Description:
Supporting A&A processes (Assessment & Authorization) by developing artifacts, implementing policies, assessing security controls, and ensuring compliance with Federal, DoD, and Intelligence Community (IC) standards
Monitoring and assessing cybersecurity posture by conducting regular vulnerability and compliance assessments, reviewing system security configurations, and coordinating responses to potential threats and incidents
Assisting in the implementation of security solutions, including firewalls, IDS/IPS, and endpoint protection software, and assist with their configuration and testing
Conducting risk assessments and assisting in identifying and mitigating cybersecurity risks based on system vulnerabilities, potential threats, and overall risk exposure
Tracking and managing security risks through a Plan of Action and Milestones (POA&M), ensuring corrective actions are applied, documented, and closed within established timelines
Assisting in incident response activities, including analyzing security incidents, escalating as needed, and performing root cause analysis for systemic vulnerabilities
Collaborating with the Government's security team to ensure security controls are implemented and continuously updated to address new and emerging threats
Maintaining and updating documentation for system security policies, standards, and procedures related to cybersecurity
Providing support for security audits, risk assessments, and continuous monitoring activities
Supporting the creation and execution of incident response plans, ensuring that mitigation strategies are in place and that security incidents are handled swiftly and efficiently
#LI-DH1
Requirements:
Bachelor's or master's degree in information systems, Cybersecurity, or related field, or equivalent combination of education and experience
Minimum of 5-8 years of direct experience in cybersecurity, with at least 3 years of hands-on experience in an ISSO or security role, preferably with DoD or government entities
Current Top-Secret clearance with SCI eligibility or ability to obtain SCI clearance
Demonstrated experience with cybersecurity principles and risk management frameworks (RMF, NIST, etc.)
Comprehensive knowledge in key cybersecurity areas including incident response, security control implementation, risk analysis, and system assessments
Ability to plan, assess, and implement security controls, monitor system security, and track issues to resolution
Experience working with and supporting cybersecurity governance and regulatory compliance requirements
Strong ability to communicate security issues, risks, and mitigations to stakeholders at various levels (technical and non-technical)
Team-oriented with leadership potential to guide and mentor junior staff as needed
Proficient in using security tools such as SIEM, vulnerability scanners, security technical implementation guide (STIG) and risk management systems
Desired Skills:
Certifications:
+ Certified Information Systems Security Professional (CISSP)
+ Certified Information Security Manager (CISM)
+ Certified in Risk and Information Systems Control (CRISC)
+ Offensive Security Certified Professional (OSCP)
+ Additional DoD security certifications (e.g., IAM, IEM)
Extensive DoD experience and knowledge of DoD Cybersecurity policies and frameworks
Experience working in Sensitive Compartmented Information (SCI) environments
Knowledge of vulnerability management and compliance tools and their integration into risk mitigation strategies
Clearance Information:
MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.