OBXtek - McLean, VA

posted 4 months ago

Full-time - Mid Level
McLean, VA
Professional, Scientific, and Technical Services

About the position

OBXtek is seeking an Information Assurance Security Specialist (IASS) to support the Department of State Consular Affairs (CA/CST) Bureau. The IASS will serve as a subject matter expert (SME) in information system security, focusing on compliance with FISMA, NIST standards, the Privacy Act, HIPAA, E-Gov, and OMB Circulars A-11 and A-130, as well as the Clinger-Cohen Act as they pertain to data and application security. This role is critical in ensuring the security and integrity of automated information systems (AIS) within the Consular Affairs sector, both domestically and for overseas deployed systems, including those hosted in cloud environments (IAAS, SAAS, and PAAS). The IASS will be responsible for conducting Assessment and Authorization (A&A) activities, tracking and reporting the status of assigned A&As, and addressing any obstacles that may hinder the completion of these processes. This includes ensuring that A&A packages are submitted to Information Assurance (IA) and following up to secure approval for each phase of the A&A process before the expiration of the systems' Authorized to Operate (ATO) status. The specialist will analyze production system configuration change requests (CCR) to assess their security impact and will initiate necessary actions to maintain the security posture and authorization status of the systems. In addition to these responsibilities, the IASS will support regular meetings with Government Technical Monitors (GTMs) and developers, facilitating boundary meetings, RMF Step 1 Kick-off meetings, and System Categorization meetings. The role requires gathering information to support system authorization, organizing technical working groups, conducting interviews, and assessing system security categorization levels. The IASS will also draft and maintain project schedules for assigned systems throughout the RMF process and develop various security application documentation, including Security Categorization Forms (SCF) and System Security Plans (SSP). Furthermore, the specialist will assist in the development of Contingency Plans (CP) and Privacy Impact Assessments (PIA), ensuring timely completion of data calls and monitoring the status of Plans of Action and Milestones (POA&Ms). The ideal candidate will possess a strong background in cybersecurity, information assurance, and IT, with extensive knowledge of FISMA compliance and NIST guidelines. They should have hands-on experience in writing essential RMF documentation and conducting RMF activities, particularly in cloud environments. Proficiency in tools such as SharePoint, Microsoft Teams, and the Archangel GRC tool is also required, along with excellent communication skills and the ability to thrive in fast-paced environments.

Responsibilities

  • Serve as a subject matter expert (SME) on information system security standards and guidelines including FISMA and NIST.
  • Conduct Assessment and Authorization (A&A) activities for Consular Affairs automated information systems (AIS).
  • Track and report the status of assigned A&As and address any obstacles to completion.
  • Ensure A&A packages are submitted to Information Assurance (IA) and follow up for approval before ATO expiration.
  • Analyze production system configuration change requests (CCR) for security impact and maintain security posture.
  • Support meetings with Government Technical Monitors (GTMs) and developers, facilitating various security-related meetings.
  • Gather information to support system authorization and organize technical working groups.
  • Draft and maintain project schedules for assigned systems throughout the RMF process.
  • Develop and maintain security application documentation including Security Categorization Forms (SCF) and System Security Plans (SSP).
  • Assist in the development of Contingency Plans (CP) and Privacy Impact Assessments (PIA).
  • Complete data calls in a timely manner and monitor the status of POA&Ms.

Requirements

  • Active Secret Clearance.
  • Bachelor's degree in computer science, Information Technology, Information Assurance, Cybersecurity, or a related field.
  • 3-5+ years of experience in Risk Management Framework (RMF) process, cybersecurity, information assurance, or IT.
  • Extensive knowledge of FISMA Compliance and NIST guidelines, including RMF and NIST SP 800 series.
  • Hands-on experience writing System Security Plans (SSPs) and Security Categorization Forms (SCF).
  • Experience conducting RMF Steps 1, 2, 3, & 6.
  • Proficient writing and communication skills.
  • Experience working in an Agile environment.
  • Experience performing RMF activities on cloud systems or FedRamp approved IAAS, SAAS, or PAAS.

Nice-to-haves

  • Certifications such as CAP, CISSP, or other IT and security-related certifications.
  • Working experience with the Archangel GRC tool.

Benefits

  • 401(k) matching
  • Dental insurance
  • Flexible spending account
  • Health insurance
  • Paid time off
  • Tuition reimbursement
  • Vision insurance
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service