Information Systems Security Officer managing RMF and security integration for CACI. Leading technical projects and mentoring junior engineers while ensuring compliance with cyber regulations.
Responsibilities
Manage Risk Management Framework (RMF) process
Work with system development team to identify needed RMF artifacts and load them into the government’s EMASS system.
Develop security plans, policies, and designs.
Configure and implement security solutions based upon the customer’s performance criteria and specifications
Conduct systems pre-test and acceptance tests to validate the designed performance criteria
Structure mock designs based upon RFP specifications in support of the Bids & Proposal teams
Collaborate with government and /or subcontractors at customer site for security solution integration into existing infrastructure
Develop and perform technical presentations for customers
Mentor junior engineers and technicians
Serve as technical lead on projects.
Travel to other CACI Locations or Customer Sites as necessary
Proactively ensure a safe work environment and adhere to CACI EH&S policies and procedures
Perform other duties as required
Requirements
A Bachelors degree is required.
Knowledge of risk assessment tools, technologies, and methods including EMASS system
Experience designing secure networks, systems, and application architectures
Experience planning, researching, and developing security policies, standards, and procedures
Ability to communicate network security issues to peers and customers
Working knowledge of current Cyber technologies and experience with NIST 800 Series and DoD 8570 regulations and governing DISA STIGs and/or SRGs
Understanding of Information Assurance Vulnerability Management (IAVM) and Information Assurance Vulnerability Assessments (IAVAs)
Prior experience with RMF controls, risk assessments, and POA&M generation
Strong working knowledge of Confidentiality, Integrity, and Availability (CIA) concepts, to include 2-factor authentication, Public Key encryption techniques, patch management, end-point security systems, intrusion detection, security event management and defense-in-depth.
Well versed in DoD cyber security Assessment and Authorizations (A&A) DoD Implementation, Directives, NIST Special Publications and other government cyber security standards, policies, and directives
Experience with Nessus, ACAS, SCAP
Experience completing and review DISA Security Technical Implementation Guides (STIGs)
Experience conducting risk analysis on products and system components through review of CVEs, plugins, IAVAs
Experience onboarding assets to centrally managed Enterprise solutions.
Application Security Architecture and Design experience
Security Compliance Operations and Application Security Assessment experience
DoD 8570.01 IAT level 2 or greater cyber security certification per DoD 8570.01 (such as Security+)
Experience designing and implementing Commercial Solutions for Classified (CSfC) Multi-Site Connectivity Capability Package desired
Systems integration experience
Excellent interpersonal and presentation skills
At least five years of continuous recent experience in the field of DoD information systems security and/or cybersecurity.
Possess an active Information Assurance Management (IAM) Level III certification.
Additional cyber and/or IT certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or CompTIA’s Advanced Security Practitioner (CASP)
Personnel Security Specialist leading intake operations at PSI. Focused on case coordination, quality assurance, and team training for security suitability tasks.
Security Coordinator overseeing supervision and training of security personnel for BronxWorks' homeless services programs. Ensuring compliance, safety, and coordination with social services directors in Bronx area.
Part - Time Security Officer safeguarding personnel and property at Kaman Air Vehicles. Providing access control, monitoring systems, and responding to incidents in Bloomfield, CT.
Security Officer responsible for maintaining a safe environment for clients and employees. Enforcing policies and responding to emergencies at the client's site.
Senior Security Advisor enhancing security measures to align with corporate objectives at Desjardins. Leading development of strategic initiatives and overseeing best practices in security.
Controls Professional assessing internal control frameworks at Barclays, improving control effectiveness and managing risks to ensure compliance with regulations.
Senior Information Security Engineer at Wells Fargo investigating insider threats and strengthening cybersecurity measures. Conducting advanced investigations and collaborating with cyber teams to mitigate risks.
Staff Product Manager overseeing enterprise security product strategy for Tenable. Collaborating with various teams to deliver customer - focused solutions and product features.
Program Security Representative providing multi - discipline security support for Special Access Programs. Ensuring compliance, developing policies, and conducting security assessments in a military context.
Information Systems Security Officer managing operational security posture for information systems at GDIT. Collaborating closely with ISSM and ISO, handling security aspects, and ensuring compliance with security standards.