Responsibilities:
- Collaborate with system engineers, program managers, and Authorizing Officials (or their delegates) to define and implement system security requirements.
- Lead efforts to ensure continuous monitoring and verification of cybersecurity requirements throughout the system lifecycle.
- Serve as a trusted cybersecurity advisor, providing guidance and recommendations to government stakeholders and contractor teams.
- Design, review, and refine system security architectures for cloud, on-premises, and hybrid environments.
- Support the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) approvals.
- Identify, track, and mitigate security control gaps and areas of non-compliance, ensuring alignment with security standards.
- Conduct risk assessments, vulnerability assessments, and develop and maintain critical documentation, such as System Security Plans (SSPs).
- Manage and facilitate Interim Authority to Test (IATT) activities, risk assessments, and all ATO-related processes.
- Analyze and interpret security control deficiencies to assess their impact on enterprise risk levels and cybersecurity program effectiveness.
- Partner with the Information System Security Manager (ISSM) and product teams to identify control gaps, propose mitigations, and prepare Program of Action and Milestone (POAM) plans for ATO submission.
- Guide system engineers on the mitigation of vulnerability findings using state-of-the-art security scanning tools, DoD policies, and industry best practices.
- Provide cybersecurity engineering expertise in evaluating alternatives, assessing trade-offs, and recommending risk treatment strategies.
- Collaborate with cross-functional teams to ensure the delivery of secure and dependable systems.
- Develop and maintain dashboards to monitor platform system controls, logs, and compliance status, ensuring seamless reporting.
- Demonstrate expertise in implementing cloud cybersecurity solutions and practices.
- Apply NIST SP 800-53 Revision 4 or 5 security controls and security assessment procedures from NIST SP 800-53A.
Core Knowledge, Skills, Abilities, and Tasks (KSATs) - DoD Cyber Workforce (DCWF):
- In-depth knowledge of computer networking concepts, protocols, and methodologies to ensure effective network security.
- Expertise in risk management processes, including methodologies for identifying, assessing, and mitigating risks.
- Comprehensive understanding of national and international laws, regulations, policies, and ethical standards impacting cybersecurity operations.
- Proficient knowledge of core cybersecurity principles and best practices for protecting information systems and data.
- Awareness of cyber threats, vulnerabilities, and emerging attack vectors that could compromise systems and information.
- Strong understanding of the specific operational impacts that cybersecurity lapses can impose on systems, data integrity, and organizational objectives.
- Expertise in cloud computing service models, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
- Solid understanding of cloud computing deployment models, including private, public, hybrid, and the key differences between on-premises and off-premises environments.
- Knowledge of cloud computing deployment models in private, public, and hybrid environment and the difference between on-premises and off-premises environments.