Computer Security Specialist: A&A/RMF

General Dynamics

Type of Requisition: Regular

Clearance Level Must Currently Possess: Secret

Clearance Level Must Be Able to Obtain: Secret

Suitability: No Suitability Required

Public Trust/Other Required:

Job Family: Information Security

Job Description:

GDIT is seeking a Security Computer Specialist: A&A/RMF to provide services to the JSP Enterprise Transport Management contract at the Pentagon in Arlington VA. NOTE: Due to the type of access this role entails, telecommuting is not allowed.

In this role, you will apply your understanding of computer security, military system specifications, and Department of Defense Information Assurance (DoD) (IA) policies, in the execution of all aspects of the systems and their Cybersecurity posture. This position is responsible for execution of the DoD Information Assurance Risk Management Framework (DIARMF), and the implementation of Cyber Security and IA boundary defense techniques, various IA-enabled network technologies and appliances to facilitate certification and security engineering tasks in support of the customer.

You will partner with IT Security Analysts and Enterprise Architects to establish, understand, and adhere to technical and IT security standards. Involved in all aspects of the technology life-cycle to ensure that non-functional and functional requirements are adhered to in design and build so solutions are stable, secure, resilient, and perform well. This position will work under general supervision to provide Cybersecurity engineering documentation services to build secure technical documentation for applications, systems, architectures, and infrastructure that are operationally viable and efficient.

Providing mid-level Assessment and Authorization support, you will lead the manual and application based STIG evaluations for the network enterprise. This position will be responsible to plan, develop, and execute automated and manual tests to validate security posture/controls in accordance with DOD 8500.2/8510.01. This position will work directly with teams that support DoD Information Assurance Certification and Accreditation (DIACAP) and Risk Management Framework (RMF). You may also be tasked to engage the JSP CA Liaisons, SCA Reviewers, and ISSMs to discuss and obtain mitigation guidance.

A typical day in this position will include:

Author DoD IA Assessment and Authorization (A&A) artifacts.

Document a system from an IA perspective

Derive, document and/or identify system CONOPS for Mission Assurance Categorization per DoDI 8500.2

Lead the research, recommend and document logical and physical solutions that prevent, detect and correct the system to be certified and accredited

Research and apply DISA Security Technical Implementation Guides (STIGs) and NSA recommendations

Lead the identification of disagreements between as built specifications, security requirements and DoD security policies and design implementations to bring the system into compliance.

Plan, develop, execute and document results of security test procedures

Lead the preparation and execution an Information Assurance Vulnerability Management (IAVM) Plan

Lead the preparation and production of a System Security Plan (SSP) and Plan Of Action and Milestones (POA&M)

Lead the technical support effort in identifying and specifying requirements and performing risk assessments

Lead or Develop Standard Operating Procedures (SOP)

Ensure IT solutions meet requirements for security, availability, capacity, resiliency, and performance in a way that is efficient and supportable, reducing overall support costs

Understand industry leading solutions and trends for assigned technologies and applying those as appropriate

Understand business needs and partnering with appropriate IT counterparts to recommend technology solutions

Establish and maintain an IT multi-year strategy with a focus on continuous improvement. Create and maintain solutions architecture artifacts and other strategy and system documentation

Use tools such as Host Based Security System (HBSS), Assured Compliance Assessment Solution (ACAS), Junos Space, Cisco Prime and Cisco Adaptive Security Appliance

Assist the government with input, instructions, and guidance as needed for the creation of adequate package documentation and artifacts.

Develop and present briefings to technical and senior management audiences and communicate assessment results, risk analyses, mitigation strategies, and forward plans

Required Qualifications:

Active Secret security clearance

Computing Environment certification – Examples: Linux+, RHCSA, RHCE, RHCSS (Other Examples – MCSE Server 2012, MCSA Server 2012, MCSE Productivity, Linux+, RHCSA, RHCE, RHCSS, LPIC-1, LPIC-2, Novell Certified Linux Engineer, Oracle Solaris System Administrator (OCA, OCP or OCF), GCUX, BSDA, CSE – Specialty in Networking and Security – HP-UX, etc.

DoD 8570 IAT/IAM Level II or Level III certification - Examples: Security+ CE, SSCP, GSEC, CISSP, CISA, CASP, CISM, GSLC, CAP, CASP, CISM

Bachelor's Degree in Computer Science, Engineering or Information Technology field OR equivalent work experience in lieu of degree

5 years of experience in information technology

Experience with performing both manual AND tool performed STIGs

Experience with computer networking and telecommunication architecture, the OSI model, and communications protocols

Experience in collaborating with multiple technical teams to drive solutions that requirement driven including technical subject matter experts, including hardware and software designers, operations personnel, and test engineers and communicate potential security risks and mitigations

Experience in organizing and coordinating deployments of complex systems

Experience with OS Tier 2 Support in heterogeneous operating system environments (Linux, Windows)

A working knowledge of deployment methodologies and tooling

Experience using Microsoft Office including MS Visio, MS Word, MS Excel and other appropriate tools.

Experience with DoD Certification and Accreditation (C&A) process, DoD Authorization & Accreditation including familiarity with Risk Management Framework (RMF) and the process to obtain an Authority to Operate (ATO)

Strong English communication skills with ability to communicate clearly and succinctly in written and oral presentations

Able to report onsite as indicated above

Desired Qualifications:

Active TS/SCI security clearance

Masters Degree in Computer Science, Engineering or Information Technology field

Knowledge of multiple database architectures, such as: Cisco, Oracle, Linux, Windows, and VMWare

1 year Supervisory/Lead experience in Information Technology

Experience in coordination of: Management Networks, Out Of Band Management, Joint Regional Security Stack (JRSS) implementation and/or Production Monitoring Environments

Experience in ITIL framework

Conducting internal security reviews/audits of responsible government systems

#ETMcareer

Scheduled Weekly Hours: 40

Travel Required: None

Telecommuting Options: Telecommuting Not Allowed

Work Location: USA VA Arlington

Additional Work Locations:

We are GDIT. The people supporting some of the most complex government, defense, and intelligence projects across the country. We deliver. Bringing the expertise needed to understand and advance critical missions. We transform. Shifting the ways clients invest in, integrate, and innovate technology solutions. We ensure today is safe and tomorrow is smarter. We are there. On the ground, beside our clients, in the lab, and everywhere in between. Offering the technology transformations, strategy, and mission services needed to get the job done.GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.

Appcast

Source

© 2019 Disabled Veterans National Foundation a tax-exempt 501(C)(3) nonprofit organization EIN #26-1446183 
By creating an account, you agree to DVNF's Terms of Service, Cookie Policy and Privacy Policy. You consent to receiving news letters and messages from the Disabled Veterans National Foundation and may opt out from receiving such messages by following the unsubscribe link in our messages, or as detailed in our terms. | Privacy Policy
cloud-syncearthbullhorncrosslistchevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram