layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
ENS Solutions, LLC
Annapolis Junction, MD, US; Sterling, VA, US
Source: ENS Solutions, LLC careers · View original posting
From ENS Solutions, LLC's posting. “We” and “our” refer to the employer.
Our work depends on a Risk Management Framework Cybersecurity Analyst joining our team to support Government activities. As a RMF Cybersecurity Analyst supporting the Federal Government and the Intelligence Community (IC), you will be entrusted with ensuring our IT engineering solutions meet the highest security standards, that they adhere to all applicable standards, guidelines, and mandates; and that all appropriate documentation necessary to make up a Body of Evidence (BoE) is provided to the Chief Information Security Officer
(CISO), and Authorizing Official (AO) to successfully justify the issuing an Authority to Operate (ATO).
Acting as an appointed Information System Security Officer (ISSO) for IC cyber systems being developed by the engineering team.
Reporting, documenting, and briefing the status of systems under development while assuring their successful and timely progression through the DIA Risk Management Framework (RMF) to the satisfaction of the appointed Information System Security Manager (ISSM), and/or senior govt leadership.
Providing clear justification describing the satisfaction of all applicable security control implementation as specified by the IC, AO, or NIST-800-53, rev 4 rev 5.
Authoring System Security Plans (SSP).
Authoring System Security Test Plans (SSTP).
Conducting self-assessments of all systems under development
Analyzing security controls and the impact changes would introduce to the environment.
Preparing for and assisting with formal risk assessments conducted by the AO’s designated Security Control Assessors (SCA) while acting as a member of the security assessment test team.
Ensuring the remediation of any findings assigned to engineering as documented in the Security Assessment Report (SAR) and its Plan of Actions and Milestones (PO&AM).
Documenting and defending reasoning when waivers are sought, or non-standard remediation solutions are requested for specific security controls.
Assisting with the transition of systems granted an ATO to the Operations branch and the assignment of an operations ISSO.
Researching remediation options for vulnerabilities identified for systems under development or already in production under an ATO.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: