Employee Type: Full-Time
Location: Suffolk, VA
Job Type: Analysis
Experience: 3+ Years
AERMOR is seeking a Junior Information System Security Engineer (ISSE) to help support the development, delivery, and sustainment of the Risk Management Framework (RMF) life cycle, ensuring systems are properly assessed and receive/maintain authorization in the N68 Division of Navy Cyber Defense Operations Command (NCDOC).
- Creates, reviews, updates, and validates Cybersecurity Standard Operations Procedures (SOPs) as required.
- Reviews and maintains an inventory of all divisional authorized software (software custodian).
- Reviews and maintains an inventory of all divisional devices and media.
- Maintain and update all Risk Management Framework (RMF) and C&A documentation to ensure the relevancy and currency of NCDOC and Navy Red Team assets to include required revisions and updates for ISSO’s to input into eMASS. If there are discrepancies, communication must be taken to the stakeholders.
- Assist with annual RMF package reviews to ensure continued compliance of the Navy Red Team tool suite and/or Networks.
- Ensure traceability is maintained throughout the RMF submission process (e.g.: C&A Plan, POAM, RAR, Topology, Software, Ports Protocols and Services, Test Plan).
- Maintain documentation and registration of Network Ports, Protocols, and Services.
- Assist with updating RFC’s (Request for Change) status notes with progress, and all updates made to the master RMF documentation. Once updates are completed, the ISSE Lead will close out the RMF Update portions, and in some cases close out the entire RFC.
- Work closely with the Lead ISSE to ensure all RMF documentation is up-to-date with RFC status/workflow.
- Support compliance validation of current and future directives (e.g.: IAVs, STIGs, CTOs).
- Provide security expertise to ensure security controls are implemented and the resulting documentation and artifacts are current.
- Update meeting notes/slides for weekly meetings for the Change Management Board, or others as needed/requested.
- Assist in designing/compiling information for SOP’s (Standard Operating Procedures) or guidelines for RFC workflows
- Produce test plans, draft after actions, and other documents for review and comments.
- Assist with exercise and/or training and documentation of IT contingency plan and execution.
Required Skills and Experience:
- CompTIA Security+ CE certification.
- 1- 3 years of experience with Assured Compliance Assessment System (ACAS) and/or Nessus.
- 1- 3 years Certification and Accreditation (C&A) package assembly experience.
For more information contact: email@example.com
As an Equal Opportunity Employer, AERMOR LLC complies with government regulations and affirmative action responsibilities.
AERMOR LLC does not discriminate against any applicant for employment or employee because of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristic prohibited under Federal, State, or local laws.