NQV Information Security Analyst
Professional Software Engineering, Inc. (PROSOFT) · Portsmouth, VA · 3 wk ago
On-siteInformation TechnologyFull-time
Location: Norfolk Naval Shipyard – 100% on-site. Top Secret clearance required.
About the Role
The Information Security Analyst (NQV) supports the Department of Defense Risk Management Framework (RMF) and validates Network and System assets.
Responsibilities
- Follow Accreditation & Authorization (A&A) process and standards.
- Perform system and network vulnerability analysis.
- Conduct risk assessment and risk mitigation analysis.
- Perform Security Test and Evaluation (ST&E) processing.
- Validate Security Technical Implementation Guide (STIG) processing using automated tools (e.g., Security Content Automation Protocol (SCAP), Evaluate STIG, STIGMAN, EMASSter).
- Use Enterprise Mission Assurance Support Services (eMASS) and similar RMF repositories.
- Set up and execute A&A Business Rules, Standard Operating Procedures (SOP), Concept of Operations (CONOP), and Plans.
- Perform contingency planning, training, and testing.
- Establish and interpret firewall policy.
- Identify, interrupt, register ports and protocols.
- Review hardware/software, network boundaries, flow diagrams, and technical drawings.
- Identify interrupting information in the system baseline configuration in VRAM by uploading vulnerability scans of a representative baseline system.
- Advise on proper methods to mitigate vulnerabilities.
- Produce executive documents, reports, project plans, and Plans of Action and Milestones (POA&M).
Requirements
- Minimum of seven (7) years of experience in CS/A&A analysis support in IA controls analysis, conducting risk assessments, risk mitigation analysis, or developing plans.
- Qualified and registered as a Navy Qualified Validator (NQV).
- Expert knowledge of and experience with CS/RMF requirements as defined by Public Laws, National, DoD, and DON (e.g., Federal Information Security Management Act (FISMA), DoDD 8100.02, DODI 8500.01, DoDI 8520, DoDI 8530, DoDI 8531, SECNAV 5239 Series and OPNAV 5239 Series, NIST Special Publications Series 800, etc.).
- Expert and mastery levels with institutional knowledge on mission-critical procedures, systems, and processes as they pertain to Information Technology and Cyber Security requirements.
- Experience in certifying and accrediting DON information systems and networks, as well as Platform IT.
- Expert knowledge and experience with the requirements outlined in OPNAVINST N9210.3 Safeguarding Naval Nuclear Propulsion Information.
Qualifications
- Bachelor’s degree in an IT-related discipline, or
- Level II Certification (Security+ or better) and a minimum of seven (7) years of experience.
Certifications
- Active Security+ CE or higher.
- Active Navy Qualified Validator (NQV).