Cybersecurity Specialist
LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed, serving the defense, space, healthcare, and energy sectors. Headquartered in Tysons, Virginia, LMI enhances outcomes for federal agencies through mission-ready technology and strategic expertise.
About the role
The Cybersecurity Specialist will support the Integrated Clinical System PMO’s mission to develop, manage, and perform end-to-end lifecycle logistics on medical equipment to protect and sustain the Warfighter and their families. This role involves working directly with DoD and vendors to test and evaluate medical equipment operating systems on the DoD network, ensuring compliance with the DoD Risk Management Framework (RMF) and protection against threats. The position requires the ability to obtain a Public Trust Clearance (NACI) and is open to U.S. citizens. This is a hybrid role with onsite requirements of 3 days per week at the client site in Frederick, MD.
Responsibilities
- Work with LMI’s team to ensure appropriate administrative, physical, and technical information security safeguards are implemented across a portfolio of deployed military medical devices.
- Conduct information security assessments and testing to ensure proper implementation of security controls, including populating security/risk assessments, identifying gaps and compensating controls, and publishing management reports.
- Participate in incident response investigations and identify opportunities for product improvement.
- Maintain policies and procedures designed to be operationally effective and efficient, and monitor compliance with policies, laws, and regulations.
- Select and deploy technical controls to meet specific security requirements and define processes and standards to maintain security configurations.
- Conduct evaluations of technical and non-technical security safeguards to demonstrate and document compliance with DoD’s Risk Management Framework (RMF).
- Perform information security risk assessments as part of the project lifecycle to ensure new medical device technology conforms to security standards.
- Perform Independent Verification and Validation (IV&V) testing, including documentation of Plan of Action and Milestones (POAM) data within the DoD system.
- Perform risk assessments of information and technology systems to identify potential risks and vulnerabilities to confidentiality, integrity, and availability.
- Work with security leadership and stakeholders to identify remediation strategies and plans to enforce security requirements.
- Advise during application development or acquisition projects to ensure security controls are implemented as planned.
- Assist in scoping, planning, and conducting third-party penetration testing, code reviews, or security assessments.
- Perform risk assessments of third-party technology systems and produce reports identifying gaps with DoD Security Policies & Standards, including proposed remediation plans.
- Assist in conducting information system activity reviews and participate in RMF testing exercises and activities.
- Monitor and test application and network activity to ensure systems of controls are in place and effective, and compliant with DoD policies and federal regulations.
Requirements
- Bachelor’s degree in a related discipline or a minimum of four (4) years of relevant experience.
- Ability to obtain a Public Trust Clearance (NACI); U.S. citizenship required. Active Secret Clearance preferred.
- CompTIA Security+ Certification.
- Working knowledge of internal controls, IT risk assessment, and mitigation procedures.
- Technical experience in security-related technologies such as encryption, remote access, and anti-virus systems.
- Basic knowledge of the 8 domains of the Common Body of Knowledge for information security:
- Security & Risk Management
- Asset Security
- Security Engineering
- Communications and Network Security
- Identity and Access Management
- Security Assessment and Testing
- Security Operations
- Software Development Security
Desired Qualifications
- Experience with medical devices or a working knowledge of security frameworks such as HIPAA, HITRUST, NIST, ISO, or other industry standards relevant to the DoD medical enterprise.
Pay
Target salary range: $86,126 – $125,000.
Schedule
Hybrid remote position with onsite requirements of 3 days per week at the client site in Frederick, MD.