Cybersecurity Engineer III

Mount Indie

  • San Diego, California
  • Today

    Highlights

    Adherence to the eMASS scheduled tasking within the accreditation cycle, including Quarterly Independent Verification and Validation (IV&V), quarterly STIG checks, Annual Security Review (ASR), monthly POA&M updates, and resubmission for ATO, ATC, IATC and IATT as applicable. · Conduct active and passive reconnaissance of data, with the ability to assess and author Plans of Milestones and Actions (POA&Ms) containing accurate and verifiable mitigation statements, milestone tracking, and applying to the most relevant security control.

    Numbers & Facts

    LocationSan Diego, California

    Description

    Mount Indie is seeking a Cybersecurity Engineer III to support the NIWC PAC Information Technology Management Support Services contract. The Cybersecurity Engineer III will be responsible for supporting Assessment and Authorization (A&A) accreditation efforts. This role maintains cybersecurity monitoring operations, performs triage to assess the scope and impact of incidents, identifies vulnerabilities, and recommends remediation strategies. The role requires in-depth knowledge of the Risk Management Framework.

     

    100% onsite

     

    Key Responsibilities:

    · Test and apply security controls based on security categorization, the application of overlays (privacy, classified, intel, etc.) and security control tailoring (AI, NOFORN, etc.).

    · Conduct active and passive reconnaissance of data, with the ability to assess and author Plans of Milestones and Actions (POA&Ms) containing accurate and verifiable mitigation statements, milestone tracking, and applying to the most relevant security control.

    · Development of comprehensive required A&A documentation, including System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Reports (SARs), etc.

    · Adherence to the eMASS scheduled tasking within the accreditation cycle, including Quarterly Independent Verification and Validation (IV&V), quarterly STIG checks, Annual Security Review (ASR), monthly POA&M updates, and resubmission for ATO, ATC, IATC and IATT as applicable.

    · Maintenance of DISA circuit connections (CCSDs), inheritance from accredited systems and cloud service providers, and the workflow schedule on accreditations.

     

    Requirements

    Clearance Level:

    Secret

     

    Certification IAM II

    One of the following:

    CAP

    CASP

    CISM

    CISSP (or Associate)

    GSLC 

     

    Required Qualifications:

    · 10+ years of experience in cybersecurity or incident response.

    · Certifications preferred: Certified Information Systems Security Professional (CISSP).

     

    Skills & Competencies:

    · Cybersecurity Monitoring and Incident Response

    · Security Testing, Auditing, and Remediation

    · Data Analytics and Risk Assessment

    · Proficiency with IT Security Software and Web Security Tools


    Similar Jobs

    See more jobs