Risk Management Framework Cyber Engineer
$86,800–$198,000 year
On-siteEl Segundo, California, United States
Job Summary
Guide clients through the entire Risk Management Framework (RMF) process, including DoDI 8510, AFI 17-101, NIST SP 800-37, and NIST SP 800-53. Evaluate potential weaknesses and the effectiveness of mitigations for cybersecurity solutions while providing advice on security control implementation. Interpret security controls and requirements to communicate with system developers, sustainment teams, and stakeholders. Develop and interpret technical specifications, plans, schedules, system diagrams, and network diagrams to assess control satisfaction. Assess and inform key stakeholders on dynamic adversarial tactics, techniques, and procedures using research and analysis abilities. Use the Enterprise Mission Assurance Support Service (eMASS) system and knowledge of Space Vehicle cybersecurity requirements such as CNSSI 1253. Apply cybersecurity to the development and delivery of cyber resilient systems for our nation's defenses.
Required Qualifications
- 4+ years of experience with guiding a client through the entire Risk Management Framework (RMF) processes, such as DoDI 8510, AFI 17-101, NIST SP 800-37, or NIST SP 800-53
- Experience in interpreting security controls and requirements to communicate with system developers, sustainment teams, and other stakeholders
- Experience with developing and interpreting technical specifications, plans and schedules, system diagrams, and network diagrams to assess control satisfaction
- Experience with using security tools, including the Enterprise Mission Assurance Support Service (eMASS) system
- Knowledge of Space Vehicle cybersecurity requirements, such as CNSSI 1253 Space Platform Overlay, or CNSSP 12
- Knowledge of information technology solutions used to implement security controls, such as boundary protection, data encryption, authentication, audit logs, or vulnerability scanning
- Secret clearance
- Bachelor's degree
- DoD 8140 Intermediate Certification level for Security Architect, System Testing and Evaluation Specialist, Information Systems Security Manager, or Information Systems Security Developer, such as CASP+, CEH, GSEC, Security+, or CGRC
- Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information
Desired Qualifications
- Experience with Cyber Test and Evaluation processes, such as Cyber Table Top
- Experience with space-based remote sensing systems
- Knowledge of DoD 5000.01/02 TS/SCI clearance
- Bachelor's degree in Information Technology, Cybersecurity, or Engineering preferred
- Master's degree a plus
- DoD 8140 Advanced Certification level for Security Architect, System Testing and Evaluation Specialist, Information Systems Security Manager, or Information Systems Security Developer, such as CISSP-ISSEP, CISSP-ISSAP, CISM, GDSA, GICSP, or GCIH
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.