Cyber Security Logistics Specialist SME II supporting Defense Health Agency Risk Management Executive Division initiatives. Responsibilities include documenting security responsibilities and leading self-assessments in cybersecurity contexts.
Responsibilities
Reviews and updates the Detailed Architecture Diagram, Detailed Hardware/Software Inventory, and other system artifacts to determine the DoD IT type.
Develops the baseline set of impact values (low, moderate, or high) for the medical devices.
Identifies common controls associated with the inherited controls in the Security Plan.
Documents responsibilities associated with the inherited controls in the Security Plan.
Initiates the tailoring process in eMASS to modify the control set to account for conditions affecting the specific system more closely.
Adds relevant supplemental security controls and marks extraneous or impertinent controls as 'Not Applicable'.
Identifies security controls to be monitored on an ongoing basis.
Reviews site/organization change control policies.
Documents the method of applying policies to specific controls.
Coordinates with the IV&V Team to clarify information required for Special Access Programs.
Leads the execution of the self-assessment activities.
Completes applicable checklists in assessing the NIST SP 800-53 Revision 4 controls.
Documents upload self-assessment checklist results and artifacts documentation in eMASS.
Provides support with remediation and mitigation efforts.
Creates the Risk Assessment Report.
Coordinates with the ISSM to confirm the completion of the Security Authorization Package prior to eMASS submission.
Assists program leadership with status reports, white papers, weekly activity report, and other ad hoc requirements as necessary.
Performs other job-related duties as assigned
Requirements
Bachelor’s Degree in Information Technology or Cybersecurity, or an equivalent combination of education and experience in lieu of a degree.
8 years of experience.
Federal government contracting experience required.
Must possess a Security+ or other IAT Level I, II / IAM Level I, II certification.
Ability to maintain an Active DoD Secret clearance.
Director of Physical Security managing comprehensive corporate security strategies for a defense tech company. Leading physical security operations, ensuring safety across facilities and collaboration with international defense bodies.
Director of Physical Security building security function for Swarmer, a tech company developing autonomous drone software. Overseeing security measures and fostering a proactive security culture.
OT Cybersecurity Engineer tasked with maintaining security for Operational Technology environments. Evaluating incident response, monitoring solutions, and ensuring compliance in cybersecurity frameworks from SBM Offshore in Brazil.
Técnico de Segurança do Trabalho ensuring safety compliance in Brazil's leading sanitation company. Focused on operational safety, incident investigations, and team training.
IAM Transformational Analyst enhancing security functions at Truist. Focused on innovation, strategic planning, and alignment with overall banking capabilities.
Cybersecurity Analyst evaluating risks from third - party suppliers and SaaS platforms. Responsible for developing threat models and monitoring capabilities to reduce security threats.
Forward Deployed Engineer at Virtru enhancing data privacy and security initiatives within government environments. Leading integrations and deployments of data protection solutions with federal clients.
Forward Deployed Engineer enhancing operational excellence in data privacy and security initiatives for government clients. Involves collaboration with internal teams and daily engagement with government clients.
Senior Security Manager responsible for managing cybersecurity strategies and policies at a fast - growing FinTech company. Leading vulnerability management and collaborating effectively with cross - functional teams.
Infrastructure Security Engineer responsible for integrating security into infrastructure workflows and automating security measures. Collaborating with SRE teams to maintain a secure infrastructure posture.