Overview
IvoryCloud is seeking an experienced Cybersecurity Analyst to support the Defense Contract Management Agency's (DCMA) Program, a Department of War (DoW) initiative. This position serves as a technical subject matter expert supporting the cybersecurity evaluation of the product submissions, providing advisory support to the Government on cybersecurity requirements, risk management, and assessment methodologies for embedded systems, firmware, wireless communications, and supply chain security. The ideal candidate brings practical experience interpreting penetration test results, vulnerability assessments, and software assurance evaluations, along with strong working knowledge of the DoW Risk Management Framework (RMF). This position is based on-site at the DCMA facility in Fort Lee, Virginia.
Requirements
- U.S. Citizenship: Required, non-negotiable. (This differs from eligibility to work in the U.S.)
- Clearance: Favorably adjudicated (or actively in-progress) Tier 3 background investigation required for access to Controlled Unclassified Information (CUI); interim or final security clearance granted by the Department of War (DoW) required prior to start of performance. Current ADP/IT II clearance in the Defense Information System for Security (DISS) required.
- Minimum Years Experience: Minimum of five (5) years of practical cybersecurity experience preferred, ideally including technology risk assessment or product security evaluation.
- Location: Fort Lee, Virginia – on-site at the DCMA facility. Personnel assigned to this location will initially perform work remotely until Government office space is allocated; the Government will provide 30 days’ notice prior to the start of on-site work.
- Demonstrated knowledge of cybersecurity principles applicable to embedded systems, software, firmware, wireless communications, networking, encryption, authentication, and supply chain security.
- Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls and NIST SP 800-161 (Supply Chain Risk Management), and navigating the DoD/DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO).
- Experience interpreting cybersecurity assessment methodologies, penetration testing results, vulnerability assessments, software assurance evaluations, and firmware analyses.
- Ability to evaluate the completeness, technical sufficiency, and adequacy of cybersecurity assessment reports and supporting evidence in support of Government technical acceptance decisions.
- Working knowledge of applicable Federal statutes, DoW policies, National Defense Authorization Act (NDAA) requirements, and cybersecurity frameworks relevant to small unmanned systems.
Education
- Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline.
- Equivalent professional experience may be considered in lieu of a formal degree on a case-by-case basis.
Certifications
- Certifications:
- No specific certification is mandatory for this role under current program requirements.
- CompTIA Security+, CISSP, CISM, or an equivalent cybersecurity certification preferred.
Job Description
- Serve as a technical subject matter expert (SME) supporting the cybersecurity evaluation of product submissions to the Program.
- Provide technical expertise and advisory support to the Government Program regarding cybersecurity requirements, technical standards, risk management, and assessment methodologies.
- Apply demonstrated knowledge of cybersecurity principles applicable to embedded systems, software, firmware, wireless communications, networking, encryption, authentication, and supply chain security relevant to the Program.
- Interpret cybersecurity assessment methodologies, penetration testing results, vulnerability assessments, software assurance evaluations, firmware analyses, and other technical assessment data to evaluate risks associated with candidate technologies.
- Review cybersecurity assessment reports, supporting technical documentation, and assessment evidence to evaluate completeness, technical sufficiency, and adequacy in support of Government technical acceptance decisions.
- Identify cybersecurity vulnerabilities, threats, attack vectors, and residual risks that may adversely affect DoW missions, warfighter safety, national security, operational resilience, or the confidentiality, integrity, and availability of Government information and systems.
- Provide technical recommendations regarding cybersecurity findings, risk mitigation strategies, assessment requirements, technical acceptance, and the applicability of cybersecurity requirements to program candidate technologies.
- Verify and validate whether a company's submitted remediation plan sufficiently mitigates cyber vulnerabilities identified in provided assessments.
- Maintain awareness of applicable Federal statutes, DoW policies, National Defense Authorization Act (NDAA) requirements, cybersecurity frameworks, industry best practices, and Government processes relevant to the Program.
- Provide technical consultation and advisory support to Government personnel and stakeholders regarding cybersecurity matters affecting the program technologies, assessments, policy implementation, and program execution.
- Monitor emerging cybersecurity threats, vulnerabilities, technologies, and policy developments affecting small unmanned systems and provide recommendations to support the continued evolution of the Program.
Preferred Qualifications
- Direct experience supporting DCMA, or related programs.
- Experience evaluating embedded systems, firmware, and supply chain security risk for commercial or defense technologies.
- Familiarity with the DoW Risk Management Framework (RMF) and Authority to Operate (ATO) process.
- Experience reviewing third-party penetration test results and software assurance evaluations for federal acceptance decisions.
- Active or recent industry certification such as CompTIA Security+, CISSP, or CISM.
Benefits
- Salaried position and eligible for participation in company and Business Development bonus programs
- Full-time benefits include:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Referral program
- Retirement plan
- Vision insurance
About IvoryCloud
IvoryCloud is a growing 8(a) certified small business. Our work with Federal and commercial clients includes Mission Systems development, modernization, and support, Software services, AI/ML engineering, Enterprise Cybersecurity, and Mission Optimization services. We are a growing, privately held small business located in Rockville, MD. IvoryCloud is an Equal Opportunity Employer (EEO).
Pay: $80,000.00 - $110,000.00 per year
Benefits:
- 401(k) matching
- Health insurance
- Paid time off
- Vision insurance
Application Question(s):
- Are you a US Citizen (required)?
- Are you able to come onsite 5 days a week in Fort Lee, VA?
- Have you passed a Tier 3 investigation (ADP/IT-II equivalent) or have an investigation in progress?
Work Location: In person