Job Description :
Information Systems Security Engineering personnel shall support required Assessment and Authorization (A&A) and Continuous Monitoring (ConMon) actions and tasks associated with ensuring compliance with all Risk Management Framework (RMF)
requirements in technology diverse, multi-level classification environments. This includes :
- Coordinating, developing and maintaining required Body of Evidence (BoE)
- Tracking and executing RMF actions to obtain / maintain valid authorizations to include
- IATT / ATO w / PoAM submissions
- Stakeholder collaboration
- Workflow / tracking tool updates
- Executing all ConMon activities within documented timelines
- BoE collection / coordination
- ConMon tracking tool updates
- Track Lien remediation / resolution activities
- Coordinating and collaborating across Technical and Security Services functional areas and agency stakeholders as directed / required
- Evaluating system change requests and assessing changes to determine system and organizational risk.
- Providing recommendations for implementation of security controls and, when necessary, counter-measures or mitigating controls.
- Conducting regular / recurring reviews of system state and security posture to ensure that systems are being operated securely, and information systems security policies and procedures are being implemented as defined in security plans.
- Responding to all queries and requests for applicable security information and reports.
- Supporting investigations of computer security violations and incidents, reporting as necessary to management.
- Researching, evaluating, testing, recommending, communicating and implementing security software or devices.
- Implementing, enforcing, communicating and supporting development of security policies or plans for data, software applications, hardware, and telecommunications.
- Developing materials for computer security education / awareness programs.
- Providing recommendations to stakeholders on information assurance engineering standards, implementation dependencies, and changing information assurance related technologies.
- Engagement with and use of Enterprise Security Services tool (e.g. HBSS, ACAS, Splunk) and coordination with both Security Services and Cyber Engineering stakeholders for prioritization and remediation actions of vulnerability and compliance deficiencies.
QUALIFICATIONS :
- Bachelors Degree in Information Systems or Cyber Security (or equivalent experience)
- Minimum of 4 years of demonstrated related / applicable experience
- Minimum certification (active and valid 8570 IAM Level I Compliant certification (CAP CND Cloud+ GSLC Security+ CE HCISPP)
- IAM Level II compliance preferred (CAP CASP+ CE CISM CISSP (or Associate) GSLC CCISO HCISPP)
- Location : On Customer Site
- US Citizenship Required
GDIT is Your Place :
- 401K with company match
- Comprehensive health and wellness packages
- Internal mobility team dedicated to helping you own your career
- Professional growth opportunities including paid education and certifications
- Cutting-edge technology you can learn from
- Rest and recharge with paid vacation and holidays
The likely salary range for this position is $100,175 - $135,530. This is not, however, a guarantee of compensation or salary.
Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours :
Travel Required : None
None
T elecommuting Options :
Onsite
Work Location : USA VA Chantilly
USA VA Chantilly