Responsibilities
The Senior Cybersecurity Internal Controls Administrator provides comprehensive support in accordance with DoDI 8500.01, DoDI 8510.01, and AR 25-2, delivering Enterprise eMASS and Risk Management Framework (RMF) services, including developing RMF packages, maintaining asset lists and categorizations, and scheduling and coordinating system validation reviews.
This is a remote-eligible position. Local candidates in the Roanoke and Radford, Virginia area are encouraged to apply, and work may be performed locally for those who prefer an on-site or hybrid arrangement. The ideal candidate will bring deep RMF and eMASS compliance expertise, strong DoD cybersecurity compliance knowledge, and the ability to support mission-critical Army IT services across enterprise data centers and cloud-hosted environments.
Key Responsibilities
- Provide Enterprise eMASS and RMF services, including developing RMF packages and maintaining asset lists and categorizations.
- Schedule and coordinate system validation reviews.
- Generate artifacts to support control compliance; review ACAS and STIG reports and coordinate remediation efforts.
- Create, track, and maintain Plan of Action and Milestones (POA&M) documentation.
- Perform annual security reviews and participate in Continuity of Operations (COOP) and Incident Response testing.
- Maintain Army PPSM and Circuit Registry records.
- Participate in Software Assurance reviews to ensure ongoing items are appropriately documented via eMASS POA&M.
Qualifications
Requirements:
- Cybersecurity Certification (such as CISSP or equivalent).
- Bachelor's degree in Computer Science is preferred; equivalent years of cybersecurity and RMF experience will be considered in lieu of a degree.
- Active DoD Secret Security Clearance.
- 10 or more years' experience with Cybersecurity and RMF-related areas.
- Extensive experience with Enterprise eMASS and RMF services.
- Proficiency in developing RMF packages and maintaining asset lists and categorizations.
- Ability to schedule and coordinate system validation reviews.
- Experience generating artifacts to support control compliance.
- Knowledge of ACAS and STIG reports and coordinating remediation efforts.
- Experience creating, tracking, and maintaining Plan of Action and Milestones (POA&M).
- Ability to perform annual security reviews.
- Participation in Continuity of Operations (COOP) and Incident Response testing.
- Ability to maintain Army PPSM and Circuit Registry records.
- Participation in Software Assurance reviews and documenting items via eMASS POA&M.
- Experience with security compliance and control documentation.
Preferred:
- Bachelor's degree in Computer Science or equivalent years of experience.
- Familiarity with DoDI 8500.01, DoDI 8510.01, and AR 25-2.
- Strong analytical and problem-solving skills.
- Excellent communication and coordination skills.
- Experience with Army enterprise monitoring tools and practices.
- Knowledge of security regulations and best industry practices.
- Ability to work effectively in a team environment and collaborate with various stakeholders.
- Experience with incident response activities.
- Understanding of Continuity of Operations Plans and Communication Plans.
Certifications:
CISSP or equivalent Cybersecurity Certification
Pay Band MinUSD $87,320.00/Yr.
Pay Band MaxUSD $135,160.00/Yr.