Position SummaryOdyssey Systems has an exciting opportunity for a
Senior Cybersecurity Program Analyst providing support to the AFLCMC/C3I C2ISR Division. C3I C2ISR Division provides support for all the weapon systems, platforms, cells, and capabilities managed by the C2ISR Division in support of AFLCMC/HB, and other classified programs designated under C3I or extensions of HB under C2ISR.
This is a full-time position located in Palmdale, CA
ResponsibilitiesDuties include, but not limited to: - Collect and maintain data needed to meet system cybersecurity reporting requirements IAW cybersecurity law, regulation, and policy
- Identify gaps in cybersecurity compliance for the assigned system, create plans of action to resolve cybersecurity gaps, communicate plans to organizational leadership, execute plans to ensure cybersecurity compliance is met
- Ensure security improvement action are identified, validated, and implemented as required for the assigned system; tracks cybersecurity program requirements to ensure successful implementation
- Ensure that cybersecurity requirements are integrated into the continuity planning for the assigned system and organization; makes recommendations to update cybersecurity policy for organizational efficiency
- Plan, monitor, and track cybersecurity tasks to ensure successful completion
- Identify alternative information security (INFOSEC) strategies to address cybersecurity tasks or requirements that are a risk to the system's continued operation and mission success
- Monitor the assigned system to ensure cybersecurity data and data sources meet cybersecurity policy requirements, and communicate status to organizational leaders
- Audit cybersecurity information, data, system configuration, and other cybersecurity characteristics to ensure requirements are met; report gaps or issues to division cybersecurity leadership
- Conduct import/export reviews for acquiring systems and SW
- Review source code scanning reports to identify vulnerabilities and identify risks
- Develop methods to monitor and measure risk, compliance, and assurance efforts; develop contingency plans, disaster recovery procedures, and other methods to mitigate and/or resolve cybersecurity risks
- Identify and document the requirements necessary to ensure SW acquisition programs, contract requirements, or other product development efforts meet applicable cybersecurity law, regulation, and policy
- Develop methods to ensure programs or projects meet the requirements of DoDI 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling
- Support the Risk Management Framework (RMF) tasks related to system/application efforts to include Assessment and Authorization efforts, system audits, and other quality checks; ensure cybersecurity RMF artifacts (documents, data, etc.) meet the requirements of cybersecurity policy
- Recommend policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data
- Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs
- Participate in network and systems design to ensure implementation of appropriate systems security policies
- Ensure the rigorous application of INFOSEC/cybersecurity policies, principles, and practices in the delivery of all IT services
- Perform the Information System Security Engineer duties in an Information Assurance (IA) Workforce System Architecture and Engineering position as outlined in AFI 33-200, AFI 33-210 and AFMAN 33-285 for assigned systems
QualificationsCitizenship: Must be a US citizenMinimum Required QualificationsClearance: Top SecretEducation: Bachelor's degree in a related field and 12 years of experience in the respective technical/professional discipline being performed, five of which must be in DoD acquisition.
Years of Experience: 15 years of directly related experience with proper certifications, eight of which must be in DoD acquisition.
Certifications: 805-IT Program AuditorIntermediate or Advanced.
Technical Skills- Experience with Defense Acquisition System processes including UCA, MTA, MCA, SW Acquisition and Acquisition of Services.
- Familiarity with DoD Security Requirements Guides (SRGs) and Security Technical Implementation Guides (STIGs) is required.
- In depth knowledge of DISA policy and guidance is required.
Additional InformationLocation: Palmdale, CATravel: NoneOn-site#LI-DD1