Cybersecurity Assessment & Authorization (A&A) Engineer Analyst

KBR Inc

North Charleston, SC

JOB DETAILS
SKILLS
Analysis Skills, Applications Security, Asset Management, CISSP - Certified Information Systems Security Professional, Change Control, Communication Skills, CompTIA Security+, Database Technology, Defense Information Systems Agency (DISA), DoD Directive 8140, DoD Directive 8570, Documentation, Electronic Warfare, Information Technology & Information Systems, Information/Data Security (InfoSec), Internet Security, Microsoft Excel, Microsoft SQL Server, Microsoft Visio, Microsoft Word, MySQL, Network Architecture/Engineering, Operating Systems, Oracle, Presentation/Verbal Skills, Project Planning, Rapid Prototyping, Research & Development (R&D), Risk Analysis, Risk Management Framework (RMF), SSCP - Systems Security Certified Practitioner, Secret Clearance, Security Analysis, Security Clearance, Single Scope Background Investigation (SSBI), Systems Administration/Management, Systems Analysis, Team Player, Technical Strategy, Technical Writing, Test Requirements, Time Management, United States Department of Defense (DoD), Writing Skills
LOCATION
North Charleston, SC
POSTED
23 days ago

Title:

Cybersecurity Assessment & Authorization (A&A) Engineer Analyst

Program Summary:

KBR's Product and Technology Solutions Division specializes in rapid prototyping and advanced technology solutions for directed energy, electronic warfare, and security applications. With expertise in electronic warfare systems, critical infrastructure protection, and product R&D, KBR delivers cutting-edge innovations to meet mission-critical needs. Backed by a global presence and a strong ethical framework, KBR collaborates closely with customers to develop secure, effective, and forward-thinking solutions.

Job Summary:

The candidate plays a critical role in the assessment and authorization of existing or new systems. One of the primary responsibilities of this position will be to collaborate with system administrators in assessing the security posture of systems assigned to the candidate throughout the risk management framework (RMF) lifecycle (accreditations, annual reviews, risk assessments, and continuous monitoring activities). The candidate will be essential in interacting with all team members to ensure a comprehensive accreditation package is maintained. This position will require a high degree of self-motivation and organization.

Roles and Responsibilities:

  • Perform self-assessments utilizing all applicable tools (ACAS, SCAP, STIGs, SRGs) for technology area assigned (Requires SSBI/T5)
  • Interact/collaborate with system owner on remediation activities
  • Provide support to system owner on STIG/SRG requirements
  • Develop POA&Ms (reason system cannot be remediated, mitigation statements, milestones)
  • Work in eMASS (upload self-assessment results, manage assets, create/edit POA&Ms
  • Respond to CCB requests for assigned technology area (review requests, assign security testing requirements, document final findings)
  • Collaborate to create and maintain authorization documentation
  • Provide weekly activity report

Basic Qualifications:

Minimum Security Clearance: Active Secret required. Completed SSBI/T5 investigation (preferred and required to fulfill complete duties)

Certifications: DoD or DoN Cybersecurity Workforce (CSWF) Certification or compliance (DoDD 8140 or SECNAV M-5239)

  • Certifications: DoD 8570 Education and Training certification
  • DoD Training: Approved DoD Training Courses
  • SSCP/CISSP (Highly desirable)

Education/Experience:

  • BS degree preferred and 8 years of hands-on experience in Information Technology/Information Assurance. In lieu of degree, 16 years of hands-on experience in Information Technology/Information Assurance.
  • Must possess a CompTIA Security + to start work
  • OS Certification/Approved Training completed within 180 days of hire

Travel: 10-15%

Preferred Qualifications:

  • Ability to work in a team and independently
  • Excellent communication skills (verbal and written)
  • Excellent project planning and time management skills
  • Experience with Word/Excel/Visio
  • Global thinker/analyzer with the ability to assimilate a number of inputs into a cohesive output/strategy
  • Well versed in Networking products/technologies
  • Working knowledge of Database products/technologies such as: MSSQL, MySQL, Oracle
  • Experience with all applicable DISA STIGs associated with listed technologies in preceding bullet
  • Able to work with network engineers and system administrators to provide sound advice on technologies from a STIG perspective

Experience with RMF package development:

  • Excellent technical writing skills and RMF control knowledge (must be able to technically document assigned area of responsibility as it relates to meeting the requirements of the control)
  • Experience with developing POA&Ms (must be able to technically document mitigation strategies and milestones for findings associated with assigned area of responsibility)
  • Experience with PPSM (must be able to utilize available information [ACAS scans, CCB forms, etc.] to evaluate and determine appropriateness of required ports/protocols/services for systems assigned)
  • Experience with eMASS (must be able to utilize all functions of eMASS including: uploading test results, handling false positives, POA&M creation/management, control review/testing)
  • Experience with ACAS (must be able to create/run/review scans, download and import to eMASS, create, and run reports)

Belong, Connect and Grow at KBR

At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

About the Company

K

KBR Inc

When you become part of the When you become part of the KBR team, your opportunities are endless. As a leading global technology, engineering, procurement and construction company serving the hydrocarbons and government services industries. For decades it has been the company that customers turn to for their most challenging assignments.

With operations in 40 countries, KBR has more than 25,000 people delivering services to customers in over 70 countries. Together they represent an unmatched reservoir of talent and experience in a wide range of markets.

Whatever the assignment, no matter how complex or demanding, KBR can marshal resources across every product line to respond quickly and effectively to changing markets and customer needs.

Whether it's providing the technology and consulting know-how to develop our customers' valuable assets; designing and constructing the infrastructure and facilities to develop energy resources in some of the world's more remote and challenging locations; providing support and services for men and women of their countries' armed forces; or navigating the intricacies of undertaking major projects in geopolitically or culturally sensitive environments, our clients depend on KBR because they know that We Deliver.

Join us and you'll be part of a dynamic, elite team of professionals who understand what it takes to get a job done and has the experience, knowledge and determination to succeed.”

COMPANY SIZE
10,000 employees or more
INDUSTRY
Construction - Industrial Facilities and Infrastructure
FOUNDED
1998
WEBSITE
https://www.kbr.com/en