Quantico, VA, 22134, USA
81 days ago
Cloud Security Control Analyst
We have a current opening for a Senior-level Cybersecurity Analyst to perform analysis of cybersecurity packages using the Risk Management Framework (RMF) process to achieve an Authority to Operate (ATO) while supporting the Marine Corps Systems Command (MCSC) in Quantico, VA. This position works closely with government officials and senior engineers. **Security Clearance** : DoD Secret with the ability to obtain Top Secret **Responsibilities include, but are not limited to:** + Ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc. + Perform Compliance reviews and analyses to verify compliance with federalrequirements (e.g., EO, OMB Memos, A-130, NIST SP 800-37, 800-53, FIPS199, and FIPS-200, etc.). + Perform analyses of security implementations for assigned systems pertaining to people, processes, and technologies, identify gaps and recommend solutions. + Conduct daily, weekly, monthly compliance monitoring of assigned systems for all RMF steps. + Assist in the preparation and review of documentation to include System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Authorization Recommendations (ARs), Cybersecurity Strategies (CSSs), and other A&A artifacts. + Research major obstacles related to the ever-changing FISMA requirements,which customers will need to overcome and provide recommendations. + Provide updates and input to the GRC SharePoint sites to include documentuploads, page updates, access requests, permissions, etc. on an ongoing basis. **Minimum Requirements:** + Bachelors Degree and at least 10 years of related experience to include the following (additional 4 years of experience can be substituted in lieu of degree): + Must be compliant with DoD 8140 at an intermediate or advanced level. Thus, will need a CASP+CE, Security+, CISSP, or CISM certification. + Experience and expert knowledge on NIST guidelines, FISMA, Cybersecurityprinciples and methodologies, Executive Orders (EO's), Office of Management and Budget (OMB) Memorandums, Federal, DoD and CISA Technical Reference Architectures, Maturity Models, Risk Management Framework (RMF), Cybersecurity Framework (CSF), technical knowledge of IT systems + Knowledge of and experience using relevant cybersecurity and analysis toolssuch as Archer, Nessus Security Center, Splunk, etc. + Must be able to conduct system analysis and quality reviews to detectperformance issues. + Experience applying an enterprise-wide set of disciplines for the planning, analysis, design and construction of information systems on an enterprise-wide basis or across a major sector of the enterprise. + Experience applying reverse engineering and re-engineering disciplines to develop migration strategic and planning documents. + Familiarity with agency mandated security tools such as: ACAS/Nessus, HBSS, MDE, etc. **Preferred Qualifications:** + USMC or Navy Validator certified + Experience with cloud-based environments and technologies. + An analytical mind with excellent problem-solving ability. + Good communication skills and have good interpersonal, organizational, and analytical skills. **Clearance Requirements:** + DoD Secret with the ability to obtain Top Secret **Physical Requirements:** + This job largely operates in a professional office environment. + Ability to sit for extended periods of time.
Confirm your E-mail: Send Email