FedRAMP Cloud Cybersecurity Analyst(Primarily Remote)

3 weeks ago


Quantico, United States ASRC Federal Full time

ASRC Federal Broadleaf Division is hiring a FEDRAMP Cloud Cybersecurity Analyst in support of DCSA at Quantico.

 

OVERVIEW:

  • DCSA requires Cybersecurity Cloud support to maintain IT infrastructure, applications, and any new development projects in the cloud. As such, technical analysis, research, evaluation, and technical guidelines shall be performed to accomplish the needed support. The workload for the Cybersecurity Analyst will vary depending on the number of active developments including Federal Risk and Authorization Management Program (FedRAMP) and Risk Management Framework (RMF) governance tier level as well as other technical evaluations required by DCSA.

 

JOB DUTIES:  

  • Prior support of FedRAMP activities for cloud hosted systems such as eMASS Package (ex: Readiness Assessment Report (RAR), System Security Plan (SSP), Plan of actions & Milestones (POA&M), etc.
  • Review, Audit, and validate compliance of DCSA systems Secure Cloud Computing Architecture (SCCA) to ensure cloud systems connections to the Boundary CAP (BCAP) and Virtual Datacenter Security Stack (VDSS) are implemented in accordance with the cloud Security Requirements Guide (SRG) including support for the internal implementation of the Visual Data Management System (VDMS) solutions internally.
  • Perform periodic cyber security control assessments of IT cloud systems, identify potential risks and gaps, and make recommendations and implement cloud security improvements based on industry standards and best practices.
  • Perform Cyber Security Impact Assessments and Risk Assessments for new and existing cloud systems, determine security posture and viability for organizational use, and make recommendations for cloud security architectures and controls.
  • Provide support for the internal Information Security Continuous Monitoring Program for authorization to operate and ongoing authorization approvals for cloud-based IT systems.
  • Experience working with Third Party Assessment Organizations (3PAO)
  • Participation with the DISA Cloud Joint Verification Team (JVT) Team 
  • Assist the Product Managers (PMs) and/or Program Management Office (PMO) with cyber security audits and assessments of cloud systems including programmatic reviews and management of corrective action plans.
  • Participated in reviews of Information System Agreement (ISA) / Memorandum of Agreement (MOA), Whitelisting, etc.
  • Worked with the solution engineers to identify best practices and methods required by the FedRAMP PMO to configure and operate within the NIST SP 800 series of controls.
  • Assist with non-cloud systems authorization efforts utilizing the Risk Management Framework (RMF).
  • Demonstrated experience with research and analysis of Commercial-Off-The-Shelf (COTS) and Government-Off-The-Shelf (GOTS) and IA-enabled products as part of the security architecture and ensure products are National Security Telecommunications and Information Systems Security Policy Number 11 (NSTISSP-11) compliant and validated via the NIAP Common Criteria Evaluation and Validation Scheme or NIST Federal Information Processing Standards (FIPS) Cryptographic Module Validation Program (CMVP).

 

WORK ENVIROMENT:

  • Hybrid work schedule available dependent on work demands.

BASIC QUALIFICATIONS:

  • At least three (3) Years of Cloud Cybersecurity experience.
  • Be able to maintain TS/SCI clearance and access to require to DoD systems including NIPRNet, SIPRNet, and JWICS.
  • Knowledge of Federal/DoD IT and Cloud security policies, IT configuration tools, Network Security, and other applicable Cybersecurity Policies.
  • Understanding and familiarity with cloud architectures (e.g., SaaS, PaaS, IaaS), common commercial cloud systems (e.g., AWS, Microsoft 365, etc.) as well as specific DOD cloud architecture BCAP, ICAP, SCCA, cloud security solutions (e.g., Cloud Access Security Broker, Multi-factor Authentication, Zero Trust Architecture).
  • Understanding of DOD cyber security standards and methodologies including NIST 800-53 Cyber Security Controls, the FedRAMP, the DODI 8510.01 RMF, FISMA, and NIST 800-37 Risk Management.
  • Excellent communication (written and oral) and interpersonal skills.

 

EDUCATION:

  • At least an Associates Bachelor’s Degree, in Cybersecurity, and/or Information Systems Management
  • Bachelor’s Degree, in Cybersecurity, and/or Information Systems Managementpreferred

 

CERTIFICATION(s):

  • Required to have a cloud certification and DD8140/DoD8570.01-M IASAE level I or IAM level II or IAT level II at time of onboarding.
  • Cloud certifications preferred.

 

CLEARANCE LEVEL:

  • Active TS with the ability to obtain a SCI Clearance
ASRC Federal and its Subsidiaries are Equal Opportunity / Affirmative Action employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

  • Quantico, Virginia, United States ASRC Federal Holding Company Full time

    JOB DESCRIPTION:ASRC is hiring an Incident Responder to support onsite in Quantico, VA. This position has been approved for hybrid support (2 days onsite/3 days remote).The Incident Responders support includes continuous monitoring, data to include but not limited to network and host vulnerability scanning IDS, firewall, network sensor tuning, net...


  • Quantico, Virginia, United States SAIC Career Site Full time

    Description Introduction Make a difference for national security by joining a team of dedicated IT professionals who will sustain, modernize and transform the enterprise IT capabilities for the Defense Counterintelligence and Security Agency (DCSA). The National Security & Space Sector of SAIC is seeking a Cyber Security Analyst Senior to support a...

  • Cloud Response SME

    2 weeks ago


    Quantico, United States Resource Management Concepts, Inc. Full time

    Job DescriptionJob DescriptionResource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.RMC is hiring a Cloud...

