Cybersecurity SME (Junior)
$120,000–$120,000 year
On-siteAlexandria, Virginia, United States
Job Summary
Conduct continuous monitoring on all AGC-supported systems and networks, identifying and resolving cybersecurity incidents while managing vulnerability scanning and remediation. Develop security guidelines, plans, and analyses for incident response, RMF accreditation, and compliance with IAVM, STIG, and SRG requirements. Maintain Tenant Security Plans and eMASS records, coordinate with enterprise service providers for assessment tools, and prepare documentation for Authority to Operate decisions. Provide technical support and documentation to enable systems to meet DoD Risk Management Framework standards.
Required Qualifications
- DoD 8570.01-M IAM II
- Active TS/SCI clearance
- 5+ years of relevant experience with DoD in an IA/Cybersecurity role
- Trained and experienced with DoD vulnerability scanning tools, including Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol Compliance Checker (SCAP), Security Technical Implementation Guide (STIG) Viewer, Endpoint Security Solution (ESS), and AWS GovCloud security tools, including AWS Security Hub, Amazon Inspector, AWS Config, Amazon GuardDuty, Amazon Detective, and Amazon Macie
- Must be proficient with related automated tools, including but not limited to the Enterprise Mission Assurance Support Service (eMASS), Host-Based Security System (HBSS), and Assured Compliance Assessment Solution (ACAS)
- Expert knowledge and in-depth experience with Application and system assessment, determination of accreditation requirements (Assess Only, ATO, IATT, etc.)
- Expert knowledge and in-depth experience with Categorization of information systems and/or data types IAW NIST SP 800-60 Vol II
- Expert knowledge and in-depth experience with Establishment of Security Requirements Traceability Matrix, which identifies applicable DISA STIGs and SRGs
- Expert knowledge and in-depth experience with Selection of security controls per NIST SP 800-53 and CNSSI 1253
- Expert knowledge and in-depth experience with Writing System Security Plan (SSP), associated security controls assessment artifacts, and PO&AMs
- Expert knowledge and in-depth experience with Application of DISA STIGs and SRGs
- Expert knowledge and in-depth experience with Management of security controls assessment artifacts in eMASS in preparation of packages for RMF (DoDI 8510.01, NIST SP 800-37) processes
- Expert knowledge and in-depth experience with Evaluation of security controls per NIST SP 800- 53A
- Expert knowledge and in-depth experience with Implementation of continuous monitoring solutions per NIST SP 800-13
- Knowledge and experience with current DoD and Army IA policies and procedures, RMF certification and accreditation procedures and requirements, APMS reporting procedures, and an understanding of the unique acquisition community IA issues
- Knowledge and experience in the security sub-disciplines supporting Army IA, certification and accreditation, IA security testing, and security management for both developmental and production systems, including but not limited to Communications Security, Physical Security, OPSEC, Risk Assessments, Personnel Security, Tempest, Network Security, Security Inspections, and User Training
- Must have advanced working knowledge of a variety of computer software applications in word processing, spreadsheets, database (MSWord, Excel, Access, PowerPoint), and Outlook
Desired Qualifications
- BA/BS degree
- IASE III certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.