Salary
💰 $140,000 - $165,000 per year
Tech Stack
CloudCyber SecurityiOSJavaScriptSDLC
About the role
- Serve as the primary cybersecurity technical advisor to the AO, PM, and ISO, ensuring integration of cybersecurity into the IT lifecycle in accordance with DoDI 8510.01
- Author and contribute to white papers, technical reports, and executive summaries to support company cybersecurity strategy, compliance posture, and innovation initiatives
- Lead and participate in special company-level cybersecurity projects, pilots, and process improvement efforts
- Manage and mentor cybersecurity staff, including task oversight, performance evaluation, and career development support
- Support the PM or ISO in maintaining current Authorization to Operate and Approval to Connect, and implementing corrective actions to keep applications secure
- Coordinate with the PMO office, SCA team, and AO staff in developing an ISCM strategy and monitoring system/environment changes
- Continuously monitor IT and environment for security-relevant events and assess proposed configuration changes for impact on cybersecurity posture
- Assess quality of security control implementation against performance indicators
- Ensure cybersecurity-related events or configuration changes that impact AF IT authorization are formally reported to the AO and other affected parties
- Ensure all ISSOs and privileged users receive necessary technical training and manage day-to-day ISSO tasks
- Manage eMASS security control test results and documentation
- Oversee the creation of RMF-related artifacts specific to NIST security control families
Requirements
- Candidate must be a U.S. Citizen
- Candidate must have at least a Bachelor's degree in information technology
- Candidate must have active DoD Secret Clearance at minimum
- Candidate must have an active DoD 8570.01 IAM Level III/8140 Advanced Certification (CISM, CISSP, GSLC, CCISO)
- Candidate must have 10+ years' experience with ISSO/ISSM experience with mission application in RMF Authorization to Operate (ATO) process management of RMF and A&A process, risk assessments, and security controls
- Experience creating, updating and reviewing ATO artifacts, required documentation, ITCSC, control baselines, PPSM, etc.
- Experience with STIG reviews, analyzing ACAS and Checkmarx results, providing remediation recommendations and test results
- Experience overseeing security configuration reviews and creating Security Test Plans
- Experience with Agile methodologies and SDLC process experience
- Meets the technical requirements relevant to the cybersecurity roles, responsibilities, and technical system functionality and processes
- Requires ability to provide clear, concise, accurate and timely communication, both verbally and in writing (100%)
- Requires ability to interact professionally with co-workers, management, and client (100%)
- Occasional business travel may be required
- Desired: Knowledge of the Atlassian Product Family (Confluence, Jira)
- Desired: Experience supporting DoD government customers preferred
- Desired: Previous experience under the CE IT AO is a plus
- Desired: Previous Cloud ATO experience