WANT TO BE AFFORDED THE OPPORTUNITY TO TRAVEL THE WORLD AND VISIT SOME EXCITING LOCATIONS? WE'RE SEEKING A CYBER PROFESSIONAL WHO IS WILLING TO TRAVEL TO VARIOUS CONUS AND OCONUS CUSTOMER LOCATIONS TO ASSESS SECURITY CONTROLS ON SYSTEMS!
PRINCIPAL DUTIES AND RESPONSIBILITIES (*ESSENTIAL FUNCTIONS)
- Will perform activities related to the CCDC Security Control Assessor-Validator (SCA-V) of the Security Control Assessor-Army (SCA-A) and DoD organizations
- Conduct Risk Management Framework (RMF) assessments for enclaves and major applications throughout the Army and DoD.
- Conduct comprehensive pre-visit teleconferences
- Test and assess all applicable Risk Management Framework (RMF) security controls and control correlation identifiers (CCIs)
- Annotate assessment procedure (AP) test results (TR) for the system being assessed in the Enterprise Mission Assurance Support Service (eMASS)
- Conduct post-visit analysis, verify and review Risk Management Framework (RMF) documentation of all controls and assessment procedures (AP)
- Review and analyze findings (e.g. false positives, risk assessment, etc.) discovered during technical testing using DISA Security Technical Implementation Guides (STIGs)
- Conduct a post-analysis teleconference to explain any unresolved issues identified while onsite
- Engage with the system owner’s team to create final deliverables including RMF security assessment reports, risk assessment reports, briefing slides, detailed finding reports, and official memorandum
- 50% travel
_At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our “Family of Professionals!” Learn about our employee-centric culture and benefits here. _
Required Skills
Required Experience
REQUIRED QUALIFICATIONS
- Bachelor’s degree in related field or equivalent experience, advanced degree preferred.
- Minimum of 2+ plus years of work related experience
- Must be willing and able to travel 50% (OCONUS and CONUS)
- Minimum of a Secret clearance required
- Minimum of IAT III, IAM II, or IASAE I required
PREFERRED QUALIFICATIONS
- Active CISSP certification
- Experience working with Risk Management Framework (RMF) Controls and the Enterprise Mission Assurance Support Service (eMASS) preferred
- Experience working with DISA Security Technical Implementation Guides (STIGs) and Security Requirement Guides (SRGs) preferred