XOR Security an Agile Defense Company
Job Title: Info Sys Sec Mgr
Location: 661 Washington Blvd, Ft. Eustis, Virginia 23604
Clearance Level: Active DoD - Secret
- DoD IAM Level II Certification.
The United States Army Training and Doctrine Command (TRADOC) is a major command of the Unites States Army headquartered at Fort Eustis, Virginia. It is charged with overseeing the training of Army forces and the development of operational doctrine. TRADOC recruits, trains, educates, develops, and builds the Army, establishes standards, drives improvement, and leads change to ensure the Army can deter, fight, and win on any battlefield now and into the future. This TRADOC Cloud & Ancillary Support Services (TCASS) contract includes objectives and tasks for cloud migration planning services to include: Inventory (Users, Applications, Infrastructure, Security & Privacy, Services Management); Application Mapping and Assessment; Migration Planning, Migration Services, and Cloud Support Service
JOB DUTIES AND RESPONSIBILITIES
- Manage all aspects of the RMF process from start to finish and support accreditation package development through customer acceptance.
- Fully understand and execute all RMF steps necessary for creating A&A packages in accordance with DoD, Defense Information Systems Agency (DISA), and Army cybersecurity requirements.
- Monitor and manage system Enterprise Mission Assurance Support Service (eMASS) records.
- Conduct cybersecurity testing analysis and provide overall vulnerability and risk assessment reports.
- Create and update Plan of Action and Milestones (POA&Ms).
- Provide Cybersecurity support to enterprise technical teams/system administrators with IAVA remediation and STIG checklist creation and maintenance.
- Work closely with internal and external personnel to address unique cybersecurity concerns.
- Communicate and collaborate with EISD team members to ensure cyber related taskers are worked, reported, and completed in timely manner.
- Work well in a team-oriented environment and can self-manage their tasks to ensure success.
- Complete reviews of required A&A documentation and artifacts to include: POA&Ms, SCA-V Reports, MOU, MOA, connection agreements, dataflow diagrams, network diagrams, and other documents and make recommendations to the O-ISSM.
- Support the ISO/PM in his or her role to ensure assigned IT capabilities are properly identified, evaluated, configured, and authorized to operate at the approved level of risk.
- Assign ISSO’s for IT owned by the organization within the scope of the O–ISSM.
- Ensure hardware connected to any system or network has the express written consent.
- Establish procedures to scan their networks quarterly to identify assets; application, network, and operating system vulnerabilities; configuration errors; and points of unauthorized access.
- DoD IAM Level II Certification.
Education, Background, and Years of Experience
- 10+ years of relevant experience (with MA/MS). 12+ years experience (with BA/BS).
ADDITIONAL SKILLS & QUALIFICATIONS
- Experience performing the full cycle of system Assessment and Accreditation (A&A) activities.
- Excellent working knowledge of the National Institute of Technology (NIST) Risk Management Framework (RMF).
- Solid technical background with strong understanding of network architectures and communications, operating systems, web platforms, and databases.
- Experience developing and maintaining system security documentation, including but not limited to System Security Plans, Security Assessment Reports, Contingency Plans, and Interconnection Security Agreements.
- Experience developing and updating Plans of Actions and Milestones (POA&Ms) and overseeing efforts to rectify issues found as a result of security vulnerabilities and security controls analysis.
- Excellent interpersonal, organization, writing, communicating, and briefing skills.
- Contractor site with 0%-10% travel possible. Possible off-hours work to support releases and outages. General office environment. Work is generally sedentary in nature, but may require standing and walking for up to 10% of the time. The working environment is generally favorable. Lighting and temperature are adequate, and there are not hazardous or unpleasant conditions caused by noise, dust, etc. Work is generally performed within an office environment, with standard office equipment available.
- Sedentary – 10 lbs. Maximum lifting, occasional lift/carry of small articles. Some occasional walking or standing may be required. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
- Stand or Sit; Walk; Repetitive Motion; Use Hands / Fingers to Handle or Feel.
XOR Security an Agile Defense Company offers a very competitive benefits package including health insurance coverage from the first day of employment, 401k with a vested company match, vacation and supplemental insurance benefits.
XOR Security an Agile Defense Company is an Equal Opportunity Employer (EOE). M/F/D/V.
Citizenship Clearance Requirement
Applicants selected may be subject to a government security investigation and must meet eligibility requirements - US CITIZENSHIP and PUBLIC TRUST CLEARANCE REQUIRED.
- Citizenship: Not Provided
- Incentives: Not Provided
- Education: Not Provided
- Travel: Not Provided
- Telework: Not Provided