At a glanceSummarised by Seekless from the posting.
Must have7
Minimum of two (2) years of cybersecurity experience supporting RMF and Assessment & Authorization (A&A) activities
Experience developing and maintaining RMF packages, including Security Plans, Risk Assessments, POA&Ms, and supporting documentation
Experience with eMASS, ACAS, STIG Viewer, and cybersecurity compliance activities
Working knowledge of NIST standards, RMF, DISA STIGs, and continuous monitoring requirements
Ability to manage multiple priorities and communicate effectively with technical and non-technical stakeholders
CompTIA Security+ or other DoD 8570/8140 IAM or IAT Level II certification
Active Secret clearance
Nice to have6
Experience supporting Navy, NAVSEA, or other DoD cybersecurity programs
Experience conducting security control assessments and supporting ATO efforts
Familiarity with cybersecurity process improvement initiatives and RMF policy development
Experience providing cybersecurity training, mentoring, or technical guidance
CAP, CASP+, CISSP, or other advanced cybersecurity certification
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field
Eligibility1
US Citizenship
Skills
eMASS
ACAS
STIG Viewer
STIG OSS Manager
NIST SP 800-37
NIST SP 800-53
NIST SP 800-53A
CNSSI 1253
DISA STIGs
Benefits
Health insurance
Dental insurance
Vision insurance
Retirement plan
401(k)
Life insurance
Paid time off
Vacation
Sick leave
Public holidays
Short term disability
Long term disability
Training and development
Wellness resources
Stock option plan
About the role
Saalex is seeking a Information Systems Security Engineer (RMF) in Newport, RI to support the Naval Undersea Warfare Center Division Newport (NUWCDIVNPT). The selected candidate will support Assessment and Authorization (A&A) activities and assist in maintaining Authorizations to Operate (ATOs) for enterprise and Research, Development, Test & Evaluation (RDT&E) systems and networks.
Position Type: Full-Time
Salary: $60k-$70k annually (depending on experience)
Work Location: Full-time onsite
Essential Functions:
•
Support Assessment and Authorization (A&A) activities to maintain Authorizations to Operate (ATOs) in accordance with DoD and Department of the Navy RMF requirements.
•
Support cybersecurity compliance, security assessments, continuous monitoring activities, and information assurance efforts across Navy enterprise and RDT&E systems and networks.
•
Develop, review, and maintain RMF package documentation, including Security Plans, Risk Assessments, POA&Ms, architecture diagrams, asset inventories, and system/site policies and procedures.
•
Perform security control assessments in accordance with NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, CNSSI 1253, and applicable Navy cybersecurity guidance.
•
Execute Security Assessment Plans, review Security Test Reports, identify security deficiencies, and support risk mitigation activities.
•
Utilize cybersecurity tools including eMASS, ACAS, STIG Viewer, and STIG OSS Manager to assess, document, and monitor compliance.
•
Develop and maintain cybersecurity documentation including Contingency Plans, Contingency Plan Tests, Business Impact Analyses, and other required security artifacts.
•
Provide guidance on Navy RMF policies, DoD cybersecurity directives, NAVSEA business rules, and cybersecurity compliance requirements while supporting process improvement initiatives.
•
Provide RMF and eMASS guidance to team members and stakeholders and support cybersecurity training efforts as needed.
•
Attend stakeholder meetings, track action items, coordinate follow-up activities, and collaborate with government and contractor personnel to support successful A&A outcomes.
•
Other duties as assigned or required.
Requirements
Required:
•
Minimum of two (2) years of cybersecurity experience supporting RMF and Assessment & Authorization (A&A) activities.
•
Experience developing and maintaining RMF packages, including Security Plans, Risk Assessments, POA&Ms, and supporting documentation.
•
Experience with eMASS, ACAS, STIG Viewer, and cybersecurity compliance activities.
•
Working knowledge of NIST standards, RMF, DISA STIGs, and continuous monitoring requirements.
•
Ability to manage multiple priorities and communicate effectively with technical and non-technical stakeholders.
•
CompTIA Security+ or other DoD 8570/8140 IAM or IAT Level II certification required.
Desired:
Nice to have
•
Experience supporting Navy, NAVSEA, or other DoD cybersecurity programs.
•
Experience conducting security control assessments and supporting ATO efforts.
•
Familiarity with cybersecurity process improvement initiatives and RMF policy development.
•
Experience providing cybersecurity training, mentoring, or technical guidance.
•
CAP, CASP+, CISSP, or other advanced cybersecurity certification.
Education:
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field preferred. Equivalent combination of education, certifications, military experience, and professional cybersecurity experience may be considered.
Security Clearance:
Active Secret clearance required. Requirements to obtain a clearance include US Citizenship, security investigation, etc.