Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Assurance / Security Specialist

Diverse Systems Group LLC

Job Description

Job Description

Description:

Overview:

Diverse Systems Group, LLC is seeking an Information Assurance Specialist to support Walter Reed National Military Medical Center (WRNMMC)’s system security authorization processes in compliance with the Department of Defense (DOD) and Defense Health Agency (DHA)’s NIST RMF related policies and requirements.

Job Summary:

  • Lead and perform Defense Health Agency (DHA)-specific Risk Management Framework (RMF)-related tasks throughout all stages of a system’s lifecycle to include:
  • stakeholder engagement and development of A&A or Threat Management Team project plans
  • preparation and maintenance of FIPS-199 system security categorization,
  • preparation and maintenance of FIPS-200 system security controls exceptions,
  • performance of risk assessments,
  • analysis of risk remediation and mitigation options and strategies,
  • development, review, and submission of Assessment & Authorization (A&A) system security packages,
  • selection and documentation of applicable NIST 800-53 rev. 4 security controls in systems’ Security Controls Traceability Matrices (SCTM),
  • collection, development, and analysis of NIST 800-53 rev 4-related security controls artifacts,
  • participation in and organizational oversight of Independent Verification & Validation (IV&V) activities,
  • development of and status tracking for Plans of Action & Milestones (POA&M),
  • performance of Continuous Diagnostics and Monitoring (CDM)-related activities, and
  • status tracking and reporting to leadership and organizational stakeholders.
  • Supports the year-round work of maintaining security posture to meet DoD RMF requirements.
  • Manage system security packages in DOD Enterprise Mission Assurance Support System (eMASS) throughout system authorization cycles, to include:
  • system registration
  • uploading and maintenance of system security packages,
  • Plans of Action & Milestones (POA&M) entry and tracking, and
  • system decommissioning.
  • Conduct and technology assessments, reviews, and technical inspections to identify and mitigate potential security weaknesses and to ensure all applicable security features and functionality are implemented and function as intended and required.
  • Work in partnership with System and Network Administrators to perform self-assessment and hardening of workstations, servers, network devices, and clinical devices to include application of Secure Technical Implementation Guidelines (STIG) and running hardening and security artifact collection scripts and Security Content Automation Protocol (SCAP) and Assured Compliance Assessment Solution (ACAS) scans.
  • Develop and maintain cybersecurity-related training materials and delivery of training for users and System Administrators (SA).
  • Possess and maintain comprehensive understanding of federal security regulatory requirements and security frameworks including DoD/DHA IT Security and IA policies, RMF, NIST SP 800-series, FISMA, FIPS, FedRAMP, policies, directives, and publications etc.
  • Proactively maintain awareness and understanding of current and emerging threats and vulnerabilities and their potential impact on organizational mission accomplishment, patient safety, and security of patient data.
  • Apply security patches, IAVAs, STIGS, and updates for all assigned systems
  • Provide support for the escalation and communication of status to agency management and internal customers and clearly communicate technical information to both technical and non-technical personnel
  • Implement and manage disaster recovery and COOP plans, systems, and operations.
  • Works collaboratively with team to ensure the following; Maintenance of baseline system security according to organizational policies, cyber threats and vulnerabilities are mitigated, and information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, and encryption) are adhered to.
  • Provide configuration management and accurately assess the impact of modifications and vulnerabilities for each system.
  • Maintain thorough understanding of NIST 800-53 controls, and determine which controls are applicable to the application, as well as document implementation in Security Controls Tractability Matrix (SCTM).
  • Oversee the monitoring and resolving Plan of Action and Milestones (POA&M) to mitigate system vulnerabilities on assigned Information Systems.
  • Ensures technical system documentation required for A&A packages are complete and clearly supports validation and ATO in accordance with system security requirements.
  • Performs comprehensive A&A tasks including package development, controls analysis, risk assessment, contingency planning, security test & evaluation, risk mitigation analysis, and technology assessments.
  • Utilizes application NIST and FIPS standards and guidance documents to register and complete accreditation packages in the DISA eMASS system.
  • Leads the RMF accreditation lifecycle for assigned systems from cradle to grave, managing stakeholder engagement, lifecycle progression, schedule development, accreditation package review, submission and validation.
  • Maintains and supports current and ongoing A&A packages to ensure an uninterrupted delivery of information technology systems for the organization.
  • Creates, manages, and maintains setup documentation and security policies for compliance and accreditation purposes for all programs, projects, including SOPs, Policies, Procedures, Plans, guidelines, checklists, presentations, training guides, etc… in alignment with the DOD/DHA IT organizational cybersecurity needs or in accordance with RMF guidelines.
  • Reports on assessment process status, participates in Independent Verification & Validation (IV&V) activities, conducts/oversees IV&V testing as required, and assists system certifiers during evaluations.
  • Reviews regulatory security policies, as well as best practices, and develop the technical solution required in order to implement those requirements on servers, routers, firewalls and other LAN/WAN equipment.
  • Works with System and Network Administrators to monitor the security posture of all networked systems and applications and take appropriate steps to quickly deal with any vulnerabilities.
  • Provides system, network, security engineering expertise and guidance for all aspects of information assurance, including those systems required to meet DoD regulations and requirements.
  • Manages the cybersecurity program to minimize risk and exposure across projects.
  • Oversee a team performing self-assessment and hardening of system servers, applying STIGs, SCAP and ACAS scans, and other scripts
  • Comprehensive understanding of DoD MHS services and programs, and other usability standards, as well as user interface design methodologies.
  • Other duties assigned as related to the Cybersecurity Division.

