Information System Security Specialist II

ATG

$80K — $95K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active Secret clearance (eligible for TS clearance)
  • Bachelor's degree in Computer Science, Information Technology, or related field
  • 3-5 years of experience in Information Assurance Compliance
  • Certifications: CCNA, CAP, Security+ (CE), or ENSA

Responsibilities

  • Support evaluation and documentation in eMASS for security posture assessments
  • Submit and maintain RMF packages per DoD and NAVSEA guidelines
  • Develop required RMF package documentation for submission
  • Conduct risk and vulnerability assessments for systems
  • Perform security evaluations, audits, and reviews to determine residual risk
  • Execute Security Assessment Plans (SAPs) through on-site testing
  • Analyze logs and events from various cybersecurity tools

Benefits

  • Performance bonuses and annual salary reviews
  • Health, dental, and vision insurance
  • Short-term and long-term disability insurance
  • Life insurance options
  • 401(k) plan with company match
  • Opportunities for professional growth and development
  • Collaborative and inclusive work environment
Full Job Description
Job Title: Information System Security Specialist

Clearance: Secret

Work Location: Philadelphia, PA

Employment Type: Full-Time

*Position is contingent upon award*

Job Summary

We are seeking an Information System Security Specialist to join our team. You will play a key part in ATG's technical support for Naval Surface Warfare Center Philadelphia Division (NSWCPD) specializing in cybersecurity support, validation support, IT and cyber policy writing and program implementation support. Our team will provide direct support for cybersecurity policy, A&A artifacts, validation, and security posture reviews.

Key Responsibilities
  • Support evaluation and documentation in eMASS to include the security posture of the system or site being Assessed, Authorized, and maintained.
  • Submit, and maintain RMF packages in accordance with DoD Instruction 8510.01, NAVSEA Business Rules, DON RMF Process Guides, NAVSEA Standard Operating Procedures (SOPs), and the business rules of cognizant review offices.
  • Support development the RMF package documentation required for submission in accordance with DoD/NAVSEA directives. Documents may include but are not limited too HW/SW Lists, Authorization Boundary Diagrams, Privacy Impact Assessment (PIA), etc.
  • Conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs.
  • Conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor's (SCA) and higher level review.
  • Execute Security Assessment Plans (SAPs) by supporting on-site testing for afloat and PIT ashore systems.
  • Conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system.
  • Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS).
  • Assess impacts from observed risks and report via the Cybersecurity Program chain of command.
  • Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities.
  • Support the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution.
  • Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance.
  • Maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM).
  • Ensure RMF artifacts are in compliance with published Navy, NAVSEA Business Rules (OPNAV N2N6 and/or NAVSEA), NIST SP-800-37 and SP-800-53 Rev 4.

Qualifications

Required:
  • Active Secret clearance (eligible to obtain and maintain a TS clearance)
  • Bachelor's degree (Computer Science, Information Technology or related technical degree) from an accredited College or University.
  • 3-5 years of professional experience in Information Assurance Compliance.
  • CCNA or CAP or Security + (CE) or ENSA certification.

Desired:

Additional Benefits

Performance Bonuses and annual salary reviews

Health, dental, and vision insurance

Short Term Disability, Long Term Disability, and Life Insurance

401(k) plan with company match

Opportunities for professional growth and development

A collaborative and inclusive work environment

Similar Jobs

More Jobs at ATG

More Aerospace & Defense Jobs

Find similar Information System Security Specialist II jobs: