Cybersecurity Analyst (3959)
Navarro Research and Engineering delivers comprehensive nuclear, environmental, and technical services to federal agencies, commercial enterprises, and private clients. Our expertise supports organizations such as the Department of Energy, the National Nuclear Security Administration, the Department of Defense, and NASA, as well as commercial industries facing complex engineering and environmental challenges.
About the role
The Cybersecurity subcontractor will execute all aspects of National Institute of Standards and Technology (NIST) directives to support the Risk Management Framework (RMF). Responsibilities include assisting information system owners with development of System Security Plans (SSPs) and Security Assessment Reports (SARs) using the RSA Archer application on the Naval Nuclear Propulsion Network (NNPP Net) to support information system authorization. The role also involves developing Plans of Action and Milestones (POA&Ms) and Risk Based Decisions (RBDs) for deficiencies identified during the authorization process.
Job locations: Bettis (West Mifflin, PA) or Knolls (West Milton, NY). Due to government contract requirements, US citizenship and an active DOE clearance or DOD equivalent are required.
Requirements
- At least four years of combined experience as a security control validator, security control assessor, Information System Security Officer (ISSO), or Information System Security Manager (ISSM).
- At least two years of experience supporting development of information system security authorization packages in accordance with Risk Management Framework (NIST 800-37, 800-53, 800-53a).
- At least two years of experience working with Federal Risk and Authorization Management Program (FedRAMP).
- Security+ Certification.
Qualifications
- Experience with the RSA Archer application.
- At least two years of experience working on IT security project teams.
- At least one year of experience managing IT projects.
- Knowledge of IT infrastructure and services (data centers, physical and virtual servers, local and wide area networking components, cloud Infrastructure/Platform/Software as a Service, etc.).
- Knowledge of security policies such as NIST Special Publications, Security Technical Implementation Guides (STIGs), DOD Cloud Computing Security Resource Guide (SRG).
- Knowledge of infrastructure security, endpoint protection, and vulnerability management tools.
- Previous work authorizing information systems within a classified DoE or DoD environment.
- Familiarity with NIST 800-171.
- Certified Information Systems Security Professional (CISSP) certification (desired).
- Certificate of Cloud Security Knowledge (CCSK) certification (desired).
Benefits
- Health Care Plan (Medical, Dental & Vision).
- Retirement Plan (401k).
- Life Insurance (Basic, Voluntary & AD&D).
- Paid Time Off (Vacation & Public Holidays).
- Short Term & Long-Term Disability.