Role OverviewAs an Information Security Analyst Sr Principal, you will be responsible for the ICAM program's network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies.
What You Will Do
Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network. Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports. Define, draft, publish, and maintain Information Security policies, standards, and guidelines. Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports.
Why It Might Be a Fit
This role requires an active DoD Security Clearance of SECRET or higher, and a minimum of eight years' experience supporting IT customers in an enterprise environment. You will need a CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification, and experience with FedRAMP Cloud processes. The likely salary range is $142,792 - $184,000, and the position offers a comprehensive benefits package including medical, dental, vision, 401(k) with company match, and various paid time off plans.
Requirements
- Active DoD Security Clearance of SECRET, or higher
- Minimum eight (8) + years' experience and proven track record supporting IT customers as part of an enterprise environment
- BA/BS and 8+ years of Computer Science or equivalent experience
- CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification
- Experience with FedRAMP Cloud processes
- Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 'Cybersecurity', NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 'Risk Management Framework'
- Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS
- Ability to lead in highly collaborative, fast-paced, growth-focused environment
- Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee
- Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans
- Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud
- Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans
- The ability to effectively communicate with people ranging from non-technical to engineering level
Benefits
- Medical plan options with Health Savings Accounts
- Dental plan options
- Vision plan
- 401(k) plan with company match
- Full flex work weeks
- Vacation, sick and personal time
- Holidays
- Paid parental leave
- Military leave
- Bereavement leave
- Jury duty leave
- Short and long-term disability benefits
- Life insurance
- Accidental death and dismemberment insurance
- Personal accident insurance
- Critical illness insurance
- Business travel and accident insurance
]]>