Acquire and manage all necessary documentation/artifacts, including cybersecurity support and resources, to support IT cybersecurity goals and objectives from a risk management perspective.
Advise senior management on system risk levels and cybersecurity posture for cloud-based environments.
Assist in the deployment, architecture and configuration of security controls of deployed systems with Cloud Architects.
Ensure that developed systems and architectures are consistent with all applicable DoD and Army cybersecurity policies and guidelines.
Perform Assessment and Authorization (A&A) cybersecurity reviews, identify gaps, and support risk management plans for cybersecurity personnel to execute.
Provide input on cybersecurity requirements and collect and maintain data needed to meet system cybersecurity compliance reporting.
Provide subject matter expertise for Risk Management Framework (RMF) activities and related documentation to support system accreditation / Authority to Operate (ATO) requirements.
Interpret noncompliance to determine the impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
Track audit findings and recommendations to ensure that appropriate mitigation actions are taken.
Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
Coordinate with geographically-distributed, multi-discipline teams to ensure compliance with all applicable requirements for cybersecurity are addressed.
Requirements
Bachelor's degree in a related field
5+ years demonstrated experience designing, implementing, and monitoring cybersecurity solutions
5+ years demonstrated RMF and eMASS experience
Familiarity with cybersecurity tools such as ACAS and Tenable
Certified Information Systems Security Professional (CISSP) (or Associate), Certified Information Security Manager (CISM), or equivalent DoD 8140 IAM Level III certification
Expertise in identifying and classifying technical security requirements and specifications
Experience developing and evaluating enterprise and system security designs and related architectures
Experience developing or ensuring development adheres to cybersecurity requirements and best practices (e.g., NIST controls, DISA STIGs)
Familiarity with commercial off-the-shelf solutions for specific security capabilities