Security Control Assessor II (SCA II), (TS, w/ SCI Eligibility)
RedTrace Technologies · Kirtland, NM · 4 days ago
On-siteInformation TechnologyFull-time
Responsibilities
- Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
- Assess ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG)
- Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues
- Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization
- Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
- Advises the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
- Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
- Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
- Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
- Discuss recommendation for authorization and submit the security authorization package to the AO/DAO
- Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate
- Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy
- Assist the Government compliance inspections
- Afford security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
- Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
- Evaluate the effectiveness and implementation of Continuous Monitoring Plans
- Differentiate the differences between the various types of Cross-Domain Solutions (CDS)
- Afford joint assessments of Cross-Domain Solutions with other DoD agencies
Qualifications
- 9 - 12 years related experience
- Bachelor’s degree in a related discipline or equivalent experience (4 years)
- 9+ years’ experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties.
- Prior performance in the role of ISSO and ISSM or SCA
- Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level III or Information Assurance Architect and Engineer Level I within 6 months of the date of hire
- Must have expert knowledge of DoD, National and applicable service and agency security policy, manuals and standards
- Must have the ability to work in a dynamic environment and effectively interact with numerous DOD, military/civilian personnel and industry partners
- IAM Level III or IAAE Level I (in lieu of IAT Level III)
- Mastery of Microsoft Office (Word, PowerPoint, and Excel)
Security Clearance Requirement
TS clearance with SCI eligibility. Position requires U.S. Citizenship.
Employee Benefits
- Competitive salary for well qualified applicants
- 401(k) plan
- Annual performance bonus
- Certification and advanced degree attainment bonuses
- Student Loan / Tuition reimbursement
- Health Care Insurance (medical, dental, vision)
- Up to four weeks of paid vacation
- 11 Federal Holidays, and 3 Floating Holidays
- Team bonding events