CybersecurityJobs.io
← Back to all jobs

Job Description

Falconwood, Inc. is seeking a Cyber Security Analyst to support the USFF N6 Directorate Fleet Enterprise Support Team and the PSO in delivering end-to-end Risk Management Framework (RMF) Assessment & Authorization (A&A) support for Navy shore commands. The role focuses on overarching expertise for A&A, compliance validation, and the tracking and mitigation of physical, policy, and network security issues across mission-relevant systems.

Working onsite in Norfolk, VA, you will help ensure submitted A&A packages meet DoD and Navy Cybersecurity requirements, while also supporting risk assessment and accreditation decision milestones for Navy Authorizing Officials (NAOs).

Responsibilities

  • Review A&A package submissions to verify that system and network architectures, along with technical and non-technical operating features, adequately protect and defend against unauthorized access, support system availability, and satisfy DoD/Navy Cybersecurity implementation policy and data protection safeguards.
  • Perform CS compliance and A&A documentation validation assessments for Naval networks, legacy applications, and other systems.
  • Support the development and updates of existing A&A and CS documentation to ensure completeness in accordance with DoD A&A and CS policy.
  • Assist in developing procedures for A&A workflow processes, including criteria that support NAO accreditation decision milestones.
  • Contribute to trainings, presentations, briefings, and written documentation supporting A&A and CS functions as needed.
  • Help develop and maintain Standard Operating Procedures (SOPs), checklists, workflow process charts, and other documentation required for NAO processes and related A&A functions.
  • Support USFF subordinate commands with risk assessment related tasks such as discussing assessment results, documenting vulnerability status, and providing guidance and training across RMF topics.
  • Collaborate with motivated teammates and provide reciprocal support across the team.
  • Monitor and report the security posture for mission critical systems, including communicating risk and recommended mitigations.

Requirements

  • Information Assurance Technician (IAT) Level III qualifications (including CISSP, CISM, CASP, etc.).
  • Active DoD Secret clearance.
  • Minimum 5 years of experience in DoW/DoN Cybersecurity, Engineering, Test & Evaluation, or Assessment & Authorization (A&A).
  • Ability to provide technical support and apply expertise assessing information system compliance with DoN and Navy RMF standards, including review, verification, and validation of required DoD RMF documentation and artifacts in accordance with DoD Instruction 8510.01, the Navy SCA Risk Assessment Guide (RAG), and the Navy RMF Process Guide (RPG).
  • Demonstrated knowledge of DoD cybersecurity policies, procedures, and practices (including RMF and NIST SP 800-53) to achieve and maintain system accreditation and authorization.
  • Experience analyzing, summarizing, and reporting security vulnerabilities and weaknesses verbally and in writing to appropriate leadership.
  • Self-motivated with an understanding of technical concepts, strong communication skills, and the ability to collaborate on technical items.
  • Knowledge and experience using DoD tools and capabilities for vulnerability assessments and compliance reporting, including eMASS, ACAS, STIGs, SRGs, SCAP, and related capabilities.
  • Knowledge and experience with cybersecurity, information technology, and network architecture, including computers, operating systems (Linux and Windows-based), networks, network devices, deployment environments (such as data centers and cloud), and systems and application security threats and vulnerabilities.
  • Ability to perform quality assurance reviews for required A&A process package content in accordance with provided SOPs and checklists.
  • Proficiency with Microsoft Office (Word, Excel, PowerPoint).

Technologies

  • CISSP, CISM, CASP
  • DoD Instruction 8510.01
  • Navy SCA Risk Assessment Guide (RAG)
  • Navy RMF Process Guide (RPG)
  • RMF, NIST SP 800-53
  • eMASS, ACAS, STIGs, SRGs, SCAP
  • Linux, Windows-based
  • Microsoft Office (Word, Excel, PowerPoint)

Preferred

  • BS degree in Computer Science, Cyber Security, or a related technical field.
  • Minimum of 3 years of experience as a Navy Qualified Validator (NQV).
  • Experience training or instructing a small group with varied levels of experience.
  • Experience supporting information assurance for US Navy systems.
  • Experience performing information assurance for cloud environments (and/or cloud-related certification).

Pay Range

$130,000 - $140,000 per year.

Similar Jobs