NQV Information Security Analyst

Professional Software Engineering, Inc

$95K — $115K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in Cybersecurity / Authorization & Accreditation (CS/A&A) analysis support
  • Qualified Navy Qualified Validator (NQV)
  • Expertise in CS/RMF requirements and associated regulations
  • Deep institutional knowledge of critical IT and Cyber Security procedures
  • Experience in certifying and accrediting Navy information systems and networks
  • Knowledge of safeguarding Naval Nuclear Propulsion Information regulations
  • Bachelor's degree in an IT discipline or Level II Certification (Security+ or better).

Responsibilities

  • Support the DoD Risk Management Framework (RMF) process and validate network and system assets
  • Follow accreditation and authorization processes and standards
  • Perform system and network vulnerability analysis
  • Conduct risk assessments and mitigation analyses
  • Execute Security Test and Evaluation (ST&E) processing
  • Validate Security Technical Implementation Guide (STIG) processing using automated tools
  • Establish and implement firewalls and security policies

Benefits

  • Top Secret clearance required
  • Position is 100% on-site at Norfolk Naval Shipyard
  • Engagement in high-stakes projects with national security implications
  • Opportunity to work within a structured, military-focused environment
  • Potential for professional development in a critical security field
Full Job Description
Position: Information Security Analyst (NQV)

Location: Norfolk Naval Shipyard 100% on-site

Clearance: Top Secret clearance

Job Description:

The Information Security Analyst (NQV) shall work to support DoD Risk Management Framework (RMF) and validate Network and System assets. They will be responsible to:

a.Follow Accreditation & Authorization (A&A) process and standards.

b.Perform System / network vulnerability analysis.

c.Conduct Risk assessment and risk mitigation analysis.

d.Perform Security Test and Evaluation (ST&E) processing.

e.Validate Security Technical Implementation Guide (STIG) Processing. Use automated STIG processing tools [e.g., Security Content Automation Protocol (SCAP), Evaluate STIG, STIGMAN, EMASSter]. Use of Enterprise Mission Assurance Support Services (eMASS) and similar RMF repositories.

f.Setup and execute A&A Business Rules, Standard Operating Procedures (SOP)s, Concept of Operations (CONOP)s, and Plans.

g.Perform Contingency planning, training and testing.

h.Establish/interrupt Firewall Policy.

i.Identify Interrupt, register Ports & Protocols.

j.Review Hardware / Software, network boundaries, flow diagrams and technical drawings.

k.Identify interrupting information in the system baseline configuration in VRAM by uploading vulnerability scan of a representative baseline system.

l.Advise on the proper method to mitigate vulnerabilities.

m.Produce executive documents, reports, project plans and plan of action and milestones (POA&M).

Qualifications:

Minimum of seven (7) years of experience in CS/A&A analysis support in IA controls analysis, conducting risk assessments, risk mitigation analysis, or developing plans. KSAs include:
• Qualified and registered as a Navy Qualified Validator (NQV)
• Expert knowledge of and experience with CS/RMF requirements as defined by Public Laws, National, DoD, and DON [e.g., Federal Information Security Management Act (FISMA), DoDD 8100.02, DODI 8500.01, DoDI 8520, DoDI 8530, DoDI 8531, SECNAV 5239 Series and OPNAV 5239 Series, NIST Special Publications Series 800, etc.]
• Expert and Mastery levels with institutional knowledge on the mission critical procedures, systems, and processes, as they pertain to Information Technology and Cyber Security requirements.
• Experience in certifying and accrediting DON information systems and networks, as well as Platform IT.
• Expert knowledge and experience with the requirements outlined in OPNAVINST N9210.3 Safeguarding Naval Nuclear Propulsion Information

Education:

Bachelor's degree in an IT related discipline OR Level II Certification (Security+ or better) AND a minimum of seven (7) years of experience.

Certifications:
• Active Security + CE or higher
• Active NQV

Similar Jobs

More Jobs at Professional Software Engineering, Inc

More Aerospace & Defense Jobs

Find similar NQV Information Security Analyst jobs: