Job Type
Full-time
Description
NexGen Data Systems is seeking an Information Systems Security Engineer (ISSE) to manage Navy-required Risk Management Framework (RMF) efforts for multiple Navy Enterprise Network (NMCI in particular) projects. This role will work collaboratively with Information Technology (IT) Engineers and System Administrators to conduct Cyber Security (CS) analysis, mitigation, remediation, and monitoring to ensure compliance with applicable DoD and Department of the Navy (DON) policies, procedures, and regulations. This position includes all activities associated with obtaining and maintaining RMF Authority to Operate (ATO) for systems within the customer's multi-faceted network infrastructure, which includes multiple platforms residing on multiple security enclaves. This role will be a Package Owner and responsible for execution of a package with the team's support.
Roles & Responsibilities:- Conduct certification and testing in accordance with the Risk Management Framework (RMF) and National Institute of Standards and Technology (NIST) policy; identify deficiencies and providing recommendations of risk mitigation to customer.
- Support the Government to resolve conflicting system security engineering requirements.
- Create the Security Authorization Package's (SAP), required Body of Evidence (SSP, SCTM, SAP, SAR, RAR, and POA&M) for Enterprise Network Systems
- Manage processes to record Assessment and Authorization (A&A) activities in the Enterprise Mission Assurance Security System (eMASS)
- Monitor corrective actions until all POA&M actions are closed
Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Requirements
Desired/Required Skills:- Active Department of Defense Secret security clearance required
- DoD Approved 8570 / 8140 baseline certification required
- Bachelor of Science Degree in an IT or Computer Related field required.
- 10+ years performing Navy A&A responsibilities including policy development, control testing, POA&M management, and Configuration Management
- 10+ years' experience supporting an IT Enterprise environment in a cyber, system administration, engineering or management capacity.
- REQUIRED: Current active access to SIPRNET and eMASS-C
- REQUIRED: Experience developing RMF packages for Classified systems
- Experience working with security engineers to review compliance scans
- Experience performing cybersecurity assessments using standards such as CIS Benchmarks, DISA STIGS, etc.
- Excellent customer service and organization skills
- Excellent verbal and written communication skills
- Ability to work both independently and as a member of a team
Benefits:- Company covers 100% of premiums for the employee's medical, dental, and vision insurance and subsidizes premiums for spouse and dependents.
- Company provides short and long term disability plans.
- 401(k) match up to 10% of the employee's salary contributions to 401(K) plan.
- Comprehensive training and development program.
- 11 paid holidays and paid time off (PTO) accrual level starts at 15 days annually.