5+ years of experience in information systems/network security.
Familiarity with NIST RMF lifecycle and DoDI 8510.01 standards.
Experience managing Authorization to Operate (ATO) packages.
Knowledge of NIST SP 800-53 controls and DISA STIGs.
Proficiency in utilizing compliance assessment tools like ACAS.
Responsibilities
Carry out the information systems security program to meet contractual security requirements.
Conduct regular security audits of systems and ensure policy compliance.
Manage and update ATO packages and maintain eMASS records.
Execute continuous monitoring strategies and analyze system vulnerabilities.
Implement NIST SP 800-53 security controls and assess their effectiveness.
Identify and respond to cybersecurity incidents according to USAF directives.
Draft and maintain System Security Plans and track remediation actions.
Benefits
Health, dental, and vision insurance coverage.
Retirement savings plan with company matching.
Paid time off and holiday leave.
Professional development and training opportunities.
Flexible work environment options.
Full Job Description
Essential Duties and Responsibilities
Under general direction, this role carries out all phases of information systems/networks security program that involves access to computers and computerized data enabling company to meet contractual requirements for networks security.
Conducts regular audits to ensure that systems are being operated securely, and information systems security policies and procedures are being implemented as defined in security plans.
Develop, update, and manage Authorization to Operate (ATO) packages. Navigate and maintain system records within the Enterprise Mission Assurance Support Service (eMASS).
Execute continuous monitoring strategies. Review audit logs, analyze vulnerability scans, and verify system configuration baselines remain intact.
Implement, enforce, and assess NIST SP 800-53 security controls. Apply and verify Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
Utilize the Assured Compliance Assessment Solution (ACAS) to scan for, identify, and coordinate the remediation of system vulnerabilities.
Identify, report, and track cybersecurity incidents and data spills in accordance with USAF and DoW incident response directives.
Draft, review, and maintain System Security Plans (SSP), continuous tracking of Plan of Action and Milestones (POA&M), and system-specific operating procedures.
Deep understanding of the NIST RMF lifecycle, DoDI 8510.01, and USAF-specific guidance (e.g., AFI 17-101, Risk Management Framework for Air Force Information Technology).