
Cyber Security Specialist
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Virginia.
• Oversee, guide, and support Cyber Security initiatives for the GCSS-MC Program Management Office.
• Manage assessment and authorization processes related to STIG testing and Risk Management Framework (RMF) requirements.
• Create Plans of Action and Milestones (POA&Ms) to address system deficiencies.
• Evaluate adherence to NIST 800-53 Rev. 5 controls and assist with GCSS-MC Assess & Authorize documentation.
• Conduct assessments, compliance checks, and validations for IT systems and development environments.
• Provide the PMO with insights on system risks, mitigation strategies, and operational guidance.
• Execute security evaluations and vulnerability assessments using ACAS, Nessus, and SCAP tools.
• Determine relevant STIGs and carry out both automated and manual STIG assessments.
• Collaborate with network, application, and system administrators to rectify deficiencies.
• Analyze new systems and applications for security issues, drafting eMASS and OPDIR POAMs as necessary.
• Ensure compliance with DISA STIG standards for systems and applications.
• Counsel stakeholders on the implementation of cybersecurity requirements.
• Offer subject matter expertise on DoD and Marine Corps RMF while supporting RMF program execution.
• Develop and maintain comprehensive documentation for networks, cloud environments, information systems, and technologies.
• Conduct risk and vulnerability assessments for authorization purposes and prepare Security POAMs.
• Monitor and report on compliance with cybersecurity regulations and directives to the Cyber PMO.
• Maintain accreditation notification timelines, including 30-, 60-, and 90-day alerts.
• Create and uphold an Information Security Continuous Monitoring Plan.
• Identify, evaluate, and advise on compliance with cybersecurity controls and associated risks.
• Coordinate security matters, A&A, connection approvals, change requests, and waiver applications.
• Perform assessments of network, cloud, information systems, hardware, software, and devices for security purposes.
• Confirm system patching and scanning outcomes, develop POA&Ms, and report in accordance with established policies and regulations.
• Provide expert guidance on cybersecurity mitigation strategies.
• Design and implement processes, procedures, and capabilities aimed at reducing software and hardware vulnerabilities.
• Validate security measures and key performance indicators.
• Analyze the cybersecurity posture and furnish reports to the Cyber PMO and stakeholders.
• Lead small technical teams of up to five analysts in developing automation for ACAS, STIG, and control analysis processes.
• Conduct root-cause analyses and assist in corrective actions for cybersecurity incidents.
• Work in collaboration with the USMC Cyber Operations Group during penetration tests and vulnerability assessments.
• Bachelor’s degree in Cyber Security, Information Technology, or Computer Science.
• Minimum of 3–5 years of ISSO experience in support of US Marine Corps or DoD programs.
• More than 5 years of experience with the Risk Management Framework (RMF).
• Over 5 years of experience utilizing ACAS/Tenable Nessus Vulnerability Scanner.
• At least 5 years of experience with vulnerability and compliance assessment scanning tools and reporting.
• 5+ years of experience with US government security policies, including NIST 800-53 Rev. 4/5 and NIST 800-171.
• Familiarity with DODI 8500.01 and DODI 8510.01.
• Security+ certification is mandatory.
• Experience navigating all RMF steps and executing them in a challenging USMC environment.
• Ability to apply security concepts from FedRAMP, FISMA, NIST, CNSSI, and Oracle Cloud IL4/IL5.
• Background in developing cybersecurity automation or scripting for vulnerability management and compliance processes.
• Proficient experience with USMC cybersecurity procedures and DoD-specific monitoring tools.
• Experience with cloud environments such as Splunk, AWS, OCI, or Azure.
• Background working in Agile environments.
• Strong verbal and written communication skills.
• Capability to lead small technical teams of up to five analysts.
• Experience in conducting root-cause analysis and aiding in corrective actions for cybersecurity incidents.
• Understanding of the contractor’s role in supporting government clients.
• Familiarity with MC eMASS workflows, non-networked connected systems, or AI-enabled cybersecurity capabilities is advantageous.
• Flexible time off benefit.
• Comprehensive learning resources.
• Opportunities for learning and development.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Time off benefits.
• Flexible work arrangements to support work-life balance.
• Competitive compensation.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.