Maintain Assessment & Authorization (A&A) documentation in accordance with JSIG, NIST SP 800-37, and NIST SP 800-53, including SSPs, Contingency Plans, and Incident Response procedures
Track compliance deficiencies using Plans of Action and Milestones (POA&M) through mitigation or risk acceptance, delivering quarterly status updates to the ISSM and SCA
Implement and execute the Continuous Monitoring strategy to ensure ongoing compliance with authorization packages
Oversee audit log collection systems and perform weekly reviews to maintain system integrity
Manage hardware and software inventories, ensuring all deployed assets remain actively vendor-supported
Maintain security tools, patch management processes, and vulnerability management programs in coordination with the Cybersecurity team
Assess proposed system configuration changes as part of the Change Control Board (CCB) to evaluate security impacts
Facilitate annual security awareness and role-based training, personnel account verification, and general ISSM support
Masters degree preferably in IT, Cyber Security, Computer Science, Information Systems Management, Engineering, or similar field of study
Experience with security efforts related to modern Windows, Cloud computing, Linux, UNIX, Cisco, SQL or Oracle databases, and virtual computing
Experience implementing and using various Cyber Security tools including vulnerability assessment, patch management, audit collection, audit review, audit management, and end point protection