Cybersecurity RMF Analyst
2 days ago
Overview:
Falconwood is a woman-owned / veteran-owned company providing consultation and programmatic support to Department of Defense (DoD) Information Technology (IT) initiatives and programs. We provide expert advice and consultation on a diverse range of IT subjects, focusing on acquisition, cybersecurity, engineering, logistics, and process development.
We have an immediate opening for a Cybersecurity Risk Management Framework (RMF) Analyst to support the Navy Enterprise Resource Planning (ERP). The successful candidate will perform the complete DoD RMF Assessment and Authorization (A&A) process, to include system categorization, security control baseline selection and tailoring, security control implementation and assessment. They will also get to perform continuous RMF monitoring including annual control assessments, POA&M monitoring and updates, creation and/or updating of security documentation, and development of mitigations for non-fully compliant controls. This position is based at the Washington Navy Yard and requires an active secret clearance.
Responsibilities:
The candidate must have the knowledge skills and abilities required to complete Navy RMF processes as identified in the RMF Process Guide, Supply Chain Assessment - Red, Amber, Green (SCA RAG), and CyberSafe:
- Perform the complete DoD RMF Assessment and Authorization (A&A) process, to include system categorization, security control baseline selection and tailoring, security control implementation and assessment.
- Assess the effectiveness of cybersecurity controls In Accordance With (IAW) National Institute of Standards and Technology (NIST) SP 800-53A and effectively document weakness.
- Successfully complete NIST SP 800-30, compliant risk assessments.
- Must have experience using the automated RMF Assessment and Authorizations (A&A) tools, such as Enterprise Mission Assurance Support Service (eMASS), to complete and document DoD compliant RMF A&A activities.
- Support the System Level Continuous Monitoring (SLCM) activities involve ongoing assessment of an organization's systems to ensure compliance and identify risks. These activities typically include continuous auditing, controls monitoring, and transaction inspection to detect inconsistencies, errors, POA&M monitoring and updates, creation and/or updating of security documentation, and development of mitigations for non-fully compliant controls. and policy violations.
- Maintain the Navy ERP continuous monitoring IAW DoD Inst and DoN CIO Guide (Risk Management Framework Process Guide).
- Assist in the development of cybersecurity related documentation and other artifacts required to successfully navigate an information system through the DoD/Navy acquisition process.
- Execute processes and develop artifacts required to obtain DoD and Navy IATTs, ATOs and Use Case approvals.
- Perform Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) vulnerability management (identifying, tracking, remediation, mitigation, and exception management).
- Successfully complete NIST SP 800-30, compliant risk assessments.
- Coordinate Asset Management (Hardware and Software) activities.
- Review Interconnection Agreements (Memorandum of Understanding and Service Level Agreements).
- Coordinate Cyber to identify why issues are not being resolved.
Qualifications:
- Required a bachelor's degree in technology.
- Required having 3-5 years of experience performing Cybersecurity RMF A&A and RMF continuous monitoring.
- Must have enterprise Systems, Applications, and Products in Data Processing (SAP) ERP system cybersecurity experience.
- Must have the ability and willingness to perform independently and/or as part of a team to move the mission forward.
- Must have the ability to communicate effectively in writing and verbally.
- The candidate must be a self-starter by taking responsibility and initiative for the successful and timely completion of all tasks and areas assigned.
- The candidate must have in-depth knowledge of and will have successfully implemented NIST, DoD, and Navy Cybersecurity policies, guidance and standards, e.g. DoDI , FIPS-199, FIPS-200, NIST SP 800-37, NIST SP 800-53, Rev x, NIST SP 800-53A, NIST SP 800-34, NIST SP 800-18, NIST SP 800-30, NIST SP 800-64, CNSSI-1253, The Enterprise IT Control Standards (EITCS), etc.
- The candidate must be certified to meet IAT Level 1 CSWF requirements, i.e.: "CURRENT" Isc2's CISSP, Security + certifications, or equivalent.
- SECRET security clearance with favorably adjudicated T5 (SSBI) background investigation.
Pay Range:
120 to 130k
-
RMF Cybersecurity Analyst
4 days ago
Washington, Washington, D.C., United States Koniag Government Services, LLC Full timeKoniag IT Systems, a Koniag Government Services company, is hiring an experienced Senior Cybersecurity Analyst with a TS/SCI clearance to support KITS and our government customer in Alexandria, VA. This is a hybrid position.We offer competitive compensation and an extraordinary benefits package including health, dental, and vision insurance, 401K with...
-
Cybersecurity Analyst
2 days ago
Washington, Washington, D.C., United States Astrion Full time $90,000 - $120,000 per yearOverviewMid-Level Cybersecurity AnalystLOCATION: Washington DCJOB STATUS: Full-timeCLEARANCE: SecretCERTIFICATION: DoD 8140 IAT Level IITRAVEL: As NeededAstrion has an exciting opportunity for a Mid-Level Cybersecurity Analyst located at the Washington Navy Yard in Washington, DC. Work for this position is onsite at Washington Navy Yard a minimum of 4 days...
-
Senior Cybersecurity Analyst
4 days ago
Washington, Washington, D.C., United States Sayres Defense Full time $80,000 - $160,000 per yearSayres, a renowned leader in defense support services to the DOD in the shipbuilding industry, is currently seeking a skilled Cybersecurity Analyst with Secret Clearance in Washington, DC. Industry Certifications: Possess relevant certifications such as Network+, CISSP, CAP, or CEH.As a key member of our team, the Cybersecurity Analyst will play a vital role...
-
Sr. Cybersecurity Analyst I
2 weeks ago
Washington, Washington, D.C., United States MetroStar Full time $138,000 - $205,000 per yearAs Sr. Cybersecurity Analyst I, you'll lead the assessment and authorization (A&A) process to achieve and maintain Authority to Operate (ATO) for critical government systems and cloud environments up to IL6+, ensuring compliance with NIST SP 800-53, RMF, ICD 503, FISMA, and FedRAMP standards. With a focus on safeguarding mission-essential infrastructure...
-
Journeyman Cybersecurity Specialist
4 days ago
Washington, Washington, D.C., United States The McHenry Management Group Full time $80,000 - $110,000 per yearSalary: $95,000 - $115,000Travel: 10%Background check, US Citizenship, secret security clearance, and CAC are requirements for this position. Contingent on client approval.TMMG is actively seeking a highly motivated Journeyman Cyber Security Analyst to support the U.S. Coast Guard (USCG) Surface Acquisition Program Management Offices (CG-SEA) in Washington...
-
Journeyman Cybersecurity Specialist
4 days ago
Washington, Washington, D.C., United States TMMG, Inc. Full time $80,000 - $110,000 per yearDescription:Salary: $95,000 - $115,000Travel: 10%Background check, US Citizenship, secret security clearance, and CAC are requirements for this position. Contingent on client approval.TMMG is actively seeking a highly motivated Journeyman Cyber Security Analyst to support the U.S. Coast Guard (USCG) Surface Acquisition Program Management Offices (CG-SEA) in...
-
Cybersecurity Technical Writer IV
4 days ago
Washington, Washington, D.C., United States Imagineeer Full time $120,000 - $180,000 per yearBenefits: 401(k) matchingCompetitive salaryHealth insurancePaid time offAbout this Role: We are seeking a highly skilled Cybersecurity Technical Writer – Level 4 to support enterprise cybersecurity initiatives for the U.S. Department of Health and Human Services (HHS). This role provides expert-level documentation, communication strategy development, and...
-
CyberSecurity Analyst
4 days ago
Washington, Washington, D.C., United States Sprezzatura Management Consulting Full time $80,000 - $120,000 per yearJob Title: Cybersecurity ExpertLocation: VirtualOther Consideration: U.S. Citizen, Green Card HolderSUMMARY: The Cybersecurity Analyst is responsible for protecting an organization's digital assets by monitoring systems, identifying vulnerabilities, and responding to security incidents. This role plays a critical part in safeguarding sensitive data,...
-
Lead Cyber Threat Analyst
2 days ago
Washington, Washington, D.C., United States DirectViz Solutions, LLC Full time $120,000 - $180,000 per yearDirectViz Solutions, (DVS) is a rapidly growing government contractor that provides strategic services that meet mission IT needs for government customers. DVS provides innovative information technology solutions to government clients through the knowledge and expertise of our dedicated employees. DVS is an employee-centric employer that provides competitive...
-
Cybersecurity Data Analyst
4 days ago
Washington, Washington, D.C., United States Planet Technologies Full time $90,000 - $140,000 per yearPlanet Technologies, the Nation's leading Microsoft services provider to the public sector, is looking for a highly motivated individual to join our growing team as Data Cybersecurity Analyst. In this role, you will be supporting impactful projects that make a difference for our country.ResponsibilitiesPerforms analysis on data for documents, reports, and...