Information Security Analyst SME
MAG Team is seeking an Information Security Analyst SME to provide services leveraging the Risk Management Framework (RMF) accreditation in Ft. Liberty, NC. This role involves validation, approval, and sustainment of cybersecurity accreditation packages, performing and analyzing Information Security Systems Officer (ISSO) activities, and assisting with the development and implementation of security policies.
Responsibilities
- Gather and translate customer requirements, interact with stakeholders, and lead efforts to ensure customer products and recommendations meet information security policies in a dynamic technical environment.
- Categorize IT systems and the information they process, store, and transmit based on an impact analysis due to loss of Confidentiality, Integrity, and Availability (CIA).
- Select an initial set of baseline security controls for the Information System (IS) based on security categorization; tailor and supplement the baseline as needed based on organizational risk assessment and local conditions.
- Assess security controls using appropriate methods and procedures to determine the extent to which controls are implemented correctly, operating as intended, and producing the desired outcome.
- Authorize the IS based on risk determination to organizational operations, assets, or individuals, ensuring acceptable risk levels.
- Monitor IS security on a continuous basis, including assessing control effectiveness, documenting system changes, conducting security impact analyses, and reporting security status to appropriate officials.
- Review, prepare, and update RMF authorization packages.
- Conduct assessments of information security controls to measure effectiveness and identify gaps.
- Manage remediation efforts and report on the status of control deficiencies.
- Provide security expertise to business units and key stakeholders.
- Deliver timely status updates and reporting on assessments and assigned projects.
- Travel as necessary for customer projects, technology expositions, and corporate meetings.
Requirements
- Compliance with DoD Cyber Workforce 8570.01.
- 5+ years of experience in Information Assurance/Cybersecurity, including development, integration, and implementation of cybersecurity and program protection standards for networking, computers, and custom applications.
- Thorough knowledge of DoD 8510.01 Risk Management Framework (RMF) for DoD IT, DoD Instruction 8500.1 Cybersecurity, DoD Directive 8140.01, NIST 800 Special Publications, Federal Information Processing Standards (FIPS), and current authorization practices within the DoD.
- Experience creating and maintaining security configuration baselines for Windows and Linux platforms, networking equipment, cloud technologies, and custom applications (e.g., CIS benchmarks, STIGS).
- Subject matter expertise in planning, implementation, and accreditation of technology and solutions.
- Must meet DoD Directive 8570.01-M requirements for Information Assurance Management (IAM Level II).
- BS in Computer Science or Information Technology (or equivalent experience).
- US Citizenship and an Active TS/SCI Clearance.
Qualifications
- Familiarity with DIA assessments and accreditation documentation within the XACTA management platform.
- Experience with eMASS – USSOCOM ENTERPRISE MISSION ASSURANCE SUPPORT SERVICES platform.
- Experience with cloud authorization processes.
- Ability to read, review, and consolidate ACAS scans, DISA STIGS, and Websense results.
- Excellent interpersonal skills, including the ability to work on multi-functional teams.
- Detailed knowledge and understanding of multiple technology infrastructures.
- Ability to serve as a principal advisor on all matters involving IS security.
- Proactive self-starter with initiative to influence events and achieve goals.
The position is contingent upon the candidate’s ability to meet physical and medical requirements, including compliance with all applicable federal, state, and local jurisdictional requirements. Government or customer site-specific requirements may include proof of full COVID-19 vaccination status, except where legally entitled to an accommodation.