Responsibilities: Performs Cybersecurity activities for a large Program; coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures. Support the government ISSMs in the development and staffing of documentation related to the Authorization to Operate (ATO), Authorization to Connect (ATC), Interim Authorization to Test (IATT), Plans of Action & Milestones (POA&Ms), etc. Assist in the development and execution of any required Security Test and Evaluation (ST&E) plans. Produce and provide A&A materials (to include engineering project briefs and outstanding RMF actions? for DoD IT packages by phase, including expiring authorizations and the resolution of issues impacting those packages). Provide USG with a review of architecture documentation, security impact analysis, and risk mitigation/acceptance to support RMF for DoD IT authorization. Provide security design management control of build processes for servers, services, and end points. Comply with hosting facility ATOs where the MPCO IS are dependent on them. Ensure good cybersecurity and vulnerability management practices are developed, implemented, and enforced. Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), DISA SCAP, ACAS vulnerability scanner, ESS Policy Auditor to mitigate those findings for Linux, Windows, Cisco, Juniper, VMWare and other associated operating systems and technologies. Implement the Continuous Monitoring program by creating, tracking, reviewing, and closing Plan of Action and Milestones (POA&Ms) and Risk Acceptances and assist in conducting solution identification to assist in problem remediation and resolution. Communicate tactical and strategic threat information to Government leaders, Cybersecurity-Ops and A&A Staff to assist them in making cyber risk decisions and to mitigate threats. Carries out DoD Risk Management Framework (RMF) in accordance with DoD 8510 to ascertain information systems' security posture by utilizing security control validation activities and coordinating security testing. Coordinates with AFRL, and USAF, and other organizations in support of audits and inspections and provides all necessary documentation as required for SAVs, ST&Es, and CCRI Evaluate change requests (firewall, systems, networks) and assess organizational risk. Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices. Provides guidance and work leadership to less-experienced technical staff members. Maintains current knowledge of relevant technology as assigned. Process tickets in support of the program using the accepted ITSM system.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees