Information Assurance Compliance Specialist

Athena Technology Group
Philadelphia, PA, United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Configuration Management Cyber Security Networking Hardware Intrusion Detection and Prevention Security Information and Event Management Software Vulnerability Management Firewalls (Computer Science) Web Content Navsea Plan of Action and Milestones Vulnerability Analysis

Job description

We are seeking an Information Assurance Compliance Specialist to join our team. You will play a key part in ATG’s technical support for Naval Surface Warfare Center Philadelphia Division (NSWCPD) specializing in cybersecurity support, validation support, IT and cyber policy writing and program implementation support. Our team will provide direct support for cybersecurity policy, A&A artifacts, validation, and security posture reviews., * Support evaluation and documentation in eMASS to include the security posture of the system or site being Assessed, Authorized, and maintained.

  • Develop, submit, and maintain RMF packages in accordance with DoD Instruction 8510.01, NAVSEA Business Rules, DON RMF Process Guides, NAVSEA Standard Operating Procedures (SOPs), and the business rules of cognizant review offices.

  • Support development the RMF package documentation required for submission in accordance with DoD/NAVSEA directives. Documents may include but are not limited too HW/SW Lists, Authorization Boundary Diagrams, Privacy Impact Assessment (PIA), etc.

  • Develop or revise existing policies, plans, and strategy documents to meet requirements for RMF Control Families and ensure all IA requirements have been addressed.

  • Conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs.

  • Conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor’s (SCA) and higher level review.

  • Execute Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems.

  • Develop and maintain in eMASS a Plan of Action and Milestone (POA&M) for all IA-related tasks and deliverables.

  • Conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system.

  • Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS).

  • Assess impacts from observed risks and report via the Cybersecurity Program chain of command.

  • Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities.

  • Perform the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution.

  • Present and submit data to management, develop reports, and produce procedural documentation in a comprehensive and cohesive manner.

  • Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance.

  • Determine a system’s compliance with all applicable Controls and Assessment Procedures (APs) for an assigned DoN system, including developing the appropriate test procedures, if necessary; executing the test procedures; and accurately documenting the results of security testing.

  • Maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM).

  • Manage, attend, and support configuration control board practices, as needed.

  • Ensure RMF artifacts are in compliance with published Navy, NAVSEA Business Rules (OPNAV N2N6 and/or NAVSEA), NIST SP-800-37 and SP-800-53 Rev 4.

  • Create and verify the accuracy of POA&Ms/RARs as identified by vulnerability actual test results

Requirements

Required:

  • Active Secret clearance (eligible to obtain and maintain a TS clearance)

  • Masters’s degree from an accredited college or university (7 years of experience can substitute for a degree).

  • 5+ years of professional experience in Information Assurance Compliance.

  • CISSP or CISM or GSLC or CASP certification

  • Experience in eMASS

Desired:

  • Previous Experience in NAVY cyber security environments

  • 2 years experieince in RMF

Benefits & conditions

  • Performance Bonuses and annual salary reviews

  • Health, dental, and vision insurance

  • Short Term Disability, Long Term Disability, and Life Insurance

  • 401(k) plan with company match

  • Opportunities for professional growth and development

  • A collaborative and inclusive work environment

About the company

Athena Technology Group, Inc. (ATG) is a Service-Disabled Veteran Owned Small Business (SDVOSB) and Historically Underutilized Business Zone (HUBZone) established in 2010. ATG has immense experience and a strong, solid reputation throughout various government agencies, providing consistently superior, innovative, and cost-effective solutions. ATG is a premier provider of cybersecurity, risk management framework (RMF), and communications cybersecurity solutions, as well as information technology (IT) and communications consulting, system engineering, integration, deployment and operation of state-of-the-art command and control and information systems that deliver critical network centric solution to the warfighter. We are looking for innovative industry professionals to join our team and continue our proven track record.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

9:02 min

Building enduring web content against algorithmic search paywalls

Chris Heilmann +2 · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:16 min

Implementing content permissions for large language web crawlers

Farooq Sheikh Farooq Sheikh +3 · World Congress 2025

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all