GRAVICOM has three (3) Cybersecurity positions to fill, and we'd love for you to be on the team! The position is for an Information Security Systems Engineer (ISSE) with RMF experience. We're looking for 1 senior person, and 2 supporting personnel. Must have RMF (eMASS / POA&M, etc.) and vulnerability management experience.
Salary: Starting at $70,000-$120,000 annually (Negotiable, based on experience, certifications, and knowledge).
GRAVICOM LLC is looking for a Cyber Security Specialist, with knowledge in:
- Risk Management Framework (RMF) Assessment and Authorization (A&A)
- Application and mitigation of STIGS,
- Knows how to run ACAS and SCAP scans
- Can do RMF Security Control Testing (SCT) if needed
- Knows how to update POA&Ms, SSPs, mitigate findings, and update eMASS
The majority of the work will be maintaining and reporting the cybersecurity posture of systems by updating eMASS, updating documentation, doing STIGs, running ACAS scans, running SCAP scans, writing mitigations, documenting findings in POA&Ms, and updating RMF packages for systems.
- Must have Risk Management Framework (RMF) Assessment and Authorization (A&A) experience.
- Must have at least one of these certifications: Security+, CISSP, or CASP
- Must have a SECRET or above security clearance (we will sponsor you for a clearance at no cost if you don't have one).
- Experience as an ISSE, ISSO, ISSM, Systems Administrator, Network Administrator, or a Network Security Officer is preferred.
GRAVICOM LLC seeks an IT Security Professional in support of for the Navy GBAD Program Office, out of Bloomington Indiana. You will be working with a team of people supporting the RMF A&A posture of all of their systems and environments.
RESPONSIBILITIES: Primary responsibilities and typical duties include:
- Creating/updating mitigations, documenting findings in POA&Ms, updating eMASS, and updating RMF artifacts for the Assessment and Authorization (A&A) cycle.
- Systems Administration / Continuous Monitoring. The candidate may be required to apply STIG security lockdowns to the environment and document compliance, non-compliance, or non-applicability.
- Completing STIGs, running ACAS scans, running SCAP scans.
- Analyze completed Checklists, ACAS Scans, SCAP Scans, System Security Plans (SSPs), and Plans of Action and Milestones (POA&Ms)
- Candidate will be knowledgeable of RMF processes and activities needed to support Navy Validators and the A&A process.
- Provide Information Security Systems Engineering (ISSE) services
- Assure IAVA program and reporting compliance, USMC OPDIRs as needed
- Provide support for FISMA audits and document requests.
- Assure software is current and associated in DITPR-DON / DADMS
Update documentation as needed
---Assure inheritance and security controls are documented and implemented properly.
---Technical Diagrams, PPSMs, Checklists
---Update the Contingency Plan (CP) and Incident Response Plan (IRP)
---Update System Lifecycle Continuous Monitoring (SLCM) Plans
---Maintain and document packages and artifacts in eMASS / MCCAST
---Memorandums for the Record (MFRs), FISMA compliance documents
---Use Case documents for system changes
---Privacy Impact Assessments (PIA), RMF Overlay security controls and checklists,
---Preparation of IA waivers, DON-CIO escalations, IA data calls, and other IA related programmatic items as needed.
---Negotiate issues with, and enter tickets within Remedy.
---Work with technical teams as needed to support ISSE functions, RMF functions, CTOs, FRAGORDs, WARNORDs, OPORDs, etc.
Serve as a technical liaison between Program Managers & Engineering to update:
- Creation of diagrams, software lists, hardware lists, POA&Ms, RARs, SPs, SSPs, PPSMs, and A&A packages.
- Assessment of DoD, Navy, and USMC policy for STIG implementation,
- Execute submissions into DITPR-DON / DADMS on behalf of the program.
- POA&M maintenance & milestone tracking.
- Periodic reporting to ISSM, ISSO, and Cyber managers.
- Interfacing with the configuration management system to institute Engineering Change Requests (ECRs),
- Report or validate applicable patches including information assurance IA vulnerability alerts (IAVA), information assurance IA vulnerability bulletins (IAVB), and technical advisories (TAs);
- Comply with Computer Tasking Orders (CTOs), complete reporting as necessary;
- Validate specific IA security countermeasures to assure security posture is maintained;
- Understand the policy requirements for PII, PHI, CUI, NNPI, Classified, and other protected data types. Know the security & reporting requirements.
- Coordinate with the Configuration Management (CM) team, and implement IA related Engineering Change Requests (ECRs).
- Attend programmatic phone conferences and daily SCRUM meetings
- Complete other duties as required by the customer.
The requirements above are specialized, and the candidate may or may not have experience in all areas. The successful candidate is an individual who knows about information security, understands how it works, understands risk and mitigating risk, knows how to operate in a USMC RMF A&A environment, and understands how to create and evaluate documentation to address risk. Documentation can be high level strategy all the way down to very articulate technical detailed documentation.
Location: Bloomington, Indiana. On-site work is required. Telework may be authorized from time to time (for weather, special projects, etc.), however, most work will be in person on site.
Qualifications: Required Knowledge, Skills, and Abilities:
- Must have experience in RMF A&A and STIGs, and have a technical background;
- Must be able to meet deadlines on projects;
- Must have good English communication and analytical skills;
- Must be a US citizen and have a DOD SECRET security clearance;
- Must be able to work independently, be results-oriented, and be well-organized;
Minimum Required Education/Training and experience:
- Must have a DOD 8570 / 8140.01 compliant security certification such as: Security+ CE certification (or higher cert, such as CASP, CISSP, CISM, GSEC, and/or GSLC are preferred).
- Must be proficient in Microsoft Excel and Microsoft Visio
- Maintain a DoD 8570 / 8140 compliant IA Level II Cyber Security Work Force (CSWF) status;
- 3+ years of experience.
- Exceptional character and professional references.
Language Skills:
- Ability to read, analyze, and interpret general business periodicals, professional journals, technical procedures, and governmental regulations in standard American English;
- Ability to write reports, business correspondence, and procedure manuals; and
- Ability to effectively present information and respond to questions from groups of managers, clients, customers, and the general public.
- Ability to work in online compliance portals, differentiate information, and analyze for changes.
Mathematical Skills:
- Ability to add, subtract, multiply, and divide in all units of measure, using whole numbers, common fractions, and decimals; and
- Ability to compute rate, ratio, and percent and to draw and interpret bar graphs.
Reasoning Ability:
- Ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists; and
- Ability to interpret a variety of instructions furnished in written, oral, diagram, or schedule form.
Security Restrictions:
- Must be a US Citizen and have a valid Secret clearance (i.e. No active financial troubles, back taxes, felonies, foreign national interests, etc.).
Job Summary: Full-time
Salary: Salary: $70K-120K annually (Negotiable based on experience, certifications, and knowledge)
Required Job Location: Bloomington, IN
Required experience: Cyber / Information Assurance: 3 years
Required license or certification:
- Required to be Cyber Security WorkForce (CSWF) qualified
- Required to be US Citizen and obtain a SECRET security clearance
Job Type: Full-time
Pay: $70,000.00 - $120,000.00 per year
Benefits:
- Dental insurance
- Flexible schedule
- Health insurance
- Paid time off
- Vision insurance
Education:
Experience:
- RMF: 2 years (Required)
- Cybersecurity: 2 years (Required)
- Windows/Linux/AD: 3 years (Preferred)
License/Certification:
- Naturalized Citizen, or are a Natural Born U.S. Citizen (Required)
- Security+, CISSP, or CISM certification (Required)
Security clearance:
Ability to Relocate:
- Bloomington, IN 47401: Relocate before starting work (Required)
Work Location: Hybrid remote in Bloomington, IN 47401