Information Systems Security Analyst
EIGENNET LLC
Job Description
Job Description
Job Title: Information Systems Security Engineer (ISSE) – Systems Security Analyst
Employment Type: Full-Time – Up to 40 hours per week
Employment Status: Contingent Upon Contract Award
Customer Agency: Naval Facilities Engineering Systems Command (NAVFAC) Marianas – Command Information Office (CIO3 Office)
Work Location: On-Site
Place of Performance:
- Naval Facilities Engineering Systems Command (NAVFAC) Marianas facilities:
- Building 205, Halsey Drive, Nimitz Hill, Piti, Guam 96915.
- Building 3179, Sumay Drive, Naval Base Guam, Santa Rita, Guam 96915.
- Additional Government facilities as required:
- Marine Corps Base Camp Blaz, Guam.
- Andersen Air Force Base, Guam.
Position Overview
· The Information Systems Security Engineer (ISSE) will provide cybersecurity engineering support to the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO). The ISSE will support the protection, operation, and continuous improvement of Facility-Related Control Systems (FRCS) by ensuring the confidentiality, integrity, availability, and security of Government information systems, networks, and data.
· The successful candidate will execute cybersecurity engineering activities supporting the Risk Management Framework (RMF), Authority to Operate (ATO) authorization processes, vulnerability management, continuous monitoring, security assessments, and cybersecurity risk management activities across NAVFAC Marianas installations.
· This position requires demonstrated experience supporting Department of the Navy (DoN) and Department of Defense (DoD) cybersecurity environments, including RMF implementation, NIST SP 800-53 security controls, eMASS authorization package management, vulnerability assessments, Security Technical Implementation Guide (STIG) compliance, Plan of Action and Milestones (POA&M) management, and configuration management activities.
· The ISSE will work independently with minimal Government supervision and serve as a mission-essential cybersecurity resource supporting cybersecurity operations, Configuration Control Board (CCB) activities, and Cyber Emergency Response Team (CERT) functions.
Essential Duties and Responsibilities
- Execute Risk Management Framework (RMF) lifecycle activities (Steps 1–6) in accordance with applicable Department of the Navy (DoN), Department of Defense (DoD), and NAVFAC Echelon II cybersecurity guidance.
- Review and validate:
- System inventories.
- Security documentation.
- Authorization artifacts.
- Compliance evidence.
- RMF package information.
- Support Authority to Operate (ATO) authorization activities for Facility-Related Control Systems (FRCS), including:
- Maintaining and tracking authorization packages.
- Supporting annual security reviews.
- Preparing and maintaining Memorandums for Record (MFRs) for approved baseline changes during RMF Step 6 activities.
- Develop, maintain, and update cybersecurity documentation, including:
- System Security Plans (SSPs).
- Security policies.
- Standard Operating Procedures (SOPs).
- Implementation plans.
- After-action reports.
- Cybersecurity-related technical documentation.
- Apply NIST SP 800-53 security controls and tailor cybersecurity requirements to FRCS operational environments.
- Develop and execute vulnerability management strategies using approved DoD and Department of the Navy cybersecurity processes.
- Perform vulnerability and compliance assessments using approved cybersecurity tools, including:
- ACAS/Nessus.
- Security Content Automation Protocol (SCAP).
- Evaluate STIG.
- Security Center.
- Vulnerability Remediation Asset Management (VRAM).
- Perform manual Security Technical Implementation Guide (STIG) and Security Requirements Guide (SRG) compliance validation using:
- .ckl files.
- .cklb checklist formats.
- Generate cybersecurity assessment reports and maintain vulnerability documentation, including:
- Scan results.
- Compliance artifacts.
- Remediation documentation.
- Risk acceptance documentation.
- Upload and maintain cybersecurity artifacts within applicable systems, including:
- Enterprise Mission Assurance Support Service (eMASS).
- Vulnerability Remediation Asset Management (VRAM).
- Perform System-Level Continuous Monitoring (SLCM) activities, including:
- Vulnerability scanning.
- Audit log review.
- Remediation tracking.
- Plan of Action and Milestones (POA&M) updates.
- Support RMF Step 4 assessment activities by:
- Coordinating technical evidence collection.
- Performing system validation activities.
- Supporting security assessment preparation with system owners and assessment teams.
- Serve as a cybersecurity technical representative and/or Configuration Management (CM) Officer supporting Configuration Control Board (CCB) activities.
- Perform:
- Cybersecurity impact analyses.
- Risk assessments.
- Security reviews for proposed FRCS configuration changes.
- Support cybersecurity incident response operations as part of the MAR Cyber Emergency Response Team (CERT).
- Participate in designated on-call rotations and provide cybersecurity support during emergency or mission-essential conditions.
- Coordinate cybersecurity support activities across multiple FRCS environments and installation locations.
- Prepare and provide cybersecurity status reporting, including:
- Bi-weekly RMF status reports.
- Monthly status reports.
- Contract-required documentation.
- Maintain FRCS RMF project tracking information using applicable project management systems, including:
- Maximo.
