Remotery

Cybersecurity Assessment and Authorization SME

atElectrosoftRemoteUS flagUnited StatesFull-timeCybersecurity / Security EngineerMid-levelSenior$115k – $125k/year

Posted Jul 27

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as a Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert, assisting with enterprise Risk Management Framework (RMF) initiatives across customer Information Systems, Cloud Hosted Services, Operational Technology (OT), Platform Information Technology (PIT), Facility Related Control Systems (FRCS), and hybrid computing environments.

• Oversee and contribute to all stages of the RMF lifecycle, including system categorization, security control selection, implementation, assessment, authorization, and ongoing monitoring.

• Create, review, update, and sustain RMF documents such as System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Continuous Monitoring Strategies, Privacy Impact Assessments (PIAs), Risk Assessment Memorandums (RAMs), Authorizing Official Risk Acceptance (AORA) documentation, and authorization packages.

• Evaluate and verify security controls in alignment with DoDI 8510.01, NIST SP 800-53, DLA RMF guidance, and relevant Federal and DoD cybersecurity standards.

• Execute security control assessments, vulnerability analyses, and compliance reviews to gauge the effectiveness of deployed cybersecurity measures.

• Assist in authorization decisions by identifying residual risks, analyzing compensating controls, and offering technical recommendations to Security Control Assessors (SCAs), Authorizing Officials (AOs), and senior Government leaders.

• Conduct cybersecurity evaluations supporting enterprise IT infrastructure, Cloud environments, Operational Technology (OT), Facility Related Control Systems (FRCS), warehouse execution systems, and Platform IT (PIT) environments.

• Aid in the implementation and validation of Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Assured Compliance Assessment Solution (ACAS) scans, IAVA compliance, vulnerability remediation, and ongoing monitoring activities.

• Use eMASS to manage authorization packages, track security control implementation, document vulnerabilities, and uphold authorization status throughout the system lifecycle.

• Collaborate on remediation efforts with ISSMs, System Owners, engineers, Information Owners, Program Managers, and Government stakeholders to address cybersecurity findings and maintain authorization.

• Support cybersecurity inspections, audits, compliance assessments, incident response activities, and investigations related to potential cybersecurity incidents or unauthorized disclosures.

• Prepare executive-level presentations, technical reports, dashboards, and risk assessments that communicate authorization status, cybersecurity posture, and recommendations to Government leaders.

• Keep abreast of evolving cybersecurity threats, regulatory changes, and emerging technologies to ensure ongoing compliance and enhance enterprise cybersecurity posture.

• Offer technical mentorship and cybersecurity expertise to project teams while fostering continuous improvement, collaboration, and cybersecurity best practices.


⛳️ Requirements

• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a comparable technical field. Alternatively, four (4) additional years of relevant experience may substitute for the degree requirement.

• At least five (5) years of experience in supporting Cybersecurity Assessment & Authorization (A&A), Certification & Accreditation (C&A), or Risk Management Framework (RMF) activities within Department of Defense or Federal settings.

• Proven experience in implementing and applying the DoD Risk Management Framework (RMF) according to DoDI 8510.01 and NIST SP 800-53.

• Candidates must fulfill applicable DoD 8140 workforce qualification standards, including IAM Level III (or its successor), as mandated by the contract.

• Security Clearance Level: Must possess a SECRET Clearance and be able to obtain or currently have IT-II Non-Critical Sensitive security clearance or Tier 3 (T3).

• Experience in assessing security controls and performing authorization activities for large, intricate enterprise environments involving multiple systems, enclaves, applications, and infrastructure components.


🏝️ Benefits

• Meaningful work

• Growth opportunities

• Work-life balance

People also viewed

ASG Technologies7 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike7 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International8 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape8 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity9 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist11 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers