Edgewater Technical Associates - West Mifflin, PA

posted 17 days ago

Full-time - Mid Level
West Mifflin, PA
Professional, Scientific, and Technical Services

About the position

The Cybersecurity Analyst will be responsible for executing all aspects of the National Institute of Standards and Technology (NIST) directives to support the Risk Management Framework (RMF). This includes assisting information system owners with the development of System Security Plans (SSPs) and Security Assessment Reports (SARs) using the existing RSA Archer application on the Naval Nuclear Propulsion Network (NNPP Net) to support information system authorization. The role also involves assisting in the development of Plans of Action and Milestone (POA&Ms) and Risk Based Decisions (RBDs) for deficiencies found during the information system authorization process.

Responsibilities

  • Execute NIST directives to support the Risk Management Framework (RMF).
  • Assist information system owners with the development of System Security Plans (SSPs).
  • Develop Security Assessment Reports (SARs) using RSA Archer application.
  • Support information system authorization processes.
  • Assist in the development of Plans of Action and Milestone (POA&Ms).
  • Create Risk Based Decisions (RBDs) for deficiencies found during authorization.

Requirements

  • Active or recently active DOE Q or DOD Top Secret Clearance.
  • At least four years of experience in security control validation, assessment, or as an Information System Security Officer (ISSO).
  • At least two years of experience supporting development of information system security authorization packages in accordance with Risk Management Framework (NIST 800-37, 800-53, 800-53a).
  • At least two years of experience with Federal Risk and Authorization Management Program (FedRAMP).
  • CompTIA Security+ certification.

Nice-to-haves

  • Experience with the RSA Archer application.
  • Two years of experience working on IT security project teams.
  • One year of experience managing IT projects.
  • Knowledge of IT infrastructure and services (Data Centers, servers, networking components, cloud services).
  • Familiarity with NIST Special Publications and Security Technical Implementation Guides (STIGs).
  • Knowledge of infrastructure security and vulnerability management tools.
  • Previous work authorizing information systems within a classified DOE or DOD environment.
  • Certified Information Systems Security Professional (CISSP) certification.
  • Certificate of Cloud Security Knowledge (CCSK) certification.

Benefits

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Disability insurance
  • Health insurance
  • Paid time off
  • Vision insurance
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service