Cybersecurity Administrator
Virginia Beach, VA - USA
Job Summary
Job Title: Cybersecurity Administrator
Job Location: Virginia Beach VA
Job Category: Information Technology/Systems
Job Status: Full Time
Salary Range: $40 - $55/hr
Job Description:
The Cybersecurity Administrator is responsible for implementing and maintaining the security controls required for CMMC (Cybersecurity Maturity Model Certification) Level 2 across the enterprise in accordance with NIST SP 800-171 Protecting Controlled Unclassified Information. The administrator will maintain and improve the organizations System Security Plan (SSP) and Plan of Action and Milestones (POA&M) support assessment readiness with the companys C3PAO and DIBCAC and help sustain the security of Controlled Unclassified Information (CUI).
The Cybersecurity Administrator shall have experience with boundary defense techniques commercial off-the-shelf (COTS) security products and cloud services used to meet the enterprises system security objectives.
Duties and Responsibilities:
- Plan develop implement test and document security controls to meet CMMC Level 2 (NIST SP 800-171) requirements
- Develop and enforce information security policy
- Perform IT risk and security assessments and support risk mitigation efforts
- Assess flow-down of DFARS requirements to subcontractors and support vendor/supply-chain risk reviews
- Develop approaches to mitigate vulnerabilities and recommend changes to systems or components as needed
- Facilitate an IT business continuity plan
- Perform internal security control assessments and self-assessments including SPRS scoring support
- Identify information protection needs for the computing and network environments
- Develop maintain and analyze the System Security Plan (SSP) and associated cybersecurity risk analysis
- Advise network system and software engineers on the results of cybersecurity risk analysis
- Execute and support network security initiatives
- Conduct vulnerability scanning
- Ensure patch compliance
- Support incident response and remediation efforts
- Participate in assessment activities including interviews documentation requests and artifact requests
- Review responses and deliverables for accuracy and assist with interpreting assessment requests
- Review assessment findings and assist management in developing responses and remediation plans
- Create track and provide status updates on Plan of Action and Milestones (POA&M) items
- Develop update and maintain metric/KPI status reports on a defined schedule for IT initiatives
- Respond to requests for clarification and information
- Oversee and provide technical guidance to Cybersecurity Analysts
Job Requirements / Skillsets:
- Experience implementing controls to meet NIST SP 800-171 requirements
- Experience designing and maintaining a System Security Plan (SSP)
- Experience performing security audits with and without specialized SIEM tools
- Experience certifying or validating compliance of information systems
- Current certification compatible with IAT Level III in accordance with DoD 8140 (formerly DoD 8570.01-M) or the ability to obtain one within six months of hire
- Comprehensive understanding of computer security and the ability to communicate clearly and succinctly in written and oral presentations
- Working knowledge of a vulnerability management system
- Experience utilizing MS Purview and Data Loss Prevention (DLP) policies
- Experience securing cloud-based security controls
Job Preferences:
- Current ISC2 CISSP certification
- Experience developing and testing an Incident Response Plan
- Mobile Device Management (MDM) administration
- Experience with network administration
- Experience with system administration
- Experience implementing or managing FedRAMP-authorized vendor products (e.g. GCC High)
- Experience in a classified environment
Education:
Bachelors degree in computer science Information Technology Computer Information Systems or a related field and 5 years of experience in the field or a related area; or a Masters degree in a related field and 2 years of experience in the field or a related area. Active industry cybersecurity certifications (ISC2 CompTIA Cisco Microsoft) may substitute for some years of experience depending on the certification.
Security Clearance:
Requires U.S. citizenship and the ability to obtain a DoD Secret clearance.
Benefits:
Q.E.D. offers competitive benefits such as: Paid Leave Medical Dental Vision Short/Long-Term Disability 401(k) retirement plan Basic Life Insurance supplemental insurance and an Employee Assistance Program.
To Apply:
Email resume to Julio Valdez at .
EOE including disability/vets
Required Experience:
Unclear Seniority