CybersecurityJobs.io
← Back to all jobs

Job Description

Support AFOSI cybersecurity operations with intermediate-level information assurance, RMF deliverables, vulnerability management, and security monitoring.

Responsibilities

  • Provide technical engineering and implementation of security solutions, including:
    • Designing and managing a vulnerability scanning architecture
    • Engineering and implementing a SIEM solution
    • Integrating security testing into the development pipeline
    • Defining secure configuration baselines
    • Developing technical documentation for security architecture
  • Build, coordinate, maintain, and update RMF Assessment and Authorization packages and support security documentation for AFOSI systems and enclaves
  • Implement and monitor security controls, document findings, and track remediation activities through the POA&M process
  • Support vulnerability scanning and reporting, including:
    • Reviewing scan results
    • Maintaining asset lists
    • Scheduling scans
    • Identifying configuration issues and missing patches using ACAS or comparable tools
  • Correlate vulnerability findings with IAVM alerts and bulletins, including CVE mapping to support compliance tracking
  • Review system and application configurations against applicable DISA STIGs and Security Requirements Guidance
  • Maintain GRC records and eMASS artifacts, including policies, plans, procedures, reports, and authorization documentation
  • Support security-log review and reporting using SIEM tools such as Splunk or ArcSight; use basic PowerShell scripts to collect and organize security data
  • Collaborate with cybersecurity, infrastructure, operations, and development teams; communicate findings clearly; support readiness assessments and incident-response activities as assigned

Requirements

  • Active Top Secret clearance and SCI eligible
  • Approved DoD 8570/8140 IAT Level II certification, or ability to obtain required certification within the timeframe permitted by the contract
  • Foundational knowledge of:
    • RMF
    • STIGs
    • Security controls
    • Vulnerability management
    • POA&M tracking
    • Event-log review
    • Firewalls
    • Security risk assessments
  • Familiarity with tools is preferred rather than required, including:
    • eMASS and other GRC applications
    • ACAS/Tenable and HBSS
    • Splunk and ArcSight
    • Active Directory, PowerShell, and asset-management tools
  • U.S. citizenship
  • 5 years of cybersecurity and information assurance experience, including at least 3 years of systems administration experience supporting servers and infrastructure
  • Associate’s or bachelor’s degree in cybersecurity, information technology, computer science, or related field preferred; equivalent technical training and relevant experience considered
  • Demonstrate attention to detail, analytical problem-solving, effective oral and written communication, and ability to learn DoD cybersecurity processes and tools

Technologies

  • Risk Management Framework (RMF)
  • Security Information and Event Management (SIEM)
  • Splunk
  • ArcSight
  • PowerShell
  • ACAS
  • Tenable
  • eMASS
  • HBSS
  • Active Directory
  • IAVM
  • Common Vulnerabilities and Exposures (CVE)
  • DISA Security Technical Implementation Guides (STIGs)
  • Security Requirements Guidance
  • Plan of Action and Milestones (POA&M)
  • GRC applications
  • Asset-management tools

Benefits

  • Medical
  • Dental
  • Vision
  • Life and disability coverage
  • Retirement savings with company match
  • Paid time off
  • Voluntary supplemental benefits
  • Access to an employee assistance program
  • Educational assistance with tuition reimbursement

Location: Quantico, VA (onsite)

Salary: USD 100,000 - 145,000 per yearly

Similar Jobs