Job Title : Cybersecurity Risk and Authorization SME
Location : Remote
Summary :
Mission is to plan, assess, execute and oversee cloud hosting solutions for all DLA systems and services in DLA managed cloud environments, encompassing Microsoft Azure, Amazon Web Services (AWS), Oracle Cloud Infrastructure (OCI), Google Cloud Platform (GCP). These cloud environments are in geographically dispersed locations and are architected to meet US Department of Defense (DoD) security requirements for Cloud Computing Security Requirements (SRG) Impact Level 4 (IL4) and Impact Level 5 (IL5) restrictions
Responsibilities :
- Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures
- Performs a DOD cybersecurity process serving as a SME for an information system undergoing authorization
- Possess an understanding of how the security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization's IT infrastructure such as DLA's, in which there is a compilation of large and small enclaves, AIS applications and IT processes
- Determines the applicable severity value for an identified vulnerability (e.g., non-compliant security control) and determines the possible ramifications on the system's current or future authorization.
- Provides audit readiness and sustainment support by participating in all phases of audit and creates compliance documentation
- Ensure Cybersecurity compliance and corresponding RMF, ATO, audit documentation is maintained in a repository to include any dates and / or modifications to all relevant documented artifacts
Requirements :
Five (5) years of relevant Risk Management Framework (RMF) and NIST A&A experience, Zero Trust, SCCA FRD and SRGCertification as a Certified Cloud Security ProfessionalDOD cybersecurity experienceExperienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes.Knowledgeable in the cybersecurity of emerging technology areas such as Cloud and Industrial Control Systems (ICSs), warehouse execution systems and Operational Technology (OT) infrastructuresMust possess IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) at time of proposal submissionDoD Approved 8570 / 8140 Baseline Certification at time of submission : Category IAT Level IIExperience in assessing Information Assurance Controls and conducting Certification & Accreditation reviews for large, complex organizationsMust have strong business and technical writing skillsStrong analytical and problem-solving skills for resolving security issuesExperience with DoD Audit ReadinessComputing Environment : Requires at least one industry Cloud certification(s) :AWS Cloud PractitionerAWS Developer AssociateAWS Solutions ArchitectAWS SysOps AdministratorAWS DevOps EngineerAWS Solution Architect,AWS Advanced NetworkingAWS Data AnalyticsOracle Cloud Infrastructure FoundationsOracle Cloud Data Management FoundationsOracle Cloud Infrastructure Architect FoundationsOracle Cloud Infrastructure ProfessionalOracle Cloud Infrastructure Security ProfessionalOracle Clous Database Service ProfessionalOracle Cloud Database Migration and Integration ProfessionalOCO Observation and Management ProfessionalOracle Cloud Platform Enterprise Analytics ProfessionalAzure FundamentalsAzure Development AssociateAzure AI Engineer AssociateAzure Administrator AssociateAzure Solutions Architect ExpertGoogle Cloud Platform Cloud EngineerGoogle Cloud Platform Cloud Architect