OverviewResponsibilities
As aSecurity Analyst, you will assist the Subject Matter Expert (SME) and Cybersecurity Engineers with Risk Management Framework (RMF) related activities including Security Control Assessments (SCA) and assisting system owners in the transition to RMF compliance. In assuming this position, you will be a critical contributor to meeting Empower AIs mission: To deliver innovative, cost-effective solutions and services that enable our customers to rapidly adapt to dynamic environments. This position is located in Fort Huachuca, Arizona. Must have active Secret clearance or the ability to obtain one.
Highlights of Responsibilities:
- Working under close supervision, performs a variety of relatively routine project tasks applied to specialized technology problems (e.g. logic design, circuit design, I/O design, firmware development, computer architecture analysis and design, network structure design, etc.)
- May be responsible for program coding, testing, debugging, patching, and documentation
- Analyzes user requirements, concept of operations documents, and high-level system architecture to develop system requirement specifications
- Guides users in formulating requirements, advises alternative approaches and conducts feasibility studies
- Typical assignments may involve integration of software, systems, and electronic processes or methodologies to resolve total system problems or applications
- Processes may range from simple to moderately complex use of computers or other electronic technology and equipment
- Edit and manage written cybersecurity deliverables, including Risk Management Framework (RMF) packages and associated artifacts.
- Assess Department of War Information Systems against the RMF security controls in accordance with Department of Defense Instruction (DoDI) 8500, DoDI 8510, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 5
- Develop and review RMF documentation and artifacts such as Configuration Management Plans, Network Infrastructure Plans, Business Continuity and Disaster Recovery Plans, Plan of Action and Milestones (POA&Ms), topology diagrams and all supporting policies in support of RMF Assess and Authorize (A&A) activities
- Interview technical SMEs as well as non-technical management personnel to ascertain the security posture of an Information Technology (IT) system
- Evaluate a wide array of IT devices for Security Technical Implementation Guide (STIG) compliance using Assured Compliance Assessment Solution (ACAS)/ Nessus, Security Content Automation Protocol (SCAP) Compliance Checker (SCC), and manual checklist reviews.
- Ensure Security Technical Implementation Guides (STIGs) are in compliance with NIST SP-800-53 by providing thorough technical written explanations and proof
- Apply STIGs on baseline environment consisting of a variety of software and devices to ensure security compliance with NIST SP-800-53
- Manage packages in Enterprise Mission Assurance System (eMASS) based on a strong understanding of the NIST SP-800-53 requirements and the application of Control Correlation Identifiers (CCI) outlined in the Committee on National Security Systems Instruction (CNSSI) 1253 to achieve system compliance
Qualifications
Requirements:
Current/active Secret clearance.
At minimum 3 years of Cybersecurity Experience.
Bachelors degree or equivalent combination of education and related work experience
Security+ certification required
Physical Requirements:
- Sitting for long periods
- Standing for long periods
- Ambulate throughout an office
- Ambulate between several buildings
- Stoop, kneel, crouch, or crawl as required