Sr. Cybersecurity RMF Specialist

Honolulu, Hawaii

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

Apply now Apply later

Description

MSM Technology is seeking a highly skilled and experienced Senior Cybersecurity RMF Specialist to join our dynamic team in anticipation of an upcoming proposal. 

  • Deliver Cybersecurity and RMF/FISMA support to PACAF mission owners; distributing current policy and provide guidance, and mentorship to the cyber forces to ensure compliance.
  • Assist PACAF MOBs & GSUs improve & maintain implementation of congressional FISMA, DoD, and AF cybersecurity directives.
  • Conduct (on-site and/or virtual) A&A validation and reviews, using National/DoD/AF standards (e.g., DISA Security Technical Implementation Guides (STIGs), National Institute of Standards and Technology (NIST) SP 800- 12).
  • Collect and develop A&A artifacts in accordance with AO Office
  • Assisting MOBs and GSUs maintain and sustain A&A packages, including tracking/updating A&A documents/products in the following databases:
  • Connection Approval Process (CAP) for SNAP
  • GIAP circuit management tools
  • eMASS and ITIPS
  • Continuous Monitoring Risk Scoring (CMRS) efforts
  • Assist MOB and GSUs create and maintain comprehensive RMF products for the theater circuits/enclaves via eMASS as required. Products must include all requirements IAW applicable DoD and AF Instructions.
  • Assist the Government in the creation, consultation, revision, finalization, submission of the deliverables for RMF to include but not limited to the following:
  • System Security Plan
  • Ports Protocol Services Matrix (enclave)
  • Artifacts for control validation (STIG results, Policies, Scans, Charters, etc., unit provided)
  • Plan of Actions and Milestones (POAMs)
  • System Topology
  • Provide updates through AF central FISMA database repository, ITIPS.
  • Ensure A&A data are synchronized across AF and DISA repositories (eMASS, ITIPS, SNAP, and GIAP).
  • Assist processing circuit connection requests for all the main bases through SIPRNet Global Information Grid (GIG) Interconnection Approval Process (GIAP) System (SGS) and the NIPRNet SNAP.
  • Prepare and mentor NAF, Wing and cybersecurity forces through the CRR-M program.
  • Train and assist PACAF MOBs & GSUs personnel in the use of DoD security technical implementation tools and technology to maintain & improve cyber readiness.
  • Consult to resolve any issues with DoD required vulnerability scanning tools, including system credentials, access control list, and identified network assets.
  •  Consult to resolve any issues with DoD required endpoint security solutions for all host devices in the network enclaves.
  • Assist and prepare PACAF Wings for CORAs & CCORIs on NIPRNet, SIPRNet and supported information systems.
  • Create CORA and CCORI scores and Risk Assessment Report for the MOBs & GSUs using DISA CORA Scoring and Risk Assessment tools
  •  Provide recommendations for mitigations & follow-on actions to include POAMs.
Requirements

Minimum Requirements

  • Top Secret (TS) / Sensitive Compartmented Information (SCI) security clearance
  • Certification requirement: CISM or CISSO or CPTE or CySA+ or FITSP-A or GCSA or CISA or CISSP or CISSP-ISSEP or GSLC or GSNA OR CASP+ CE, CISA, CISSP, CCSP, or CISSP Associate
  •  2-3 years of experience and the skills required to execute Federal, National, DoD, USAF CIO, and US State Department Requirements to be able to assess cyber risk, identify mission sets, and defend the mission.
  • 2-3 years of experience of applying, assessing, and advising MAJCOM staff and Wings on cybersecurity requirements.
  • Understand the AF Cyber architecture and PACAF MOBs and GSUs roles.
  • Ability to travel to PACAF MOBs Guam, Alaska, Japan, Korea -at a maximum up to 40% of the time.
  • Proficiency in Microsoft Office Suite products and SharePoint collaborative tools.

RMF/FISMA/ATO Requirements

  • 2-3 years of experience conducting RMF/FISMA/ATO A&A.
  • 2-3 years of experience maintaining accreditation at a level consistent with AF, DoD and FISMA requirements for all base enclaves and providing situational awareness of assigned systems at MOBs and GSUs.
  • 2-3 years of experience with DISA Connection Approval Process vehicles (e.g., SNAP, SGS, GIAP, and CDS-approval).
  • Expertise with FISMA compliance vehicle – AF centralized repository for FISMA reporting is ITIPS.
  • Expertise with AF System A&A process vehicles (e.g., eMASS, AF PPSM, AF Software Approval) to produce ATO, ATC, Interim Authority to Connect (IATC).

CRR-M Requirements

  • 2-3 years of experience of conducting assessments of SIPRNet/NIPRNet network, enclave, and system security posture providing guidance, mitigation recommendations and familiarization to personnel on cyber security to include prepare/advise pre-, post-, and during-inspections.
  • In-depth experience with DISA STIGs and by-product analysis

CORA & CCORI Support Requirements

  • 2-3 years of experience of conducting CORA & CCORI inspections.
  • Expertise with CORA process vehicles.
  • Expertise with CCORI process vehicles (e.g., MADSS, ELICSAR, etc.)
  • Expertise with USCYBERCOM/DISA CORA Scoring Tools (option to utilize the AF “Cyber Ready 365”).
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: CASP+ CCSP CISA CISM CISSP Clearance Compliance DISA DoD eMASS Endpoint security FISMA GSLC GSNA Monitoring NIST Risk assessment Risk Assessment Report RMF Security Clearance SharePoint STIGs System Security Plan Top Secret Travel

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.