Information System Security Specialist II
Job Title: Information System Security Specialist
Clearance: Secret
Work Location: Philadelphia, PA
Employment Type: Full-Time
*Position is contingent upon award*
About the Company
Athena Technology Group, Inc. (ATG) is a Service-Disabled Veteran Owned Small Business (SDVOSB) and Historically Underutilized Business Zone (HUBZone) established in 2010. ATG has immense experience and a strong, solid reputation throughout various government agencies, providing consistently superior, innovative, and cost-effective solutions. ATG is a premier provider of cybersecurity, risk management framework (RMF), and communications cybersecurity solutions, as well as information technology (IT) and communications consulting, system engineering, integration, deployment and operation of state-of-the-art command and control and information systems that deliver critical network centric solution to the warfighter. We are looking for innovative industry professionals to join our team and continue our proven track record.
ATG is an Equal Opportunity/Affirmative Action Employer Minorities/Females/Vets/Disability
Job Summary
We are seeking an Information System Security Specialist to join our team. You will play a key part in ATG’s technical support for Naval Surface Warfare Center Philadelphia Division (NSWCPD) specializing in cybersecurity support, validation support, IT and cyber policy writing and program implementation support. Our team will provide direct support for cybersecurity policy, A&A artifacts, validation, and security posture reviews.
Key Responsibilities
-
Support evaluation and documentation in eMASS to include the security posture of the system or site being Assessed, Authorized, and maintained.
-
Submit, and maintain RMF packages in accordance with DoD Instruction 8510.01, NAVSEA Business Rules, DON RMF Process Guides, NAVSEA Standard Operating Procedures (SOPs), and the business rules of cognizant review offices.
-
Support development the RMF package documentation required for submission in accordance with DoD/NAVSEA directives. Documents may include but are not limited too HW/SW Lists, Authorization Boundary Diagrams, Privacy Impact Assessment (PIA), etc.
-
Conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs.
-
Conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor’s (SCA) and higher level review.
-
Execute Security Assessment Plans (SAPs) by supporting on-site testing for afloat and PIT ashore systems.
-
Conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system.
-
Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS).
-
Assess impacts from observed risks and report via the Cybersecurity Program chain of command.
-
Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities.
-
Support the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution.
-
Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance.
-
Maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM).
-
Ensure RMF artifacts are in compliance with published Navy, NAVSEA Business Rules (OPNAV N2N6 and/or NAVSEA), NIST SP-800-37 and SP-800-53 Rev 4.
Qualifications
Required:
-
Active Secret clearance (eligible to obtain and maintain a TS clearance)
-
Bachelor’s degree (Computer Science, Information Technology or related technical degree) from an accredited College or University.
-
3-5 years of professional experience in Information Assurance Compliance.
-
CCNA or CAP or Security + (CE) or ENSA certification.
Desired:
Additional Benefits
Performance Bonuses and annual salary reviews
Health, dental, and vision insurance
Short Term Disability, Long Term Disability, and Life Insurance
401(k) plan with company match
Opportunities for professional growth and development
A collaborative and inclusive work environment
ATG is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, religion, creed, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, medical condition, marital or domestic partner status, sexual orientation, gender, gender identity, gender expression and transgender status, mental disability or physical disability, genetic information, military or veteran status, citizenship, low-income status or any other status or characteristic protected by applicable law. Learn more about your rights under Federal EEO laws and supplemental language.
