Salary
💰 $75,200 - $158,100 per year
About the role
- Play a critical role in the EITaaS program by identifying, tracking, reporting, and mitigating STIG findings for the Department of the Air Force.
- Document detailed action plans, create custom STIG reports for Air Force bases, and provide specific remediation guidance for both Enterprise-managed and base-managed STIGs.
- Conduct monthly reviews of Tenable and SteelCloud STIG reports; analyze data to remediation actions and identify responsible parties.
- Review updates to DISA STIGs when new ones are published.
- Document comprehensive action plans for identified STIGs and prioritize based on severity and exploitability.
- Develop and maintain custom STIG reports tailored for individual Air Force bases and communicate remediation responsibilities and timelines.
- Provide actionable remediation guidance to Air Force bases and leadership aligned with policies and resource constraints.
- Collaborate with base IT teams, Enterprise security teams, and stakeholders; participate in meetings and briefings on trends and remediation progress.
- Engage with the Cyber Security Dashboard team to identify improvements to automated messaging regarding STIGs.
- Stay current with STIG trends, threat intelligence, and best practices; recommend process and tool improvements to streamline assessment and remediation efforts.
Requirements
- 10+ Years of relevant experience (Bachelor’s Degree in applicable field may be substituted for 5 years of experience).
- Security+ certification (or equivalent)
- Minimum of 3 years of experience in STIG management or a related cybersecurity role.
- Experience with Tenable or similar STIG scanning tools.
- Familiarity with Air Force IT systems and security protocols is a plus.
- Working Knowledge of Excel and pivot tables.
- Experience with STIG Viewer and CLK files.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to work independently and as part of a team.
- Detail-oriented with strong organizational skills.
- Desired: Experience in creating and managing custom STIG reports.
- Desired: Knowledge of Air Force or DoD security standards and regulations.
- Desired: Proven track record of successful STIG remediation projects.