Senior Cybersecurity Specialist

Seneca Holdings
Tampa, FL, United States
1 day ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Xacta Software System Penetration Testing Systems Engineering Cyber Security Databases Document Management Systems Software Vulnerability Management SARS Software Products Information Technology Vulnerability Analysis

Job description

Great Hill is seeking a Senior Cybersecurity Specialist who will provide cybersecurity operations and Risk Management Framework (RMF) support for SOCRATES systems and enterprise IT initiatives in Tampa, FL. The position will support security compliance, system security assessments, vulnerability management, continuous monitoring, and cybersecurity documentation throughout the system lifecycle.

Roles and Responsibilities include, but are not limited to:

  • Provide senior-level cybersecurity and Risk Management Framework (RMF) support for SOCRATES and C4IAS enterprise IT initiatives.
  • Develop, maintain, and manage RMF and Assessment & Authorization (A&A) documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Security Authorization Packages, and Plans of Action and Milestones (POA&Ms).
  • Support IATT and ATO activities and coordinate with Security Control Assessors (SCAs), Authorizing Officials (AOs), ISSOs, and ISSMs.
  • Conduct security assessments, vulnerability scans, penetration testing, and compliance reviews to identify and address cybersecurity vulnerabilities.
  • Perform ACAS scans and support remediation of IAVAs, IAVBs, CVEs, STIG findings, and other security vulnerabilities.
  • Develop and maintain technical POA&Ms and remediation plans, prioritizing findings based on risk and severity.
  • Support continuous monitoring and implement cybersecurity countermeasures throughout the system lifecycle.
  • Ensure cybersecurity requirements are incorporated into acquisition, systems engineering, testing, integration, and implementation activities.
  • Provide cybersecurity support for the testing, integration, installation, and deployment of hardware and software.
  • Maintain A&A and cybersecurity documentation using eMASS, XACTA, or equivalent RMF management systems.
  • Support classified security activities, including document control, classified material inventories, access requests, and security-related databases.
  • Ensure compliance with applicable DoW, Intelligence Community, NIST, DISA, USCYBERCOM, and USSOCOM cybersecurity policies and requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent relevant experience.
  • Active Top Secret clearance.
  • 5+ years of experience supporting cybersecurity, Information Assurance, RMF, or related activities.
  • Experience developing and maintaining RMF/A&A documentation and security authorization packages.
  • Experience with vulnerability management, security assessments, ACAS, STIGs, and POA&Ms.
  • Working knowledge of NIST 800-53, NIST 800-37, DoW RMF, and applicable DoW cybersecurity requirements.
  • Experience using eMASS, XACTA, or similar RMF management tools.
  • DoW 8570/8140-compliant cybersecurity certification appropriate to the position.
  • Ability to work independently and communicate effectively with government and contractor stakeholders.

Desired Skills:

  • Experience supporting USSOCOM, SOCRATES, C4IAS, or other DoW/Intelligence Community programs.
  • Experience working in classified environments and supporting systems across multiple security enclaves.
  • Experience supporting IATT and ATO processes from initiation through authorization.
  • Experience with DISA STIGs/SRGs, ACAS, penetration testing, and continuous monitoring.
  • Experience addressing USCYBERCOM IAVAs/IAVBs and cybersecurity tasking.
  • Experience with privileged user/system administrator responsibilities.
  • Experience with Supply Chain Risk Management (SCRM) and related cybersecurity requirements.
  • CISSP or other advanced cybersecurity certification.
  • Experience coordinating with SCAs, AOs, ISSOs, ISSMs, and other government cybersecurity stakeholders.

Benefits & conditions

Our team of talented individuals is what makes us successful. To support our team, we provide a balanced mix of benefits and programs.Your total rewards package includes competitive pay, benefits, and perks, flexible work-life balance, professional development opportunities, and performance and recognition programs. We offer a comprehensive benefits package that includes medical, dental, vision, life, and disability, voluntary benefit programs (critical illness, hospital, and accident), health savings and flexible spending accounts, and retirement 401K plan. One of our fundamental principles is to offer competitive health and welfare benefits to our team members, providing coverage and care for you and your family. Full-time employees working at least 30 hours a week on a regular basis are eligible to participate in our benefits and paid leave programs. We pride ourselves on our collaborative work environment and culture, which embraces our mission of providing financial and

About the company

Great Hill Solutions, LLCis part of the Seneca Nation Group (SNG) portfolio of companies. SNGis Seneca Holdings’ federal government contracting business that meets mission-critical needs of federal civilian, defense, and intelligence community customers. Our portfolio comprises multiple subsidiaries that participate in the Small Business Administration 8(a) program. To learn more about SNG, visitthe website and follow us onLinkedIn.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

Videos

See all

Related articles

See all