PLEASE NOTE:
- IT IS 100 % ON SITE POSITION in Santa Rita
- Clearance: Active Tier 5 (T5) Top Secret security clearance
- Must be a United States citizen.
- Must maintain a Privately Owned Vehicle
- Primary Work Location: NAVFAC Marianas, Building 3190, Naval Base Guam (NBG), Santa Rita, Guam 96915
- Secondary Sites: Marine Corps Base Camp Blaz (MCBCB), Andersen Air Force Base (AAFB), Guam
- Employment Terms: Full-Time (40 hours/week, standard business hours; 100% in-person; remote telework not authorized)
POSITION OVERVIEW
The Information Systems Security Engineer (ISSE) provides critical cybersecurity engineering and Risk
Management Framework (RMF) execution services for the Naval Facilities Engineering Systems Command
(NAVFAC) Marianas CIO. Operating in a specialized Operational Technology (OT) and Facility-Related Control
Systems (FRCS) environment, the ISSE plays an essential role in driving end-to-end RMF lifecycles, maintaining
Authorities to Operate (ATOs), managing vulnerabilities, and safeguarding mission-critical physical
infrastructure networks across military installations in Guam.
â
KEY RESPONSIBILITIES & ESSENTIAL TASKS
1. RMF Lifecycle Execution & ATO Maintenance
- Drive end-to-end Risk Management Framework (RMF) lifecycle execution (Steps 1â6) in strict
alignment with DoN and NAVFAC Echelon II directives.
- Format, verify, and upload system inventories, security controls, and compliance artifacts into the
Enterprise Mission Assurance Support Service (eMASS).
- Facilitate annual security reviews and author Memorandums for Record (MFRs) for system baseline
modifications to attain and maintain Authorities to Operate (ATOs) for FRCS assets.
2. Vulnerability Management & Compliance Assessments
- Develop and execute an overarching Vulnerability Management Strategy tailored to the FRCS
operational environment.
- Conduct automated scanning and compliance checks using DoN-approved tools (e.g., ACAS/Nessus,
SCAP, Evaluate STIG).
- Perform manual STIG and Security Requirements Guide (SRG) validations (.ckl / .cklb files), generate
Security Center and eMASSter reports, and upload scan results to the Vulnerability Remediation Asset
Management (VRAM) database.
3. Continuous Monitoring & Configuration Management
- Sustain System-Level Continuous Monitoring (SLCM) by analyzing audit logs, driving vulnerability
mitigations, and updating quarterly Plan of Action and Milestones (POA&M) reports.
- Serve as a technical representative and Configuration Management (CM) Officer on the Configuration
Control Board (CCB), providing authoritative security impact analyses and risk assessments.
4. On-Site Validation, Incident Response & Operational Coordination
- Provide on-site technical testing and validation support to satisfy RMF Step 4 requirements in
coordination with independent validators.
- Serve as an operational member of the MAR Cyber Emergency Response Team (CERT), participating in
on-call rotation schedules and authoring After-Action Incident Response (IR) reports.
- Provide bi-weekly RMF progress reports to the Information Systems Security Manager (ISSM) and update FRCS project records in Maximo and/or eProjects.
Requirements
REQUIREMENTS & SKILL SETS
Experience & SME Qualifications
- General RMF Experience: Recommended minimum of 5 years of hands-on Risk Management
Framework (RMF) experience.
- FRCS Specialization: Minimum of 1 year of specialized experience working on Facility-Related Control
Systems (FRCS) performing RMF and cybersecurity engineering tasks.
- Independent Execution: Demonstrated ability to operate independently with minimal government
supervision. - Formal Degree: A formal college degree
DoD Cyberspace Workforce (CWF) Certification (DoDM 8140.03 WRC 461)
Must possess at least one (1) active baseline commercial certification satisfying Work Role Code 461 (Systems
Security Analyst) prior to onboarding:
- Intermediate Level (Minimum): Security+, CCSP, Cloud+, GICSP, GISF, or GSEC.
- Advanced Level (Automatically Qualifies): CISSP-ISSEP, CYSA+, RCCE Level 1, CISSO, FITSP-O, GCLD, GCSA, or GSNA.
- Requirement: Complete a minimum of 20 hours annually of Continuous Professional Development (CPD) to keep credentials active.
Technical Tools & Environment Knowledge
- Platforms & Databases: eMASS, VRAM, eMASSter, Maximo, eProjects.
- Scanning & Analysis Tools: ACAS (Nessus), SCAP Compliant Scanners, Evaluate STIG, .ckl/.cklb STIG Viewer checklists.
- Frameworks & Standards: NIST SP 800-53 control families, NIST SP 800-82 (ICS/OT), DoN/NAVFAC Echelon II business rules, SRGs/STIGs.
Physical Requirements & Local Transportation
- Capable of physical exertion typical of industrial and FRCS sites: long periods of standing, walking over rough/uneven surfaces, bending, crouching, climbing ladders, and lifting IT equipment up to 25 lbs.
- Must maintain a Privately Owned Vehicle (POV) or company vehicle for required local commuting between sites across Guam (expenses are non-reimbursable as a cost of doing business).