Systems Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Position Overview We are seeking a Systems Security Analyst to support our client. You will help protect the confidentiality, integrity, and availability of Facility-Related Control Systems by leading security engineering, Risk Management Framework (RMF), vulnerability management, continuous monitoring, and incident response activities. This is a mission-essential, hands-on role for a security professional who can work independently, coordinate across technical and government stakeholders, and turn complex compliance requirements into operational results., Drive the end-to-end RMF lifecycle (Steps 1-6) in accordance with current Department of the Navy and NAVFAC Echelon II guidance; verify artifacts for completeness, quality, and compliance and maintain accurate eMASS packages. Achieve, maintain, and track Authorities to Operate (ATOs) for FRCS; support annual security reviews and prepare Memorandums for Record for approved baseline changes. Develop and maintain security policies, standard operating procedures, and implementation plans mapped to applicable NIST SP 800-53 control families and tailored to the FRCS environment. Execute vulnerability and compliance assessments using approved DoN tools such as ACAS, SCAP, and Evaluate STIG; complete manual STIG/SRG validations and maintain .ckl/.cklb checklists. Prepare Security Center and eMASSter reports for eMASS integration and ensure vulnerability results are accurately uploaded and maintained in VRAM. Sustain system-level continuous monitoring through recurring scans, audit-log analysis, remediation tracking, mitigation, and quarterly POA&M updates. Coordinate and support on-site RMF Step 4 validation, including evidence collection and collaboration with system owners and independent validators. Serve as a technical representative and/or Configuration Management Officer on the Configuration Control Board, providing security-impact analyses and risk assessments for proposed FRCS baseline changes. Support cyber incident response as a member of the MAR Cyber Emergency Response Team, including participation in an on-call rotation and preparation of operational logs and after-action reports. Provide bi-weekly RMF status reports to the ISSM, maintain project records in Maximo and/or eProjects, and contribute to monthly status reporting.
Requirements
Must be a US Citizen Must hold Secret Clearance Minimum of five years of RMF experience, including at least one year of specialized experience supporting FRCS RMF and cybersecurity engineering activities At least one current qualifying certification: CCSP, Cloud+, GICSP, GISF, GSEC, or Security+, RCCE Level 1, CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, GSNA.
Benefits & conditions
401(k) Dental insurance Health insurance Paid time off Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.wayup.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking
Walking Into The Era of Supply Chain Risks