- eProjects.
- Provide on-site cybersecurity support at Naval Base Guam and other supported locations, including:
- Marine Corps Base Camp Blaz.
- Andersen Air Force Base.
- Perform other cybersecurity engineering duties as assigned by the Contracting Officer’s Representative (COR).
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering, or a related technical discipline preferred.
- Equivalent combinations of education, professional experience, and cybersecurity certifications may be considered.
- Minimum five (5) years of professional experience supporting Risk Management Framework (RMF) activities.
- Minimum one (1) year of specialized experience supporting Facility-Related Control Systems (FRCS) cybersecurity engineering and RMF implementation.
- Demonstrated experience executing RMF lifecycle activities (Steps 1–6) within:
- Department of Defense environments.
- Department of the Navy environments.
- Experience supporting Authority to Operate (ATO) processes, including:
- Authorization package development.
- Security reviews.
- Security documentation maintenance.
- Experience developing and maintaining cybersecurity documentation, including:
- System Security Plans (SSPs).
- Plans of Action and Milestones (POA&Ms).
- Memorandums for Record (MFRs).
- SOPs.
- Security policies.
- Implementation plans.
- Experience implementing and assessing NIST SP 800-53 security controls.
- Experience performing cybersecurity assessments using DoD-approved tools, including:
- ACAS/Nessus.
- SCAP.
- Evaluate STIG.
- Security Center.
- VRAM.
- Experience performing manual STIG/SRG compliance validation using .ckl and .cklb checklist formats.
- Experience supporting continuous monitoring activities, including:
- Vulnerability management.
- Audit reviews.
- Remediation tracking.
- POA&M management.
- Experience supporting Configuration Control Board (CCB) activities and cybersecurity impact assessments.
- Experience supporting cybersecurity incident response operations, CERT activities, or equivalent cyber defense functions.
- Strong written and verbal communication skills with the ability to communicate effectively with:
- Government personnel.
- System owners.
- Information Systems Security Managers (ISSMs).
- Cybersecurity stakeholders.
- Ability to work independently, prioritize multiple tasks, and perform cybersecurity activities with minimal Government supervision.
- Ability to operate within secure military installation environments while complying with DoD security requirements.
- Ability to perform essential field activities, including:
- Walking on uneven terrain.
- Climbing ladders.
- Bending, crouching, and reaching.
- Lifting and moving IT equipment up to 25 pounds.
- Conducting on-site cybersecurity assessments.
Preferred Qualifications
- Experience supporting:
- NAVFAC cybersecurity operations.
- Department of the Navy cybersecurity programs.
- DoD cybersecurity environments.
- Experience supporting:
- Facility-Related Control Systems (FRCS).
- Operational Technology (OT).
- Industrial Control Systems (ICS).
- Building automation and security systems.
- Hands-on experience managing RMF authorization packages within eMASS.
- Experience using eMASS for:
- Authorization package management.
- Artifact uploads.
- Package maintenance.
- Knowledge of:
- DoN cybersecurity directives.
- NAVFAC Echelon II RMF Business Rules.
- DoD cybersecurity policies.
- Experience tracking cybersecurity project activities using:
- Maximo.
- eProjects.
- Experience supporting military installation cybersecurity operations and mission-essential environments.
- Experience performing:
- Security assessments.
- Technical reviews.
- Vulnerability remediation.
- Cybersecurity risk management.
- Strong technical writing skills with experience preparing:
- Cybersecurity policies.
- Procedures.
- Implementation plans.
- Incident response documentation.
- Ability to manage multiple cybersecurity projects and FRCS environments simultaneously.
Required Certifications
Candidates must possess and maintain at least one approved commercial cybersecurity certification aligned with DoDM 8140.03 Work Role Code 461 (Systems Security Analyst), Intermediate Proficiency Level prior to onboarding.
Intermediate-Level Certifications
- Certified Cloud Security Professional (CCSP).
- CompTIA Cloud+.
- Global Industrial Cyber Security Professional (GICSP).
- GIAC Information Security Fundamentals (GISF).
- GIAC Security Essentials Certification (GSEC).
- CompTIA Security+.
Advanced-Level Certifications (Also Acceptable)
- Registered Cybersecurity Career Professional (RCCE) Level 1.
- Certified Information Systems Security Officer (CISSO).
- CISSP Information Systems Security Engineering Professional (CISSP-ISSEP).
- CompTIA Cybersecurity Analyst (CySA+).
- FITSP-Operations (FITSP-O).
- GIAC Cloud Security Automation (GCLD).
- GIAC Certified Security Architect (GCSA).
- GIAC Systems and Network Auditor (GSNA).
Certification Maintenance Requirements
- Certifications must remain active and in good standing throughout contract performance.
- Personnel must complete:
- Minimum twenty (20) hours of Continuous Professional Development (CPD) annually; or
- The minimum CPD requirement established by the certification provider, whichever is greater.
Operational Requirements
- Position requires full-time on-site performance at Naval Base Guam.
