Risk Management Framework SME - Military veterans preferred

2019-01-04
SAIC (www.saic.com)
Other

/yr

  full-time   employee


Hanahan
South Carolina
29410
United States

Description

RMF Analyst  

 

This individual will be responsible for supporting vendor and assigned ISSM efforts to develop RMF packages and providing relevant cybersecurity expertise. They will help take a Defense Health Agency (DHA) Program of Record (POR) through a full accreditation assessment and achieve an ATO. 


Responsibilities include:

  • Support and coordinate workflow, activity, and documentation necessary to achieve successful DIACAP C&A (and/or RMF A&A efforts) for various DoD environments. 

This includes:

  • Coordination among myriad stakeholders, e.g., Security Engineers, Network Administrators, System Administrators, Information Assurance Managers (IAMs) / Information Systems Security Managers (ISSMs), certification authorities (and representatives), accreditation authorities (and representatives), program managers, vendors, etc., necessary to properly identify, document, mitigate, and manage risk attributed to the target system, network, and/or application;
  • Identify, develop (either directly, or in coordination with applicable experts), and incorporate common artifacts found in a DIACAP (or RMF) accreditation package, e.g., system architecture and boundaries, hardware and software inventories, risk assessment reports, POA&Ms, data flows, PPSM accounting, and other necessary system, network, and application documentation;
  • Knowledge and experience identifying, assessing, and documenting compliance against applicable DoD IA security controls (technical, management, operational), Service (e.g., Army) regulations, etc., within the DIACAP (and/or RMF) package;
  • Familiarity with the use of vulnerability scanning and assessment tools (e.g., ACAS/Nessus) necessary to identify and document compliance;
  • Knowledge of and ability to use applicable compliance and accreditation reporting environments (e.g., eMASS, CMRS) to document the progress of C&A (A&A); 

 

Qualifications

Qualifications:

  • Bachelors Degree or 4 years additional years experience in lieu of degree
  • 2 years of related experience 
  • Capable of providing thought leadership to the ISSM in his/her efforts to maintain an organizational or system-level cybersecurity program, consistent with DoD appointment memorandum focal points (e.g., cybersecurity architecture, compliance requirements, objectives and policies, personnel, and processes and procedures).
  • Ability to identify, interpret and evaluate major applications, infrastructure, enclaves, and Enterprise system environments based on proposed accreditation boundaries.
  • Ability to manage multiple projects simultaneously
  • Strong verbal and written communications and interpersonal skills
Desired: 
  • Minimum of an IAT level II certification. IAT/IAM level III certification is preferred.
  • Experience with Amazon Web Services is desired.
Clearance Requirement:
  • Must currently possess Secret clearance.
DISL