  • Cloud Network Engineer

    12 hours ago


    Quantico, United States Visualsoft Full time

    Visual Soft, Inc is seeking qualified candidates (US Citizens with active ACTIVE TOP SECRET clearance - a requirement on its sub contract with work share on a Project with a Major Prime) for the following position for a federal agency. Job Title: Cloud Network Engineer - an Active Top SECRET required Compensation: Negotiable with standard benefits based on...


  • Quantico, United States ManTech International Corporation Full time

    You will need to login before you can apply for a job. Senior Cloud Information Systems Security Engineer (ISSE) with Secure our Nation, Ignite your Future Become an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech International Corporation, you'll help protect our national security...


  • Quantico, United States OnDek Solutions Full time

    Job Description We're seeking a Top Secret cleared (ability to obtain CI Polygraph) Senior Information System Security Officer to champion our IS Security Services, ensuring a shield of protection around our systems and data. This role isn't just about security-it's about pushing boundaries, harnessing innovation, and safeguarding our technological...


  • Quantico, United States ICS Nett, Inc. Full time

    A&A Validator Must be US CitizenActive Secret or Top Secret is requiredLocation: Quantico, VA ( 2 days Onsite 3 days offsite ) DoD 8570 IAM Level 1 Certification Overall Job Description: Validator will manage customer-required Risk Management Framework (RMF) efforts for DCSA customers. The Validator will be responsible to work collaboratively with...


  • Quantico, United States TEKsystems Full time

    Description: The Cyber Security Engineer will be responsible for tasks related to Assessment & Authorization (A&A) to ensure assigned DoD, DoN systems/Enclaves/Networks can obtain and maintain Authorization to Operate (ATO) and Authorization to Connect (ATC) certifications. In this role, the Cyber Security Engineer will participate in risk assessments...


  • Quantico, United States Resource Management Concepts, Inc. Full time

    Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America. The Detection Engineer Analyst SME will support the...


  • Quantico, United States Resource Management Concepts, Inc. Full time

    Job DescriptionJob DescriptionResource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.The Detection Engineer...

  • System Admin

    1 month ago


    Quantico, United States Information Protection Solutions LLC Full time

    Systems Administrator (Mid-level) About Information Protection SolutionsJoin our dynamic team at Information Protection Solutions, a leading cybersecurity firm. We are passionate about empowering businesses through secure and reliable IT solutions. Position OverviewWe are seeking a proactive and highly skilled Systems Administrator to monitor and maintain...

  • Technical Writer

    1 month ago


    Quantico, Virginia, United States ASRC Federal Full time

    Job DescriptionJOB DESCRIPTION: This position has been approved for hybrid support (1 day onsite/4 days remote). The ASRC Federal is seeking a highly skilled and detail-oriented Policy Analyst with expertise in cybersecurity to join our team. The successful candidate will play a crucial role in researching, publishing, and evaluating government policies...


  • Quantico, United States Geospatial And Cloud Analytics Inc Full time

    Job DescriptionJob DescriptionGeospatial and Cloud Analytics (GCA) is seeking a Cyber Security SecOps Administrator to join our team! Your role as a Cyber Security SecOps Administrator will be managing and maintaining the security infrastructure of an organization, focusing on the day-to-day tasks related to cybersecurity operations.Duties to...


  • Quantico, United States Geospatial And Cloud Analytics Inc Full time

    Job DescriptionJob DescriptionGeospatial and Cloud Analytics (GCA) is seeking a Cyber Security SecOps Administrator to join our team! Your role as a Cyber Security SecOps Administrator will be managing and maintaining the security infrastructure of an organization, focusing on the day-to-day tasks related to cybersecurity operations.Duties to...


  • Quantico, United States OSC Edge Full time

    Cyber Security Engineer (A&A) with DoN/DoD experience Location: Quantico, VA (Onsite five days a week) The Cyber Security Engineer will be responsible for tasks related to Assessment & Authorization (A&A) to ensure assigned DoD, DoN systems/Enclaves/Networks can obtain and maintain Authorization to Operate (ATO) and Authorization to Connect (ATC)...


  • Quantico, United States Arlo Solutions Full time

    Position Overview The Financial Analyst II shall demonstrate experience and knowledge of DoD accounting principles. This person should have knowledge of storing, presenting, processing and analyzing data in excel. Require ability to perform analysis of financial data and provide government analysts with recommendations. Work Location Quantico, VA (onsite 2-3...


  • Quantico, United States Resource Management Concepts, Inc. Full time

    Job DescriptionJob DescriptionResource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.RMC is hiring a Dection...


  • Quantico, United States OSC Edge Full time

    Cyber Security Engineer (A&A) with DoN/DoD experienceLocation: Quantico, VA (Onsite five days a week)The Cyber Security Engineer will be responsible for tasks related to Assessment & Authorization (A&A) to ensure assigned DoD, DoN systems/Enclaves/Networks can obtain and maintain Authorization to Operate (ATO) and Authorization to Connect (ATC)...


  • Quantico, United States OSC Edge Full time

    Cyber Security Engineer (A&A) with DoN/DoD experienceLocation: Quantico, VA (Onsite five days a week)The Cyber Security Engineer will be responsible for tasks related to Assessment & Authorization (A&A) to ensure assigned DoD, DoN systems/Enclaves/Networks can obtain and maintain Authorization to Operate (ATO) and Authorization to Connect (ATC)...


  • Quantico, United States Geospatial And Cloud Analytics Inc Full time

    Job DescriptionJob DescriptionGeospatial and Cloud Analytics (GCA) is seeking a SR level Network Engineer to join our team! Your role as a Senior Network Engineer will be to monitor and control the performance and status of network resources across multiple enclaves utilizing software and hardware tools; configure and install networking hardware / software...