Supervisory Responsibility: No

Requirements:

Skills & Abilities:

  • Knowledge and experience with DOD RMF A&A artifacts, network architecture, network and security management and monitoring tools and penetration test tools.
  • Experience with deploying & hardening Windows Server 2012 R2, Server 2016, Server 2019
  • Experience with PowerShell, Tanium, SCAP, NMAP, SQL Developer, Forescout, and/or Splunk
  • Large Enterprise-level IT experience with maintenance of servers, storage devices and applications
  • Strong problem solving and critical thinking skills.
  • Strong planning & organizational skills.
  • Strong verbal and written communication skills to include delivery of presentations and communication of technical concepts to non-technical personnel that may span organizations and functional groups.
  • Strong verbal and written communication skills to include delivery of presentations and communication of technical concepts to non-technical personnel that may span organizations and functional groups.
  • Strong problem solving and critical thinking skills.

Education/Experience:

  • 5+ years of technical experience related to system and / or network administration and / or cybersecurity operations.

Certification(s):

  • Minimum certification level of CompTIA Security+ CE or equivalent certification required in accordance with DoDI 8140 / DoDD 8570 requirements (IAM/IAT Level 2)
  • CISSP, CAP, CYSA, CISM, MSCE or equivalent certification required.

Clearance:

  • DOD Secret security clearance required.

Nice to have:

  • Four-year college degree in Cybersecurity, Information Technology, Computer Information Systems, Computer Science, Computer Engineering, or equivalent. (Additional years of experience may serve in lieu of a degree)
Vacancy posted 22 days ago
Similar jobs that could be interesting for youBased on the Information Assurance / Security Specialist in Bethesda, MD vacancy
  • Overview Role : Information Assurance and Security Specialist - Master Location : Washington DC Client : DC Government Duties a. Identify network problems, and recommend improvements to ensure optional performance; b. Ability to monitor and analyze data traffic patterns... 
    Suggested
    Work from home
    Flexible hours

    AHU Technologies Inc

    Washington DC
    3 days ago
  • Information Assurance (IA) / Security Compliance Specialist This position is in anticipation of contract award and is contingent upon successful contract award. Applicants will be contacted regarding employment opportunities upon award notification. 5+ years Federal IA... 
    Suggested
    Contract work

    Blue Rose Consulting Group

    Washington DC
    1 day ago
  •  ...Overview (590) Information Security Specialist III — Silver Spring, MD Company Summary Arlo Solutions (Arlo) is an information technology consulting...  ..., personnel security, cybersecurity, and information assurance functions Develop research security protocols in compliance... 
    Suggested
    Contract work
    For contractors
    Work at office

    Arlo Solutions

    Silver Spring, MD
    1 day ago
  •  ...Job Description Job Description Description: We are seeking a highly skilled and mission-focused Information Assurance / Security Specialist (ISSO) to support cybersecurity compliance, Assessment & Authorization (A&A) activities, and Authority to Operate (ATO) documentation... 
    Suggested
    Contract work
    For contractors

    Powder River Industries, LLC

    Washington DC
    4 days ago
  •  ...celebrating 26 years of excellence—is seeking a Senior Information Systems Security Specialist to Join our Team in Washington, DC. At ICI Services, our...  ...for supporting all aspects of a Program Information Assurance (IA) processes tailored to include minimum qualification... 
    Suggested
    For contractors

    ICI Services Corporation

    Washington DC
    3 days ago
  •  ...Job Description Job Description Information Assurance (IA) / Security Compliance SpecialistAbout Blue Rose Consulting Group Blue Rose Consulting Group, Inc. (Blue Rose) is a certified HUBZone and Service-Disabled Veteran-Owned Small Business supporting Federal customers... 
    Full time
    Contract work
    Work at office
    Overseas

    Blue Rose Consulting Group, Inc.

    Washington DC
    9 days ago
  • $102k - $178.4k

     ...solutions to meet Leo's regulatory and external assurance needs. In this role, you will work collaboratively with various business and security teams across Amazon to identify...  ...achieve. Basic Qualifications: 4+ years of information security and compliance experience... 
    Permanent employment
    Worldwide
    Flexible hours

    Socket.dev

    Arlington, VA
    1 day ago
  • Sr. Security & Compliance Specialist - TS Clearance Full-time SVD Solutions is focused on providing comprehensive Information Security/Assurance advisory services to Senior Executives of government and commercial organizations. We are an intelligence-driven management... 
    Full time
    Work experience placement
    Work at office
    Immediate start
    Remote work

    SVD Solutions

    Washington DC
    1 day ago
  • DescriptionSAIC is seeking an Information Security Specialist in Arlington, VA to support the Army National Guard (ARNG), focusing on derivative classification, standard operating procedures (SOP) and security education, training, and awareness (SETA) for Information Security... 

    Science Applications International Corporation

    Arlington, VA
    3 days ago
  •  ...Badging Security Processing Specialist Great Hill Solutions is part of the Seneca Nation Group (SNG...  ...security of personnel, facilities, and information for a large federal agency located...  ...NEO. Maintaining databases and assuring quality control of information.... 
    Full time
    For contractors
    Flexible hours

    Seneca Holdings LLC

    Silver Spring, MD
    1 day ago
  • $100k - $141.3k

     ...impact. Join us!Position Summary:This role supports Container Information Security activities for Bank of America, including:Assist in...  ...within container environments.Support container vulnerability assurance efforts, including compliance with configuration requirements... 
    Full time
    Internship
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Washington DC
    1 day ago
  • $89.8k - $150k

     ...Security SpecialistAMERICAN SYSTEMS is an employee-owned federal government contractor...  ...our strategic solutions in the areas of Information Technology, Test & Evaluation, Program...  ...& Analysis, and Training.As a Security Specialist with AMERICAN SYSTEMS you will have the... 
    For contractors

    American Systems

    Washington DC
    4 days ago
  • $145k - $200k

    Celestar, a B&A Company, is seeking a Technical Security Support Specialist to support the Defense Advanced Research Projects Agency (DARPA) Program...  ...used to manage SAP compartments, facilities, personnel, information, and security records.· Ability to develop database... 
    Contract work
    Local area

    Celestar

    Arlington, VA
    1 day ago
  •  ...all matters concerning the management of information as a critical DOJ resource as it...  ...Unclassified Information (CUI), National Security Information (NSI), and Sensitive Compartmented...  ...for an Information Security Specialist, GS-0080-12/13 generally include, but are... 
    For contractors
    Trial period

    Offices, Boards and Divisions

    Washington DC
    3 days ago
  •  ...Security Administration and OperationsCandidate must be authorized to work without sponsorshipMust...  ...Security, Scripting Automation, Information Security, Endpoint SecurityOur Impact:...  ...Security team to ensure solution assurance and compliance to security policy, procedures... 
    Remote work
    Weekend work
    Afternoon shift

    Samprasoft

    McLean, VA
    4 days ago
  • $99k - $225k

    Information Security Risk SpecialistThe Opportunity:As an Information Security Risk Specialist on our team, you will leverage your expertise to collaborate closely with contractor and DoD government system owners, as well as system administrators and developers, to identify... 
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    1 day ago
  • Koniag Information Security Services, LLC is seeking a Personnel Security Specialist in Arlington, VA to support personnel security for the Department of Defense. Responsibilities include managing security databases, developing SOPs, and ensuring compliance with security... 

    Koniag Information Security Services, LLC

    Arlington, VA
    4 days ago
  • Saliense is seeking an Information System Security Officer (ISSO) to support work under a federal contract, applying RMF and NIST CSF guidelines. The role involves designing and implementing controls to protect sensitive information and delivering technical evaluations... 
    Contract work

    Saliense

    Arlington, VA
    2 days ago
  • Bank of America is seeking an Information Security Controls Specialist within Global Information Security (GIS) IAM to support enterprise IAM processes and controls. You will partner with business, technology, and cybersecurity teams to ensure risks are identified, managed... 

    Bank of America

    Washington DC
    2 days ago
  • $50.64 - $83.55 per hour

     ...other company-sponsored benefits Security Clearance: Ability to obtain and maintain...  ...? PEMCCO is seeking an Senior Information Security Specialist to lead security, compliance, risk...  ...with experience in information assurance, cybersecurity, information security... 
    Hourly pay
    Contract work
    Work at office
    Local area

    PEMCCO

    Washington DC
    6 days ago
  • $44.85 - $74 per hour

     ...other company-sponsored benefits Security Clearance: Ability to obtain and maintain...  ...threats?  PEMCCO is seeking an  Information Security Specialist  to support the security, compliance...  ...with experience in information assurance, information security, cybersecurity... 
    Hourly pay
    Contract work
    Work at office
    Local area

    PEMCCO

    Washington DC
    5 days ago
  •  ...Job Title Job Description DUTY 1: Administers the Information Security Program protecting the enterprise from espionage, terrorism,...  ...national security. Enforces operational, functional, and mission assurance aspects of the program for the Air Combat Command... 
    For contractors
    Worldwide

    US Department of War

    Bethesda, MD
    4 days ago
  • $78.6k - $160.2k

     ...ingenuity for clients across defense, national security, public safety, civilian, and military...  ...forward! The Security Architecture Specialists will work in the Security Architecture,...  ...2-3 years of working experience information security or relevant experience. Experience... 
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture Federal Services

    Arlington, VA
    3 days ago
  •  ...services. When it comes to excellence, we deliver. Learn more about our employer brand at makpar.com/careers . The Senior Information Security Analyst will perform the core cybersecurity assessment and compliance work for IRS Safeguards. The role supports computer... 
    Full time
    Start working today
    Flexible hours

    Makpar Corporation

    Washington DC
    1 day ago
  •  ...transitioning service members, and military spouses are strongly encouraged to apply. Job Description The Information Systems Compliance Specialist will conduct Security Assessment and Authorization (A&A) support for USSS IT systems. This candidate must have the ability to... 

    Tria Federal (Tria)

    Washington DC
    3 days ago
  • $140k - $190k

    Celestar, a B&A Company, is seeking an Information & Industrial Security Senior Specialist to support the Defense Advanced Research Projects Agency (DARPA) Program Security Services (PSS) task order. If interested and meet the qualifications, we encourage you to apply for... 
    Contract work
    For contractors
    Local area

    Celestar

    Arlington, VA
    1 day ago
  •  ...Services | Government & Public Services | Information Technology, Media, And...  ...lights on” availability, reliability, and security of the CFSAN IT portfolio through the full...  ...regulatory agencies. COMPUTER SECURITY SYSTEMS SPECIALIST - ENGAGEMENT TEAM MEMBER QUALIFICATIONS... 
    Full time
    Contract work
    Temporary work
    For contractors
    Work at office
    Flexible hours

    Prosidian Consultng

    Silver Spring, MD
    3 days ago
  • $140k

    DescriptionInformation Security Analyst III - Q Clearance RequiredSummary:We are seeking an experienced Information Security Analyst III to support the security, assessment, authorization...  ...or college in Cybersecurity, Information Assurance, Information Technology, Computer Science... 

    ActioNet

    Vienna, VA
    5 days ago
  •  ...The SAP Security Specialist I supports the security posture of Special Access Programs (SAPs) by assisting senior staff in various security...  ...monitoring of appropriate security requirements (physical, information, personnel, industrial) for specific programs. • Draft... 

    Chugachmiut

    Arlington, VA
    20 hours ago
  • $102.5k - $187.9k

     ...and Compliance (GRC), EY is seeking SAP Security and GRC professionals who understand...  ...bachelor’s degree in computer science, information systems, information security, or a related...  ...across a full spectrum of services in assurance, consulting, tax, strategy and... 
    Summer holiday
    Flexible hours
    Shift work

    EY

    McLean, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Assurance / Security Specialist. Be the first to apply!