2 часа назад
Cybersecurity Analyst / ISSO (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity Analyst / ISSO (AI): Leading cybersecurity risk management and RMF authorization for enterprise systems with an accent on AI/ML capability assessment and zero-trust architecture. Focus on managing POA&M remediation, ensuring DoD/NIST compliance, and validating security controls via STIGs.
Location: Hybrid in Stafford, VA
Company
provides strategic and technical cybersecurity support for the Department of Defense.
What you will do
- Lead cybersecurity risk management efforts, specifically assessing AI and machine learning capabilities and their impact on enterprise risk.
- Oversee RMF authorization activities and manage the strategic burn-down of complex POA&Ms across multiple systems.
- Ensure full compliance with DoD cybersecurity directives, NIST standards, and USMC continuous monitoring requirements.
- Evaluate system architectures through a zero-trust lens and implement Cyber Tasking Orders (CTOs).
- Validate security controls and STIG compliance using DISA STIG Viewer and SCAP Compliance Checker.
- Develop organizational cybersecurity policies, Incident Response Plans, and continuous monitoring strategies.
Requirements
- Experience assessing AI/ML risks and familiarity with emerging DoD AI security guidelines.
- Ability to interpret and direct programmatic responses to MFCC, DCDC, and Cyber Tasking Orders.
- Expertise in navigating eMASS and leading systems through the complete RMF Assess and Authorize (A&A) lifecycle.
- Deep understanding of NIST SP 800-53, CNSSI 1253, NIST SP 800-161, NIST SP 800-162, and DoDI 8510.01.
- Proficiency in manually validating STIG/SRG requirements on Windows, Red Hat Linux, and Cisco systems.
- Must be based in or able to work hybrid in Stafford, VA.
Nice to have
- 4-8 years of progressive experience in DoD cybersecurity, information assurance, or Computer Network Defense (CND).
- Active Secret security clearance.
- DoD 8140/8570.01-M Baseline Certification IAM Level II or III (e.g., CISSP, CISM, CAP/CGRC).
- CSSP Auditor/Manager baseline certification.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →