Point your AI agent at freehire and let it find you a job.

Get the CLI →

prosoft

NQV Information Security Analyst

Posted Updated 2 views
Discussion

Summary

On-site Information Security Analyst at Norfolk Naval Shipyard supporting DoD Risk Management Framework, performing vulnerability analysis, ST&E processing, and STIG validation using tools like eMASS.

Position: Information Security Analyst (NQV)

Location: Norfolk Naval Shipyard 100% on-site

Clearance: Top Secret clearance

Job Description:

The Information Security Analyst (NQV) shall work to support DoD Risk Management Framework (RMF) and validate Network and System assets. They will be responsible to:

a. Follow Accreditation & Authorization (A&A) process and standards.

b. Perform System / network vulnerability analysis.

c. Conduct Risk assessment and risk mitigation analysis.

d. Perform Security Test and Evaluation (ST&E) processing.

e. Validate Security Technical Implementation Guide (STIG) Processing. Use automated STIG processing tools [e.g., Security Content Automation Protocol (SCAP), Evaluate STIG, STIGMAN, EMASSter]. Use of Enterprise Mission Assurance Support Services (eMASS) and similar RMF repositories.

f. Setup and execute A&A Business Rules, Standard Operating Procedures (SOP)s, Concept of Operations (CONOP)s, and Plans.

g. Perform Contingency planning, training and testing.

h. Establish/interrupt Firewall Policy.

i. Identify Interrupt, register Ports & Protocols.

j. Review Hardware / Software, network boundaries, flow diagrams and technical drawings.

k. Identify interrupting information in the system baseline configuration in VRAM by uploading vulnerability scan of a representative baseline system.

l. Advise on the proper method to mitigate vulnerabilities.

m. Produce executive documents, reports, project plans and plan of action and milestones (POA&M).

Qualifications:

Minimum of seven (7) years of experience in CS/A&A analysis support in IA controls analysis, conducting risk assessments, risk mitigation analysis, or developing plans. KSAs include:

• Qualified and registered as a Navy Qualified Validator (NQV)

• Expert knowledge of and experience with CS/RMF requirements as defined by Public Laws, National, DoD, and DON [e.g., Federal Information Security Management Act (FISMA), DoDD 8100.02, DODI 8500.01, DoDI 8520, DoDI 8530, DoDI 8531, SECNAV 5239 Series and OPNAV 5239 Series, NIST Special Publications Series 800, etc.]

• Expert and Mastery levels with institutional knowledge on the mission critical procedures, systems, and processes, as they pertain to Information Technology and Cyber Security requirements.

• Experience in certifying and accrediting DON information systems and networks, as well as Platform IT.

• Expert knowledge and experience with the requirements outlined in OPNAVINST N9210.3 Safeguarding Naval Nuclear Propulsion Information

Education:

Bachelor’s degree in an IT related discipline OR Level II Certification (Security+ or better) AND a minimum of seven (7) years of experience.

Certifications:

• Active Security + CE or higher

• Active NQV

What they ask for

Required

  • Top Secret clearance
  • Navy Qualified Validator (NQV) registration
  • Minimum 7 years experience in CS/A&A analysis
  • Bachelor's degree in IT discipline OR Level II Certification (Security+ or better)
  • Active Security+ CE or higher certification
  • Expert knowledge of CS/RMF requirements (FISMA, DoD directives, NIST SP 800 series)
  • Experience certifying and accrediting DON information systems and networks
  • Expert knowledge of OPNAVINST N9210.3 Safeguarding Naval Nuclear Propulsion Information

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available