Responsibilities
Support the NUWCDIVNPT in a Mid-Senior RMF ISSE Role and perform tasks related to Assess and Authorize (A&A) to maintain Authorizations to Operate (ATOs) systems (i.e., applications, networks, devices), and perform the following:
Â
- Provide a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.
- Become familiar with the system/site by reviewing the Assessment and Authorization (A&A) System Security Plan for existing systems; identify any issues with the Security Plan and Procedures; execute the Security Assessment Plan and process Security Test Report; review POA&Ms; develop/perform Risk Assessment analysis.
- Keep abreast of and provide the team with updated information on Navy RMF policies and procedures. Review DoD, DON, NAVSEA CS-related documentation (i.e., RMF Process Guide, Navy SCA Risk Assessment Guide, DoN Standard Operating Procedures, NAVSEA Business Rules).
- Be comfortable conducting independent security control assessments in accordance with NIST SP 800-53, 800-53A, CNSSI 1253, and the Risk Management Framework (RMF) described in NIST SP 800-37.
- Clearly articulate requirements and other information in written documentation such as Security Plan, Contingency Plan, Contingency Plan Test, Business Impact Analysis, etc.
- Provide guidance and training in eMASS to team members.
- Demonstrate strong organizational and time-management skills: multitasking, working individually and with a team, having a positive attitude, being self-motivated and reliable, being trustworthy, having strong interpersonal and diplomatic skills, and being able to handle stress in a professional manner.
- Attend stakeholder meetings, capture and track action items, and follow up with stakeholders to ensure timely completion.
Qualifications
- BS 5-7, MS 3-5, PhD 0-2
- Possess and Maintain a Secret Clearance
- Minimum 6+ years of professional cybersecurity experience and Risk Management Framework
- Demonstrated expert-level experience with Risk Management Framework
- Experience in RMF policy development, process improvement, and strategy implementation
- Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes
- Must have an 8570.01M IAM/IAT Level II Certificate (Security + at a minimum CAP or CASP /CISSP preferred)
- Strong National Institute of Standards and Training Special Publications (NIST SPs) knowledge
- Must be able to manage multiple projects at a time
- Assessment and Authorization (A&A formerly C&A, i.e. RMF and DIACAP respectively)
- Experience with ACAS, STIG OSS Manager, STIGViewer, eMASS
- Knowledge and experience with practices and procedures for CMMI Software Development Level 3 or greater is a plus
- Knowledge in Continuous Monitoring
- Excellent customer service and organization skills
- Excellent oral and written communication skills
- Demonstrated expert-level experience with DISA STIGs and SRGs
Equal Pay Act
This is the projected compensation range for this position. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, Arcfield invests in its employees beyond just compensation. Arcfield ’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, Short Term and Long-Term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections. Min: $87,163.99 Max: $151,561.26
EEO Statement
We are an equal opportunity employer and federal government contractor. We do not discriminate against any employee or applicant for employment as protected by law.
Learn more about this Employer on their Career Site
