Cybersecurity Systems Analyst – Senior

at Technical and Management Resources, Inc.
Published November 27, 2022
Location Colorado Springs, CO
Category Default  
Job Type Full-time  

Description

The scope of this contract is to provide enterprise-wide cybersecurity support and solutions to the SIE to enable the USSOCOM mission by helping keep the network and Information Systems (IS) secure. USSOCOM has a requirement for cybersecurity key elements which include assessment (see paragraphs 3.1 and 3.2) and authorization, compliance, policy, plans and procedures, engineering, architecture, training, certification and awareness, connectivity approval, reporting and cross domain solution.

Typical duties include:

  • Tracks A&A status of SIE governed ISs. Ensures these artifacts and documentation are available in the USSOCOM-chosen automated

  • Advises stakeholders on the adequacy of implementation of cybersecurity requirements.

  • Provide DoD & IC RMF subject matter expertise to USSOCOM, its Component Commands, TSOCs, deployed forces and their delegates, including other Contractors, and assist with the development and execution of the RMF program at USSOCOM, its Component Commands, TSOCs, and deployed forces.

  • Maintain, track, and validate DISN, cloud and DIA connection approval packages, including those from USSOCOM, its Component Commands, TSOCs, and other subordinate organizations.

  • Develop and maintain supporting documentation for new and existing networks, cloud environments, information systems and technologies as they are introduced into the SIE.

  • Develop and review the A&A of SIE networks, cloud environments, systems, services, telecommunication circuits, mobile devices, portable electronic devices, hardware, and software using the DoD & IC RMF to obtain an Authority to Operate (ATO), Interim Authority to Test (IATT), or Authority to Connect (ATC).

  • Perform risk and vulnerability assessments of IT and IS for authorization; prepare risk assessment reports for submission to the SCA and Authorizing Official/Designated Authorizing Official/Designated Accrediting Authority (AO/DAO/DAA) in accordance with DoD, DIA, USCYBERCOM, USSOCOM, Component Command, TSOC, and deployed forces policies, procedures, and regulations.

  • Assist USSOCOM, its Component Commands, TSOCs and deployed forces with the enforcement of A&A, as well as DoD, DIA, USSOCOM, Component Command, TSOC, and deployed forces connection standards for networks and systems.

  • Track and maintain A&A databases, web sites and tools to ensure that networks, systems and devices are properly documented and managed from a cybersecurity perspective.

  • Track and report to higher headquarters organizations (e.g. USCYBERCOM, DIA) compliance with applicable Cybersecurity regulations and directives.

  • Ensure timely notifications are made to responsible individuals and organizations in order to prevent lapses in accreditations (e.g., 30, 60, and 90 day notices).

  • Develop and maintain an Information Security Continuous Monitoring (ISCM) Plan. This plan shall address ongoing awareness of information security, vulnerabilities, security controls, and threats to support organizational risk management decisions.

  • Identify, assess, and advise on cybersecurity control compliance and associated risks.

  • Coordinate with USCYBERCOM, DoD, DIA, NSA, DISA, and subordinate organizations to support the resolution of issues with security, A&A, connection approvals, and waiver requests.

  • Perform network, cloud, information systems, hardware, software and device security authorization and assessments, as well as the application and execution of policy, including project management support services.

  • Validate the patching of systems, perform validation scanning, develop Plans of Action & Milestone (POA&Ms), and report as directed by applicable policies, procedures, and regulations.

  • Provide subject matter expertise for COA development and the implementation of Cybersecurity mitigation strategies.

  • Develop and implement required processes, procedures, and capabilities to mitigate vulnerabilities and weaknesses for software and hardware deployment.

  • Identify, implement and validate continued effectiveness of key performance parameters and applied security measures.

  • Perform analytics on cybersecurity posture and provide reports to the AO/DAO and applicable stakeholders as required per ISCM and AO/DAO direction.

Position Level: Senior

Clearance: Active TS/SCI clearance required

Years of Experience Required: 8+ yrs.

Education Required: BA/BS

Certification Required: DoD 8570.01- M, IAT- Level 3 or IAM Level III

  • Technical background with system administration experience, architecture and engineering preferred.

  • Technical background in networking, identity management, Microsoft and Linux operating systems, database, and mobility.

  • Must have excellent communications skill (written and oral) and interpersonal skills.

  • Knowledge of the Telos Xacta or Enterprise Mission Assurance Support Services (eMASS) system is desired.

  • Must have a working knowledge and understanding of Microsoft Active Directory, Microsoft Exchange, Windows Server 2016 and higher, and understanding of networking.

  • Must have broad knowledge of Mobile Device Management (MDM) technology, as well as, BlackBerry, iOS, Windows Mobile, and Android operating systems and devices.

  • Knowledge and experience with DOD IA processes and policies (e.g., DODI 8510.01, NIST, CNSS and other cybersecurity policies); and Working knowledge of the Risk Management Framework (RMF).

  • Experience with the US Combatant Commands (USCENTCOM/USSOCOM) is desired.

ID: 2022-3405

External Company Name: Technical and Management Resources, Inc.

External Company URL: www.tmrhq.com

Street: Peterson AFB