Information Systems Security Engineer (RMF)

SAALEX Corp.
Newport, RI, United States
4 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$60,000.0 - $70,000.0
Working hours
Regular working hours

Tech stack

CompTIA Security+ Cyber Security Information Systems Identity and Access Management Security Software Navsea Information Technology

Job description

Saalex is seeking a Information Systems Security Engineer (RMF) in Newport, RI to support the Naval Undersea Warfare Center Division Newport (NUWCDIVNPT). The selected candidate will support Assessment and Authorization (A&A) activities and assist in maintaining Authorizations to Operate (ATOs) for enterprise and Research, Development, Test & Evaluation (RDT&E) systems and networks., * Support Assessment and Authorization (A&A) activities to maintain Authorizations to Operate (ATOs) in accordance with DoD and Department of the Navy RMF requirements.

  • Support cybersecurity compliance, security assessments, continuous monitoring activities, and information assurance efforts across Navy enterprise and RDT&E systems and networks.
  • Develop, review, and maintain RMF package documentation, including Security Plans, Risk Assessments, POA&Ms, architecture diagrams, asset inventories, and system/site policies and procedures.
  • Perform security control assessments in accordance with NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, CNSSI 1253, and applicable Navy cybersecurity guidance.
  • Execute Security Assessment Plans, review Security Test Reports, identify security deficiencies, and support risk mitigation activities.
  • Utilize cybersecurity tools including eMASS, ACAS, STIG Viewer, and STIG OSS Manager to assess, document, and monitor compliance.
  • Develop and maintain cybersecurity documentation including Contingency Plans, Contingency Plan Tests, Business Impact Analyses, and other required security artifacts.
  • Provide guidance on Navy RMF policies, DoD cybersecurity directives, NAVSEA business rules, and cybersecurity compliance requirements while supporting process improvement initiatives.
  • Provide RMF and eMASS guidance to team members and stakeholders and support cybersecurity training efforts as needed.
  • Attend stakeholder meetings, track action items, coordinate follow-up activities, and collaborate with government and contractor personnel to support successful A&A outcomes.
  • Other duties as assigned or required.

Requirements

  • Minimum of two (2) years of cybersecurity experience supporting RMF and Assessment & Authorization (A&A) activities.
  • Experience developing and maintaining RMF packages, including Security Plans, Risk Assessments, POA&Ms, and supporting documentation.
  • Experience with eMASS, ACAS, STIG Viewer, and cybersecurity compliance activities.
  • Working knowledge of NIST standards, RMF, DISA STIGs, and continuous monitoring requirements.
  • Ability to manage multiple priorities and communicate effectively with technical and non-technical stakeholders.
  • CompTIA Security+ or other DoD 8570/8140 IAM or IAT Level II certification required.

Desired:

  • Experience supporting Navy, NAVSEA, or other DoD cybersecurity programs.
  • Experience conducting security control assessments and supporting ATO efforts.
  • Familiarity with cybersecurity process improvement initiatives and RMF policy development.
  • Experience providing cybersecurity training, mentoring, or technical guidance.
  • CAP, CASP+, CISSP, or other advanced cybersecurity certification.

Education:

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field preferred. Equivalent combination of education, certifications, military experience, and professional cybersecurity experience may be considered.

Benefits & conditions

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources
  • Stock Option Plan

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all