- Work schedule:
- Up to forty (40) hours per week.
- Monday through Friday.
- During normal business hours.
- Excluding Federal holidays.
- Remote telework is not authorized except for emergency or situational circumstances approved by the COR.
- Personnel are considered Emergency Essential and/or Mission Essential and may be required to support expanded mission conditions.
- Participation in MAR Cyber Emergency Response Team (CERT) activities and on-call rotations may be required.
- Local travel may be required between:
- Naval Base Guam.
- Marine Corps Base Camp Blaz.
- Andersen Air Force Base.
- Contractor personnel must provide their own transportation for local travel unless otherwise authorized.
- Overtime is not authorized under this contract.
- ...Job Description Job Description Position Overview The Systems Security Analyst / Information Systems Security Engineer (ISSE) provides cybersecurity engineering support to the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office...Information SystemWork at officeFlexible hours
- ...Work Location: Building 3190, Naval Base Guam (NBG), Santa Rita, Guam 96915 Position Overview We are seeking a Systems Security Analyst to support our client. You will help protect the confidentiality, integrity, and availability of Facility-Related Control...Suggested
$69.7k - $94.3k
...Continuous Monitoring, Incident Management, Information Security, Remediation Certifications:... ...GDIT is seeking an Information Assurance Analyst to help support our Base... ...to support the government information systems. The IA role will support the Risk Management...Information SystemFull timeContract workTemporary workPart timeLocal areaImmediate startRemote workWorldwideFlexible hours- Ross Stores, Inc. is hiring for a Loss Prevention Specialist in Tamuning, Guam. The role involves ensuring safety and compliance while deterring theft. Candidates should have a high school education and preferably some retail supervision experience. Strong communication...Suggested
- ...Award Customer Agency: Naval Facilities Engineering Systems Command (NAVFAC) Marianas – Command Information Office (CIO3 Office) Work Location: On-Site... ...Provisioning enterprise mobile devices. Configuring device security settings. Troubleshooting mobile device issues....Information SystemFull timeContract workFor contractorsInterim roleWork at officeRemote workRelocationMonday to Friday
- ...through collaboration, continuous improvement, and a commitment to secure and efficient data center operations. We take pride in being a... ...Documentation and Assets, and GTA NOC where physical security systems or records intersect. Coordinate escorts for customers,...For contractorsLocal areaNight shift
$95k - $110k
...ample opportunities for professional growth. Join Cadmus. Together, we are strengthening society and the natural world. For more information, visit cadmusgroup.com . Responsibilities Manage and coordinate delivery across multiple workstreams Coordinate activities...Permanent employmentWork experience placementLocal areaWorldwide- ...administrative support to the NAVFAC Marianas Command Information Office (CIO3) to ensure continuous and efficient operation of enterprise IT systems, hardware, software, helpdesk services,... ...) support: Provision, configure, enforce security, troubleshoot, and maintain enterprise...Information SystemContract workFor contractorsWork at officeRemote work
- ...Saipan. This position ensures reliable, secure, and uninterrupted access to mission‑critical... ..., audiovisual, VoIP, and collaboration systems used for meetings, exercises, and... ...s What You Need Bachelor’s degree in Information Technology, Computer Science, Cybersecurity...Information SystemContract workLocal areaFlexible hours
$16 - $19.5 per hour
...service with oversight and approval of the Corps Officers. Input data gathered from client intake into the Homeless Management Information System (HMIS), WellSky, and other reports. Perform assessments for the homeless, underprivileged persons, and families in crisis...Information SystemWork experience placementWork at officeLocal area- ...notification procedures; Ammunition Transaction Reporting (ATR) system; and NAVSUP-P 724, OP5, and DPAS programs, or equivalent... ...Overseas ordnance accounting data via the use of the ordnance information system (OIS) database ensuring 100% accountability of all ammunitions...Information SystemPermanent employmentFull timeContract workTemporary workLocal areaRemote workOverseas
- ...sufficiently detailed data for input of all maintenance information into the CMMS system. • Respond to and correct issues that may exist within... ...electrical schematics • Ability to be badged to work in secure areas of an airport • Ability to work 1st, 2nd, or 3rd...Information SystemPermanent employmentRelocation packageNight shiftDay shiftAfternoon shift
- ...complete, open and integrated business software and hardware systems with annual revenues of $57bn, and over 163,000 employees worldwide... ...others. Collaborate with Tax organization on tax authority information requests and audits. Implement best‑practice system processes...Full timeTemporary workPart timeWork at officeLocal areaWorldwideFlexible hours
- ...budgeting and cost estimation approaches, and providing recommendations to management and the sales team. The role involves using hotel systems to assess departmental performance and cost efficiency, coordinating communication between departments to support planning goals,...
- Job Description Job Description Summary/Objective This position will be responsible for a broad range of financial & analytical duties, including but not limited to general ledger accounting entries and account reconciliations. This position will play a key role...Work at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Systems Security Analyst. Be the first to apply!

