J.G. Management Systems, Inc. (Jgms) - West Mifflin, PA

posted 17 days ago

Full-time - Mid Level
West Mifflin, PA
Professional, Scientific, and Technical Services

About the position

The Cybersecurity Analyst will be responsible for executing all aspects of the National Institute of Standards and Technology (NIST) directives to support the Risk Management Framework (RMF). This includes assisting information system owners with the development of System Security Plans (SSPs) and Security Assessment Reports (SARs) using the RSA Archer application, as well as developing Plans of Action and Milestone (POA&Ms) and Risk Based Decisions (RBDs) for deficiencies found during the information system authorization process.

Responsibilities

  • Execute all aspects of NIST directives to support the Risk Management Framework (RMF).
  • Assist information system owners with the development of System Security Plans (SSPs) and Security Assessment Reports (SARs).
  • Utilize the RSA Archer application on the internal network to support information system authorization.
  • Develop Plans of Action and Milestone (POA&Ms) and Risk Based Decisions (RBDs) for deficiencies found during the information system authorization process.

Requirements

  • Active DOE Q Clearance.
  • At least four years of combined experience in security control validation, assessment, or as an Information System Security Officer (ISSO) or Information System Security Manager (ISSM).
  • At least two years of experience supporting the development of information system security authorization packages in accordance with Risk Management Framework (NIST 800-37, 800-53, 800-53a).
  • At least two years of experience working with Federal Risk and Authorization Management Program (FedRAMP).
  • CompTIA Security+ certification.

Nice-to-haves

  • Experience with the RSA Archer application.
  • At least two years of experience working on IT security project teams.
  • At least one year of experience managing IT projects.
  • Knowledge of IT infrastructure and services including Data Centers, servers, networking components, and cloud services.
  • Knowledge of security policies such as NIST Special Publications and Security Technical Implementation Guides (STIGs).
  • Familiarity with NIST 800-171, CISSP certification, and CCSK certification.

Benefits

  • 401(k) matching
  • Dental insurance
  • Disability insurance
  • Employee assistance program
  • Health insurance
  • Life insurance
  • Paid holidays
  • 100% company paid premiums for medical insurance
  • Up to 4 weeks paid time off a year
  • 10 paid floating holidays
  • Short- and long-term disability
  • Professional development opportunities
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service