnerability management, and continuous monitoring activities while coordinating with technical teams, external tenants, and cybersecurity leadership to maintain the system's authorization and security posture.
Responsibilities- Support implementation and sustainment of the DoD Risk Management Framework (RMF) and system Authorization to Operate (ATO).
- Maintain eMASS authorization packages, including ACAS/Nessus results, DISA STIG checklists, security controls, and supporting artifacts.
- Develop, track, and maintain POA&Ms and coordinate remediation of identified vulnerabilities and compliance findings.
- Review applicable USCYBERCOM Cyber Tasking Orders (CTOs), DISA vulnerability notifications, and other cybersecurity directives for system and tenant applicability.
- Coordinate with external tenants and technical teams to communicate cybersecurity requirements, track remediation activities, and validate compliance.
- Support risk assessments for new applications, hardware, system changes, external connections, and architecture enhancements.
- Develop and maintain RMF documentation, including SSPs, RARs, continuous monitoring documentation, and interconnection agreements (ISAs/MOUs).
- Monitor applicable Federal, DoD, and NIST cybersecurity guidance and support implementation of evolving requirements, including Zero Trust and Post-Quantum Cryptography (PQC).
- Support cybersecurity assessments, inspections, configuration management activities, and other continuous monitoring requirements.
Requirements- Active DoD SECRET security clearance.
- Bachelor's degree in a related field.
- 3-10 years of cybersecurity, ISSO, information assurance, or security analyst experience.
- Experience maintaining authorization packages and supporting ATO sustainment activities in eMASS.
- Working knowledge of ACAS/Nessus, DISA STIGs, POA&Ms, NIST SP 800-53, DoD RMF, and CNSSI 1253.
- Familiarity with security monitoring/SIEM technologies such as Elastic is preferred.
- At least one of the following certifications: GMON, SecurityX / CASP+, CCISO, CCSP, CGRC/CAP, CISM, CISSO, CISSP, CISSP-ISSMP, Cloud+, FITSP-M, GCIA, GCIH, GCSA, GICSP, GSEC, GSLC, Security+, SSCP.
Desired Qualifications- Experience with tactical systems is a plus