drjobs Senior IA Policy ComplianceRMF Lead

Senior IA Policy ComplianceRMF Lead

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Sierra Vista, AZ - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Responsibilities & Qualifications

RESPONSIBILITIES

  • Ensures compliance with current and emerging RMF requirements for all capabilities and services.
  • Risk Management Framework (RMF) is a DoDmandated process for all systems capabilities services network devices and emerging capabilities operating on the DoDIN.

  • Use established Government guidelines and reporting procedures.

  • Coordinate with the Government Lead on overall priorities and changes to Government processes and procedures.

  • Manage and maintain a valid current eMASS record for each system capability service or pilot identified in Specific Tasks and those identified by the Government as emerging requirements. eMASS records may be classified unclassified or both.

  • Utilize the RMF Knowledge Service policy and guidance in the accomplishment of all RMF tasks.

  • Develop and submit a System Security Plan for each new eMASS record or child record.

  • Apply all relevant control baselines and additional control overlays for each record.

  • Assign all baseline security controls and RMF overlay controls.

  • Assign inheritance per current DoD and Army continuous monitoring guidance.

  • Update and maintain the software and hardware list to reflect any changes for each system capability service or pilot.

  • Update and maintain RMF records per site location ensuring accurate hardware and software inventories ACAS scans and other unique site location data.

  • Update and maintain PPS/firewall documentation to reflect any changes for each system capability service or pilot.

  • Ensure monthly production security scans are completed for each system capability service or pilot and uploaded into the eMASS record.

  • Ensure STIGs are routinely addressed at least quarterly and controls are implemented and updated within the eMASS record.

  • Update POA&Ms to reflect the results of the monthly security scans and STIG updates.

  • Ensure POA&M items accurately reflect strong corrective actions or mitigations that reduce the security threat to the DoDINA Army data and Army customers.

  • Verify that all remediation dates are achievable.

  • Publish the POA&M workflow IAW with Government processes and procedures.

  • Verify that applicable CTO POA&MS are saved into Artifacts that the vulnerability is addressed within the eMASS POA&M and that the POA&M workflow is released.

  • Verify that system documentation is signed reviewed on a yearly basis and uploaded into the eMASS record.

  • Complete the Annual Security Review and release the workflow.

  • Update and maintain all other actions and functions within the eMASS record.

  • Submit workflow for an ATO once all eMASS records actions are verified to be current and accurate; ensuring the workflow is complete and accurate and submitted 90 days prior to ATO expiration date.

  • Attend monthly RMF updates on each system capability service or pilot as conducted to meet ATO suspense dates and development of new system authorizations.

  • Responsible for performing and leading support of Certification and Accreditation (C&A) or other IA/CND Compliance and Auditing processes and inspections for all enterprise systems and networks

  • Ensures validity and accuracy review of all associated documentation.

  • Leads and performs compliance reviews of computer security plans performs risk assessments and validates and performs security test evaluations and audits.

  • Analyzes and defines security requirements for information protection for enterprise systems and networks.

  • Assists in the development of security policies.

  • Analyzes the sensitivity of information and performs vulnerability and risk assessments based on defined sensitivity and information flow.

REQUIRED QUALIFICATIONS

Additional Job Information

WORK ENVIRONMENT AND PHYSICAL DEMANDS

The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

PHYSICAL DEMANDS

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this job the employee is regularly required to use hands to handle feel touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop kneel crouch or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision distance vision peripheral vision depth perception and ability to adjust focus.

WORK AUTHORIZATION/SECURITY CLEARANCE

OTHER DUTIES

Please note this job description is not designed to cover or contain a comprehensive listing of activities duties or responsibilities that are required of the employee for this job. Duties responsibilities and activities may change at any time with or without notice.

EQUAL EMPLOYMENT OPPORTUNITY

In order to provide equal employment and advancement opportunities to all individuals employment decisions will be based on merit qualifications and abilities. TekSynap does not discriminate against any person because of race color creed religion sex sexual orientation gender identity protected veteran status national origin disability age genetic information or any other characteristic protected by law (referred to as protected status). This nondiscrimination policy extends to all terms conditions and privileges of employment as well as the use of all company facilities participation in all companysponsored activities and all employment actions such as promotions compensation benefits and termination of employment.

TekSynap is committed to ensuring that our online application process provides an equal employment opportunity to all job seekers including individuals with disabilities. If you believe you need a reasonable accommodation in order to search for a job opening or to submit an application please contactfor assistance.


Required Experience:

Senior IC

Employment Type

Full-Time

Department / Functional Area

Cybersecurity

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.