Overview:
GovCIO is currently hiring for a Cyber Security Analyst SME / Information Systems Security Manager (ISSM) to support the 39th Information Operations Squadron. This position will be located at Hurlburt Field, Florida and will be an onsite position.
Responsibilities:
Responsibilities:
Provide extensive engineering, technical, and operational analytical support services. This includes performing in-depth technical assessments of vendor solutions, malware reverse engineering, network and cloud analytics, and emerging technology in support for Defensive Cyber Operations Training. The contractor shall manage cybersecurity compliance, Information Assurance (IA) oversight, network accreditations, and the required security support services for current and future systems. The contractor shall manage the development of all Risk Management Framework (RMF) artifacts required in support of accreditation including the Security Plan (SP), Security Assessment Report (SAR), Security Controls Traceability Matrix (SCTM), and Plans of Action and Milestone (POA&M).
Essential Duties and Responsibilities:
* Support Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts.
* Assist DoD, National Agency, and Contractor organizations with the development of assessment and authorization (A&A) efforts leading to ATO approval as required.
* Provide "day-to-day" support for Collateral and Sensitive Compartmented Information (SCI).
* Review, prepare, and update RMF authorization packages.
* Notify customer when changes occur that might affect RMF authorization.
* Perform self-inspections, provide security coordination and review of all system test plans.
* Identify system and network vulnerabilities and implement countermeasures.
* Represent the customer on various technical review and inspection teams.
* Conduct security surveys at subordinate facilities and gather pertinent security documentation for inclusion into system authorization packages.
* Manage security records and prepare Co-Utilization Agreements for network nodes operating in government facilities.
* Perform ISSM duties in support of in-house and external customers.
* Additionally, the candidate will assist Department of Defense, National Agency, and Contractor organizations with the development of assessment and authorization (A&A) efforts leading to ATO approval as required.
* Communicate with site leadership, co-workers, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.
* Oversee user and privilege user account management.
* Leverages technical knowledge of computer systems and networks with cyber threat information to assess the client's security posture.
* Apply information technology security principles, complete weekly system audits, and conduct security reviews.
* Occasional travel to support customer at conferences and security review boards.
Qualifications:
High School with 10+ years (or commensurate experience)
Required Skills and Experience
* Clearance Required: TS/SCI
* Certification requirement: (IAM) Level III certification.
* Thorough understanding of RMF process.
* Knowledge in the Cybersecurity Assessment and Authorization process to support DoD acquisition programs through the RMF process.
* Significant knowledge of Windows and Linux Operating Systems.
* Experience performing Security Operations in virtual environments.
* Analytical skills and problem-solving skills.
* Good organization, decision making, and verbal and written communication skills.
* Excellent self-initiative and self-motivation with the ability to work under minimal supervision.
* Ability to work effectively in small and large team settings to solve complex problems.
* Working knowledge of Microsoft Office Products.
* Able to lift 50 lbs.
* Eligibility for access to Special Access Program Information.
* US Citizenship.
Preferred Skills and Experience
* Bachelor's Degree with 5 to 8 years (or commensurate experience).
* Encryption and PKI.
* Experience in cybersecurity testing and/or leading cyber test events.
* Experience using tools like eMASS, Xacta, DISA STIG Viewer, DISA STIGs, ACAS, NESSUS, Nmap.
* DISA STIG Implementation
* Dynamic Access Control / Identity Management.
Share this job:
Share this Job