Job Description
Senior Systems Analyst
Minimum Requirements:
- Bachelor's Degree
- Seven or more years of experience providing program management support within a C4I program management office.
- Ability to maintain an active security clearance.
- Expertise using Microsoft Office suite of applications.
- Excellent oral, written, and critical thinking skills.
- Ability to work independently and as a team member.
- Ability to self-start and multitask in a fast-paced environment and prioritize multiple tasks with minimal supervision.
Key Roles and Responsibilities:
ยท Provide cybersecurity engineering support for systems/programs in the production phase for PMW 750/760 resulting in the successful accomplishment of mission requirements.
ยท Provide cybersecurity engineering support to systems/programs in the production phase to address accreditation requirements for P-8A Fleet Releases and TacMobile Technical Refreshes.
Conduct Cybersecurity RMF A&A activities. This requirement will support the Government to satisfy DoD cybersecurity requirements such as CYBERSAFE and CCA compliance. The Contractor will be required to provide staff at the TS/SCI level or Secret level, depending on the testing, integration and/or operational environment. Examples of support functions include the following, which may require access to SCI material to fulfill the Government's requirements:
ยท Collaborate with stakeholders such as the PMO and ISEA cyber personnel to obtain and sustain PMO PoR or supported accreditations
ยท Support the implementation and sustainment of the RMF in accordance with the RMF Process Guide and other DoD/DoN cyber directives. Examples of support functions include the following:
o Prepare, review, and submit RMF A&A documentation to approving authorities (i.e. NIWC PAC 5.8 and NAVWAR cybersecurity representatives and NAO office) via the PMW 750/760 Cyber APM / ISSM to obtain an ATO authorization
o Upload documents into the eMASS database
ยท Prepare A&A documentation by performing security scans, analyzing, and recommending solutions, mitigating vulnerabilities by applying updates, remedies, and patches using the STIG and IAV
ยท Routinely track the system or information environment for security-related events and configuration changes that negatively affect security posture
ยท Report adverse changes in the security posture of systems and propose mitigations immediately to the SCA and AO
ยท Provide technical comments, questions, and recommendations for a reassessment of any or all security controls to the SCA or AO as necessary
ยท Validate cybersecurity tests results to ensure compliance prior to submitting them to the PSO, SCA, and AO for review and approval
ยท Validate activities and controls are enacted to secure information
ยท Analyze and review gaps in security and propose solutions to mitigate risks in technical and business processes
ยท Support the identification and implementation of the security control baseline set and any applicable overlays
ยท Assess the quality of security control implementation against requirements
ยท Coordinate security control validation with the ISSM, SCA Liaison, PSO, and AO
ยท Support the management of schedule entries to ensure vulnerabilities are accurately tracked, mitigated, and resolved in accordance with deadlines
ยท Report missed deadlines to the AO
ยท Conduct cybersecurity testing including the use of ACAS
ยท Record security controls
ยท Record security control compliance status during the continuous monitoring phase of the lifecycle. This includes performing annual security reviews, testing of cybersecurity controls, and testing of the contingency plan to maintain FISMA compliance
ยท Manage and address trouble calls
ยท Register systems in the designated government tool (e.g. eMASS, VRAM, DITPR - DON/DADMS)
ยท Provide support for cyber-related inspections
ยท Comply with requirements such as TASKORDs, CTOs, and IAVM. This requirement involves:
o Conducting weekly applicability reviews and newly released IAVs
o Collaborating with stakeholders (e.g. engineers) to test and release patches for IAVs
o Updating the VRAM database weekly for vulnerabilities.
ยท Support the mitigation and closure of vulnerabilities under the system's change control process
ยท Prepare cybersecurity strategy documentation compliant with DoD CS policies and regulations including the RMF process
ยท Prepare SSAAs with associated appendices
ยท Provide technical comments, questions, and recommendations to categorize systems and implement RMF security controls
ยท Support cybersecurity program requirements to meet Test and Evaluation and RMF accreditation requirements for current and future PMO supported systems
ยท Provide technical comments, questions, and recommendations to address risks related to cybersecurity
ยท Present results to the stakeholders such as the NAVSEA Echelon II and AO Team to obtain approval and signature for SARs and Security Authorization Packages, to include IATTs and ATOs
ยท Analyze and review proposed changes to the fielded hardware and software systems to determine impacts on system cybersecurity accreditation for in-service systems and increments
ยท Conduct analyses such as trend analyses to support cybersecurity efforts; and
ยท Conduct cyber analysis on TacMobile Inc. 3 SCI subsystems in the production phase.
ยท Support POR (e.g. TacMobile) development
ยท Conduct Help Desk analyses for SCI systems (TacMobile Inc. 3).
Job Type: Full-time
Pay: $130,000.00 - $150,000.00 per year
Benefits:
โข 401(k)
โข 401(k) matching
โข Dental insurance
โข Health insurance
โข Life insurance
โข Paid time off
โข Referral program
โข Retirement plan
โข Vision insurance
Education:
โข Bachelor's (Required)
Experience:
โข Cybersecurity: 7 years (Required)
โข Project management: 5 years (Required)
โข Microsoft Office: 7 years (Required)
Location:
โข San Diego, CA 92110 (Required)
Security clearance:
โข Secret (Required)
Ability to Commute:
โข San Diego, CA 92110 (Required)
Willingness to travel:
โข 25% (Preferred)
Work Location: In person