Information System Security Engineer (ISSE)
Posted Updated
GENERAL SUMMARY: Seeking candidates with Risk Management Framework (RMF) Information Systems Security Engineer (ISSE) experience. Primary responsibility is to perform tasks related to Assessment & Authorization (A&A) and cybersecurity to obtain and maintain Authorizations to Operate for US Navy afloat and ashore systems.
PRINCIPAL DUTIES/RESPONSIBILITIES:
- Lifecycle cybersecurity support of US Navy systems
- Lead the RMF process for assigned programs, organizations, systems, or enclaves
- Manage POA&M entries and ensuring vulnerabilities are properly tracked, mitigated, and resolved
- Assemble the Security Authorization Package and submit for adjudication
- Assess the quality of security control implementation against all requirements in accordance with the approved SLCM strategy
SKILLS AND ABILITIES:
Essential Skills:
- Experience with Risk Management Framework (experience under DoD a plus)
- Experience using the Enterprise Mission Assurance Support Service (eMASS)
- Experience with Assured Compliance Assessment Solution (ACAS)
- Demonstrated efficiency and experience in the following areas:
- RMF package development and management, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, and hardware/software inventories
- NIST 800-53 control validation