What are the responsibilities and job description for the Information Systems Security Analyst position at Boarhog, LLC?
Boarhog LLC is seeking a mid-level Information Security Analyst (ISA) in San Diego, CA. supporting a U.S. Navy systems acquisition program office in the execution of Risk Management Framework (RMF), with Federal Information Security Management Act (FISMA) and government Technical Authority products and processes compliance.
The U.S. government client requires Information System Security Engineering Support Services in order to acquire and sustain Information Warfare systems and technologies Cybersecurity to ensure strong authentication, data integrity, confidentiality, non-repudiation, and availability of interoperable Command and Control, Communications, Computers, and Intelligence (C4I) capabilities.
The ISA will be expected to work with systems engineers in analyzing current and emerging operational and functional requirements (in the context of Cybersecurity) of existing systems as well as capabilities under development, and assist with the development of engineered solutions that adhere to RMF cybersecurity compliance requirements, evaluating Commercial-Off-The-Shelf (COTS) and other technologies for applicability to cybersecurity compliance.
Successful candidates will be expected to immediately perform Risk Management Framework (RMF) duties, and participate in the following activities:
- Support the program office’s Assistant Program Manager for Cyber Security (APM-CS) in maintaining the authorization of assigned systems, including continuous monitoring vulnerability management
- Prepare and present risk assessment briefs, including High-Risk Escalation, for executives
- Collaboration with Validators, Information Systems Security Engineers and supported Information Systems Security Manager (ISSM).
- Coordinate with Systems Engineering to authorize system upgrades
- Perform duties of the RMF Information Systems Security Engineer role as defined by the Navy’s RMF Process Guide (RPG)
- Perform assigned duties of the RMF ISO/PM role as defined by the Navy’s RPG
- Perform preliminary security assessments of components, subsystems, and systems, including reviewing and/or executing Nessus Vulnerability Scans, Security Technical Implementation Guide (STIG) Benchmarks, manual STIG testing, and NIST SP 800-53a assessment procedures
Responsibilities also include being prepared to answer routine A&A questions during meetings, gather data and perform the analysis required to close action items, and document recommendations and decisions reached.
Mandatory Qualifications, Experience, and Certifications:
- MUST have at least a current CompTIA Security certification
- MUST have at least three (3) years of RMF experience
- MUST have an active SECRET level security clearance on day one
- Cyber Security Workforce technical certification
- Examining system architectures, engineering processes, and cybersecurity functionality to include implementation, reviewing cross system interfaces and systems integration for feasibilities and vulnerabilities, assisting with and observing test and evaluation
- Verification and validation, engineering analysis, technical documentation analysis, reviewing software and hardware designs for cybersecurity risks or issues and recommend mitigation and resolution strategies.
- Proficiency with all phases of the RMF transformation and the activities to transition a system from DIACAP to RMF
- Assuring the system security posture is attained and maintained in accordance with DoD and DoN Information Assurance (IA) Technical Authority directives, Naval Information Forces (NAVIFOR) and Type Commander (TYCOM) operational guidance
- Proficiency with Enterprise Mission Assurance Support Service (eMASS)
Desired Qualifications, Certifications, and Discriminators:
- Certified Information Systems Security Professional (CISSP) or equivalent certification
- Prior Federal Public Sector (preferably Navy) Acquisition Program Management Office experience
- Prior experience authorizing RMF High Impact, classified systems
- Knowledge of Fleet operations, IT network security, software and hardware security engineering, and cybersecurity regulations, policy, and strategy
- Eligible for a Top Secret / Sensitive Compartmented Information clearance (TS/SI/TK/G/HCS)
- Navy Qualified Validator II or III
System Administrator/Information Systems Security
Tactical Engineering & Analysis Inc -
San Diego, CA
Information Systems Security Officer (ISSO)
H2 Performance Consulting -
San Diego, CA
Information Systems Security Officer - TS clearance with SCI eligibility
americansystems -
San Diego, CA