Position: Information Security Analyst (NQV)
Location: Norfolk Naval Shipyard 100% on-site
Clearance: Top Secret clearance
Job Description:
The Information Security Analyst (NQV) shall work to support DoD Risk Management Framework (RMF) and validate Network and System assets. They will be responsible to:
a.Follow Accreditation & Authorization (A&A) process and standards.
b.Perform System / network vulnerability analysis.
c.Conduct Risk assessment and risk mitigation analysis.
d.Perform Security Test and Evaluation (ST&E) processing.
e.Validate Security Technical Implementation Guide (STIG) Processing. Use automated STIG processing tools [e.g., Security Content Automation Protocol (SCAP), Evaluate STIG, STIGMAN, EMASSter]. Use of Enterprise Mission Assurance Support Services (eMASS) and similar RMF repositories.
f.Setup and execute A&A Business Rules, Standard Operating Procedures (SOP)s, Concept of Operations (CONOP)s, and Plans.
g.Perform Contingency planning, training and testing.
h.Establish/interrupt Firewall Policy.
i.Identify Interrupt, register Ports & Protocols.
j.Review Hardware / Software, network boundaries, flow diagrams and technical drawings.
k.Identify interrupting information in the system baseline configuration in VRAM by uploading vulnerability scan of a representative baseline system.
l.Advise on the proper method to mitigate vulnerabilities.
m.Produce executive documents, reports, project plans and plan of action and milestones (POA&M).
Qualifications:
Minimum of seven (7) years of experience in CS/A&A analysis support in IA controls analysis, conducting risk assessments, risk mitigation analysis, or developing plans. KSAs include:
• Qualified and registered as a Navy Qualified Validator (NQV)
• Expert knowledge of and experience with CS/RMF requirements as defined by Public Laws, National, DoD, and DON [e.g., Federal Information Security Management Act (FISMA), DoDD 8100.02, DODI 8500.01, DoDI 8520, DoDI 8530, DoDI 8531, SECNAV 5239 Series and OPNAV 5239 Series, NIST Special Publications Series 800, etc.]
• Expert and Mastery levels with institutional knowledge on the mission critical procedures, systems, and processes, as they pertain to Information Technology and Cyber Security requirements.
• Experience in certifying and accrediting DON information systems and networks, as well as Platform IT.
• Expert knowledge and experience with the requirements outlined in OPNAVINST N9210.3 Safeguarding Naval Nuclear Propulsion Information
Education:
Bachelor's degree in an IT related discipline OR Level II Certification (Security+ or better) AND a minimum of seven (7) years of experience.
Certifications:
• Active Security + CE or higher
• Active NQV