Cybersecurity Assessment & Authorization SME
Remote role but must live within 150 miles of the DLA Location: Ft. Belvoir, VA (HQ). Position is contingent upon contract award.
About the Role
The Cybersecurity Assessment & Authorization SME will assist in managing the implementation, maintenance, and monitoring of cybersecurity in support of the J6 Program Executive Officer's Portfolio of IT capabilities, associated Program Management Offices, IT infrastructure support, and Operational Technology areas for Information Systems/Programs throughout their system development life cycle. This role serves as a cybersecurity Subject Matter Expert (SME) for Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures.
Responsibilities
- Execute DoW/DLA cybersecurity processes to authorize information systems, maintain authorization, or serve as an SME for systems undergoing the authorization process.
- Understand how security controls identified in NIST 800-53 apply to assessing and authorizing a large organization’s IT infrastructure, including large and small enclaves, Cloud Hosted Services, Operational Technology, AIS applications, and outsourced IT processes.
- Determine the residual risk of identified vulnerabilities (e.g., non-compliant security controls) and assess possible ramifications on the system’s current or future authorization.
- Brief senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process.
Requirements
The role includes four key positions with the following minimum requirements:
KP-1 Enterprise RMF & Authorization Lead
- Five years of RMF, C&A, and DoD cybersecurity experience.
- Experience conducting authorization reviews.
- Secret clearance (Tier 3/NACLC/ANACI).
- IAM Level III certification (CISSP, CAP).
- Experience as a former ISSM, SCA, AO support staff, or Cyber Program Lead.
- DLA or Fourth Estate experience.
- eMASS administration experience.
- Experience briefing SES and Flag Officer equivalents.
KP-2 Security Control Assessment Lead
- Five years of RMF and NIST experience.
- Security control assessment experience.
- Authorization review experience.
- Secret clearance (Tier 3 investigation).
- IAM Level III certification (CAP, CISSP, CISA).
- Extensive NIST 800-53 assessment background.
- Experience conducting SCA-style reviews.
- Knowledge of FISMA and Federal compliance frameworks.
KP-3 Continuous Monitoring & Vulnerability Management Lead
- Five years of DoD cybersecurity experience.
- RMF experience.
- Secret clearance (Tier 3 investigation).
- IAM Level III certification (CISSP, SecurityX formerly CASP+).
- ACAS experience.
- Enterprise vulnerability management experience.
- STIG implementation expertise.
- POA&M governance experience.
KP-4 OT, Cloud & Emerging Technology Security Lead
- Five years of DoD cybersecurity experience.
- RMF and C&A experience.
- Authorization review experience.
- Secret clearance (Tier 3 investigation).
- IAM Level III certification (CISSP).
- CCSP or AWS/Azure security certification.
- OT/ICS security experience.
- Cloud authorization experience.
- Experience supporting hybrid architectures.
- Experience with platform and enclave authorizations.
Preferred Qualifications
- Excellent analytical and writing skills.
- Proficiency in Microsoft Office programs (Excel, Word, PowerPoint, MS Project, etc.).
- Experience working with DoD/DLA.
Pay
The anticipated salary range for this position is $115,000.00 to $125,000.00 USD.
Benefits
- Health, dental, vision, life, and disability insurance.
- 401(k) package.
- Generous Paid Time Off.
- Ongoing professional development opportunities.