Boarhog is interested in bringing aboard a Tactical Networks Cybersecurity Analyst to coordinate all cybersecurity activities to support Assessment and Authorization (A&A) Package documentation planning and development. Responsibilities include:
- Prepare, develop, and maintain Risk Management Framework (RMF) artifacts, packages, and deliverables to support system validation and authorization to operate (ATO)
- Perform risk and vulnerability assessments in network, system, and application areas
- Coordinate day-to-day cybersecurity operations with program technical leads to discover cyber risks, understand applicable policies, and develop mitigation plans
- Maintain RMF documents for system baseline variants that have achieved ATO
- Work independently, identify problems and devise analysis and solutions, communicate results to both technical and non-technical audiences, and lead the accomplishments of client tasks from inception to completion
- Develop and deliver cybersecurity update presentations to high level stakeholders that incorporate analysis of National Institute of Standards and Technology (NIST) controls and identified expected system and workload impacts
LOCATION: Hybrid-site billet located in San Diego, CA. No travel is anticipated.
EXPERIENCE: Minimum of four (4) years of experience in a Cybersecurity, Engineering, Test and Evaluation (T&E) or A&A related field. Experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS), as well as the specific LCAT experience requirements the candidate is proposed under. See additional specific position requirements below.
EDUCATION: Bachelor degree from an accredited university in a technical or managerial related discipline
CLEARANCE: TS/SCI with no Foreign Exception Package (FEP) requirements. PLEASE ONLY APPLY IF YOU CURRENTLY HOLD AN ACTIVE TOP SECRET CLEARANCE.
ADDITIONAL POSITION-SPECIFIC REQUIRED QUALIFICATIONS:
- 4+ years experience working with the Information Technology (IT) systems for a DoD or government agency
- 3+ years experience leading Navy RMF projects, including A&A activities for up-to TS/SCI systems, and the preparation, direct development, and maintenance of RMF artifacts, packages, and deliverables
- 3+ years Implementing security controls and policies, performing cybersecurity compliance testing using industry standard tools, and performing vulnerability analysis and remediation of networks, systems, and communications protocols
- Experience with eMASS, including Security Plan development and hands-on processing of packages through workflows, assisting with generating security policies, evaluating assessment documentation, and developing written security risks, mitigations, and recommendations