CybersecurityJobs.io
← Back to all jobs

Job Description

Grow your security engineering impact supporting RMF compliance through Assessment and Authorization (A&A) and Continuous Monitoring (ConMon) activities across multi-level classification environments. This onsite role at Fort Belvoir, VA pairs critical security engineering work with access to cutting-edge technologies and a team that coordinates across cybersecurity, technical services, and customer stakeholders.

Compensation for this position is USD 107,950 - 146,050 per year. The role is Secret clearance required and requires U.S. citizenship, with less than 10% travel.

What you’ll do

  • Coordinate with other DSMS program teams to plan and create cybersecurity architecture and design documents, ensuring compliance with DoD and other organizational IA policies and guidance.
  • Apply best practices for implementing security controls within an IS using software engineering methodologies, system/security engineering principles, secure design and architecture, and secure coding techniques.
  • Develop cybersecurity architecture and design plans for communication and collaboration products, operating system platforms (servers, devices, and management products), applications, and security considerations for product implementation.
  • Provide security engineering support for DSMS Network accreditation.
  • Integrate cybersecurity expertise into lifecycle management, including planning architecture and design management, migration and deployment, and system testing and implementation.
  • Research, develop, test, and document architectures and solutions for implementing new cybersecurity technologies to improve information collaboration and cybersecurity capabilities for the program and its user base.
  • Develop and deliver criticality analysis for logic-bearing system components (hardware, firmware, and software) and the functions they implement, protect, or that may introduce vulnerabilities.
  • Develop and maintain mission criticality analyses, vulnerability assessments, and risk assessments, including identification and countermeasure implementation for mission-critical functions, ensuring updated assumptions, rationale, results, supply chain risk information, and mitigations are available for Government review.
  • Prepare and submit Interim Authorization to Test (IATT) and Authority to Operate (ATO) requests with Plans of Action and Milestones (PoAMs).
  • Develop, maintain, and coordinate Body of Evidence (BoE) documentation for system assets.
  • Collaborate with Technical Services and Security Services teams, plus customer agency stakeholders, to support compliance.
  • Track lien remediation/resolution workflow and enter tracking tool updates; evaluate system change requests and assess both system and organizational risks tied to modifications.
  • Execute ConMon activities on established timelines, including BoE collection and tracking tool updates.
  • Conduct recurring reviews of system state and security posture to ensure secure operation and that information systems security policies and procedures are followed.
  • Recommend security control implementation and identify countermeasures or mitigating controls; respond to security information queries and report requests.
  • Support security incident investigations and report findings as needed.
  • Assist with communication, implementation, and enforcement of security policies and plans for data, applications, hardware, and telecommunications systems.
  • Advise stakeholders on information assurance standards, dependencies, and emerging security technologies; use Enterprise Security Services tools such as Trellix and ACAS to track and remediate vulnerabilities and compliance deficiencies.

What you’ll need

  • Bachelor of Arts / Bachelor of Science
  • 2+ years of related experience
  • Secret security clearance level
  • U.S. citizenship required
  • Travel: less than 10%

Tools and technologies

  • Trellix
  • ACAS
  • Plans of Action and Milestones (PoAMs)
  • Body of Evidence (BoE)

Benefits and growth

  • 401K with company match
  • Comprehensive health and wellness packages
  • Internal mobility team dedicated to helping you own your career
  • Professional growth opportunities, including paid education and certifications
  • Cutting-edge technology you can learn from and apply to solve real world problems

Additional details

  • Location: Fort Belvoir, Virginia (onsite / on customer site)
  • REQ#: RQ229469
  • Requisition type: Regular
  • Category: Cyber and IT Risk Management
  • Public trust: None
  • Work requirements: U.S. Citizenship Required; Travel Required: less than 10%

Identity verification process

  • You are expected to be on camera during virtual interviews.
  • We reserve the right to take your picture to verify your identity and prevent fraud.
  • You authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Similar Jobs