KEY DUTIES AND RESPONSIBILITIES
Essential duties and responsibilities include the following. Other duties may be assigned.
Execute and manage all Risk Management Framework (RMF) processes for Assessment & Authorization (A&A) to maintain the platform’s authorization state.
Develop, maintain, and update the System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and Authorization-to-Operate (ATO) artifacts directly within the official eMASS repository.
Conduct Independent Verification and Validation (IV&V) on all vulnerability scanning. Use ACAS and the IAVM/DTO process to monitor, track, and verify technical patching and remediation efforts.
Implement and validate the security controls mandated by NIST SP 800-53 Rev 5 and CNSSI 1253 Rev 5. Support and verify the technical hardening, patching, and STIG compliance for all operating systems (Linux/Windows) and network devices within our boundary.
Conduct critical Security Impact Assessments (SIAs) and Risk Assessments (RAs) on all proposed platform or system changes (such as new tenant onboardings or API integrations) to evaluate security risks prior to implementation.
Monitor system logs, assist with incident response activities, and ensure our continuous monitoring and compliance dashboards are accurately maintained.
Partner closely with our Lead Architect/Engineer, system administrators DevSecOps teams to ensure security is integrated into our pipelines and that they understand our security requirements.