Cyber Security Specialist
CACI International Inc · Stafford, VA · 2 wk ago
OTHR$75k–$158k/yrFull-time
The Opportunity: CACI is seeking a Cyber Security Specialist to support our customer, Global Combat Support System – Marine Corps (GCSS-MC). This senior-level position provides Cyber Security oversight, guidance, and support following the Program Management Office (PMO) requirements.
Responsibilities
- Perform assessment and authorization coordination for STIG testing, advise and assist the customer with Risk Management Framework (RMF), and develop a Plan of Action and Milestones for resolving system deficiencies following DODI 8510.01 and NIST 800-37.
- Assess compliance against controls listed in NIST 800-53 Rev5 and support the Program Management Office (PMO) associated Assess & Authorize (A&A) records.
- Perform assessment, compliance, and validation of IT systems to support the Cybersecurity program at GCSS-MC.
- Execute a comprehensive assessment, compliance, and validation of the customer system and development environment to ensure compliance with regulations, security, and standards; advise GCSS-MC PMO on system risks, risk mitigation courses of action, and operations.
- Perform security evaluations and vulnerability assessment reviews using the DOD Assured Compliance Assessment Solution (ACAS), Nessus vulnerability scanning tool, and Security Content Automation Protocol tool.
- Identify applicable STIGs and perform assessments using the Security Content Automation Protocol tool and manual STIG review process.
- Serve as a liaison with network, application, and system administrators to correct identified deficiencies.
- Review new systems and applications being introduced into the GCSS or Development environment, identify issues, and draft POAM for the government, including eMASS POAMs and OPDIR POAM (USMC).
- Liaise with the Cyber PMO to ensure systems and applications meet the DISA Security Technical Implementation Guides (STIG) standards.
- Advise stakeholders on the adequacy of implementation of cybersecurity requirements.
- Provide DoD & MC RMF subject matter expertise to GCSS, including other Contractors, cross-functional teams, and assist with the development and execution of the RMF program. Familiarity with MC eMASS Workflows is a plus.
- Develop and maintain supporting documentation for new and existing networks, cloud environments, information systems, and technologies as they are introduced into the environments.
- Perform risk and vulnerability assessments of IT and IS for authorization; prepare Security POAM (OPDIR) for submission to the Cyber PMO.
- Track and report to Cyber PMO compliance with applicable Cybersecurity regulations and directives. Ensure timely notifications to prevent lapses in accreditations (e.g., 30, 60, and 90-day notices).
- Develop and maintain an Information Security Continuous Monitoring (ISCM) Plan addressing ongoing information security awareness, vulnerabilities, security controls, and threats to support organizational risk management decisions.
- Identify, assess, and advise on cybersecurity control compliance and associated risks.
- Coordinate with Cyber PMO to resolve security issues, A&A, connection approvals, change requests (CR), and waiver requests.
- Perform network, cloud, information systems, hardware, software, and device security assessments, as well as the application and execution of policy, including project management support services.
- Validate the patching of systems, perform validation scanning review, develop Plans of Action & Milestone (POA&Ms), and report as directed by applicable policies, procedures, and regulations.
- Provide subject matter expertise for system development and the implementation of Cybersecurity mitigation strategies.
- Develop and implement required processes, procedures, and capabilities to mitigate vulnerabilities and weaknesses for software and hardware deployment.
- Identify, implement, and validate the continued effectiveness of key performance parameters and applied security measures.
- Perform analytics on cybersecurity posture and provide reports to the Cyber PMO and applicable stakeholders as required per ISCM and ISSM direction.
- Lead small technical workstreams (up to five analysts) to develop automation for ACAS, STIG, and control analysis processes that reduce incident response cycles and improve accuracy.
- Conduct root-cause analysis and support corrective action efforts for cybersecurity incidents, working collaboratively with the USMC Cyber Operations Group (MCCOG) during penetration testing and vulnerability assessments.
- Develop cybersecurity automation or scripting for vulnerability management and compliance workflows.
- Apply experience with USMC cybersecurity processes and DoW-specific monitoring tools.
- Work with Splunk, AWS, OCI, or Azure cloud environments.
- Operate in Agile environments.
- Develop automation or AI-enabled capabilities to enhance cybersecurity operations.
Qualifications
- Bachelor’s degree in Cyber Security, Information Technology, or Computer Science with experience in Cyber Security.
- BS/BA and at least 3-5 years of ISSO experience in support of US Marine Corps or DoD programs.
- 5+ years’ experience with the Risk Management Framework (RMF).
- 5+ years’ experience using Assured Compliance Assessment Solution (ACAS)/Tenable Nessus Vulnerability Scanner.
- 5+ years’ experience with vulnerability and compliance assessment scanning tools and reporting.
- 5+ years of United States government security policies including, but not limited to, NIST 800-53 Rev 4/5, and NIST 800-171.
- Knowledge of DODI 8500.01, DODI 8510.01.
- Highly responsible, team-oriented individual with solid communication skills and work ethic; self-starter.
- Resiliency in dealing with challenging situations and environments.
- Security+ certification required.
- Excellent oral and written communication skills.
- Ability to connect the dots within a large operational system transitioning to a Cloud environment.
- Apply FedRAMP, FISMA, NIST, CNSSI, and Oracle Cloud IL4/IL5 security concepts to ensure technical solutions meet required compliance standards.
- Knowledge of non-networked connected systems and assessment activities of same is a plus.
- Experience with all RMF Steps and their execution within a demanding USMC environment is required.
- Understanding of the role of the contractor to support the government client is essential.
- Experience developing cybersecurity automation or scripting for vulnerability management and compliance workflows.
- Experience with USMC cybersecurity processes and DoW-specific monitoring tools.
- Experience with Splunk, AWS, OCI, or Azure cloud environments.
- Experience working in Agile environments.
- Familiarity with developing automation or AI-enabled capabilities to enhance cybersecurity operations is an added plus.
Benefits
- A culture of integrity, placing character and innovation at the center of everything.
- An environment of trust, valuing unique contributions and providing autonomy through a flexible time-off benefit and access to robust learning resources.
- A focus on continuous growth, advancing critical missions and building on a lengthy track record of business success.
Pay
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. The proposed salary range for this position is $75,200-$158,100.