Information System Security Officer (Cybersecurity A&A Analyst)/POAM Management

Posted:
8/26/2024, 7:02:26 AM

Location(s):
Virginia, United States

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
IT & Security

Leidos's Digital Modernization Group is seeking high-level IT Professionals to provide Cybersecurity A&A Analyst/POAM Manager duties within the National Military Command Center (NMCC) at the Pentagon.

Primary Responsibilities

  • Must be able to work in a constantly changing regulatory environment with short, mid, and long term timelines for remediating any non-compliance

  • Must be able to work well within a team environment and able to adapt quickly to change

  •  Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc.

  • Maintain cybersecurity procedures and processes as assigned

  • Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs

  • Communicate the security posture of systems through designated reporting mechanism

  • Assist in preparation and review documentation to include System Security Plans (SSPs), Risk Assessment Reports (RAR), and other Assessment & Authorization (A&A) artifacts

  • Assist in the research and address information security issues as required, and develop and maintain the Plan of Action and Milestones (POA&M) and support remediation activities

  • Develop and advise development of Assessment and Authorization (A&A) artifacts and security documentation to include, but not limited to System Security Plans (SSP), Plan of Action and Milestone (POAM), Contingency Plan, Incident Response Plan, Configuration Management Plan

  • Assist with pre-assessment preparation

  • Perform Risk Management Framework (RMF) activities to achieve Authority to Operate (ATO).

  • Perform continuous monitoring of security controls to ensure that they are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the cybersecurity requirements for assigned IT systems.

  • Advise system owners on all matters, technical and otherwise, involving the security of assigned IT systems.

  • Strong verbal and written skills required providing management status reports and document system changes.

  • Analyze problems and provide focused solutions to effectively communicate information to various audiences verbally and through written communications.

  • Conduct reviews of closed Plan of Actions and Milestones (POA&M) for completeness and compliance

  • Develops and maintains POA&Ms and supports remediation activities

  • Experience with continuous monitoring and Plans of Actions and Milestones (POA&Ms)

Basic Qualifications

  • Bachelor’s degree and 5 years experience or equivalent work experience and certifications

  • Active TS/SCI Security Clearance

  • Current DoD 8570 baseline certification for IAT II (one of the following: GSEC, Security+, SCNP and SSCP certifications)

  • 4-6 years of Cyber Security experience

  • 3 Years of IT experience (Networking/System Administration)

  • Working knowledge of security system controls, policies, technical security safeguards, and operational security measures

  • Familiarity with DoD STIG process.

  • Excellent verbal and written communication skills.

  • Executing the security assessment and authorization (or ATO) process with independent assessors

  • Executing Continuous Monitoring and maintaining the security posture of IT systems day to day

  • To include familiarity with eMASS and XACTA

Original Posting Date:

2024-08-26

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $81,250.00 - $146,875.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos

Website: https://www.leidos.com/

Headquarter Location: Reston, Virginia, United States

Employee Count: 10001+

Year Founded: 1969

IPO Status: Public

Industries: Computer ⋅ Government ⋅ Information Services ⋅ Information Technology ⋅ National Security ⋅ Software