Job DescriptionThe RMF Cyber Security Analyst Senior will provide support for a program, an organization, system, or an enclave; provides support for proposing, coordinating, implementing, and enforcing information systems or enclave cybersecurity policies, standards, and methodologies; maintains operational security posture for an information system, program, or enclave to ensure cybersecurity standards, and procedures are established and followed; performs day-to-day security operations of the system or enclave; perform IT security control assessments; provide configuration management (CM) for information system security software, hardware, and firmware; manage changes to
system and assess the security impact of those changes; prepare and review documentation to include Systems Security Plans (SSPs) and Security Assessment & Authorization (SA&A) packages in accordance with DoD Risk Management Framework (RMF) procedures.
Duties:- Interface with Project/Program Managers, Subject Matter Experts (SME) and Information System Security Managers (ISSM) on Major Application / General Enclave issues and updates.
- Drive the 7 steps of the RMF lifecycle (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor).
- Create and maintain security packages in eMASS.
- Review vulnerability scan results (using tools like ACAS or Nessus) and coordinate remediation.
- Act as a bridge between technical engineers, Information System Security Officers (ISSOs), and executive leadership.
- Track and report on Plan of Action and Milestone (POA&M) items; RMF Status, Annual Assessments, Authority to Operate (ATO) and Continuous Monitoring actions.
- Responsible for documentation compliance and review to ensure programs receive ATOs for multiple systems.
- Prepare briefs and A&A documents for approval in support of RMF reporting and policy development.
- Perform ISSO Type duties as defined in DoD 8510 & 8500.
- Provide risk mitigation strategies.
- Perform quality checks on POA&Ms, risk assessments, and documentation.
- Conduct security control and risk assessments to support authorizations.
- Review existing documentation bi-annually for accuracy and relevance to current DoD and DCSA mandates.
- Assist with research on cybersecurity items of interest.
- Perform other duties as related to risk management, communication, and assessments.
QualificationsIt is required that the RMF Cyber Security Analyst Senior have the following qualifications:
- Secret clearance.
- Bachelor's degree in information technology, Information Systems Management, Cyber Security, or some other related field.
- Five (5) or more years of hands-on technical Cyber Security Experience. Additional years of experience may be considered in lieu of a degree.
- Knowledge with DISA Security Technical Information Guides, DoD A&A Process, NIST SP
800-53, IA Technical Framework, and applicable DoD Cyber Security / Risk Management policies (must have DoD or eMASS experience). - At least one (1) year of the knowledge of current security tools, hardware/software security implementation, communication protocols, and Microsoft Office suite.
- Must meet DoD 8570-M/8140-M IAT Level II.