Perform ongoing security analysis and compliance assessments under the DoD Risk Management Framework (RMF) processes, including continuous monitoring, POA&M management, and risk assessments.
Utilize ACAS (Assured Compliance Assessment Solution) and Tenable tools to perform vulnerability scanning, trending, and reporting of system compliance posture.
Conduct STIG and SCAP compliance checks on network devices, servers, and applications, coordinating remediation with system owners.
Develop data visualizations and trend analyses using Microsoft Power BI and Microsoft Excel to identify recurring vulnerabilities and track mitigation progress.
Prepare briefing materials and communicate technical issues, risks, and recommendations to customer leadership, engineering teams, and program managers.
Collaborate with information system owners to ensure systems achieve and maintain Authorization to Operate (ATO) and meet continuous monitoring requirements.
Participate in incident response efforts, investigations, and after-action reporting to improve future preparedness.
Requirements
Minimum of 3 years of experience with DoD RMF processes supporting NIST SP 800-53 and CNSSI 1253 compliance.
Demonstrated experience with ACAS, SCAP Compliance Checker, and implementation of DISA STIGs.
Experience using Power BI or Microsoft Office Suite to produce analytical reports and dashboards.
Proven skill in risk management activities, including developing, tracking, and resolving POA&Ms and conducting formal risk assessments.
Strong communication and presentation abilities to effectively brief customers and technical teams.
Experience working within DoD network environments or Federal compliance programs.
Benefits
Competitive compensation
Comprehensive benefits
Career development opportunities
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.