CybersecurityJobs.io
← Back to all jobs

Job Description

Zantech is seeking an Information Systems Security Analyst (ISSA) to support the Air National Guard Decision Support System (ANGDSS) under the AWTCSS contract. This onsite role in Reston, VA focuses on helping sustain an Authority to Operate (ATO) by executing RMF information assurance activities, inspections, testing, reviews, and ongoing security program maintenance and reporting.

Role focus

The ISSA will conduct and document RMF work to support ANG DSS in maintaining its ATO. Activities include updating and validating security control evidence in eMASS, supporting security program artifacts, and developing Plan of Actions and Milestones for items requiring remediation.

Responsibilities

  • Perform information system security inspections, tests, and reviews of the Risk Management Framework (RMF) Information Assurance Package to help ensure ANG DSS maintains an ATO.
  • Update artifacts and information in Enterprise Mission Assurance Support Service (eMASS) to validate Security Controls and Assessments.
  • Develop Plan of Actions and Milestones (POAMs) for non-compliant items.
  • Maintain a formal information system security program, including systems security plans, cyber security policies, security control assessments, contingency plans, configuration management plans, incident response plans, POAMs, risk management plans, and vulnerability scanning or vulnerability management plans.
  • Support verification that software, hardware, and firmware comply with appropriate security configuration guidelines (including security technical implementation guides and security requirement guides).
  • Ensure cybersecurity-related events and configuration changes that affect AF IT authorization or degrade security posture are formally reported to the Authorizing Official (AO) and other affected parties (including Information Owners (IOs) and stewards and AOs of interconnected IT).
  • Coordinate with the Air National Guard Readiness Center’s RMF lead on eMASS related tasks.

Requirements

  • 1+ years of experience working on ATOs for government systems.
  • Ability to manage Plan of Actions & Milestones (POA&M) documents for Information Systems.
  • Demonstrated on-the-job knowledge of the RMF process and NIST publications (including NIST 800-53 and NIST 800-37), including development and maintenance of associated certification and accreditation documentation.
  • Excellent writing, verbal communication, and time-management skills.

Technologies

  • Risk Management Framework (RMF)
  • NIST 800-53
  • NIST 800-37
  • Enterprise Mission Assurance Support Service (eMASS)
  • Plan of Actions and Milestones (POAMs)
  • Plan of Actions & Milestones (POA&M)
  • Security technical implementation guides
  • Security requirement guides

Clearance

  • US citizenship and ability to obtain and maintain an active Secret (or higher) clearance, per contract requirements.

Certifications

  • IAT Level II or IAM Level II DoD approved cybersecurity baseline certification, or higher.

Education

  • Bachelor’s Degree in Information Systems, Information Assurance Management, Computer Science, or related field (may be substituted for relevant work experience).

Similar Jobs