Risk Management Framework Cybersecurity Analyst – TS/SCI

Clearance Level
Top Secret/SCI
Category
Cyber Security
Locations
Annapolis Junction, Maryland
Sterling, Virginia
Onsite Workplace
Key Skills For Success

Cybersecurity

Risk Management

Risk Management Framework

REQ#: RQ147550
Requisition Type: Regular
Your Impact

Own your opportunity to serve as a critical component of our nation’s safety and security. Make an impact by using your expertise to protect our country from threats.

Job Description

As a Risk Management Framework Cybersecurity Analyst supporting the Federal Government and the Intelligence Community (IC), you will be entrusted with ensuring our IT engineering solutions meet the highest security standards, that they adhere to all applicable standards, guidelines, and mandates; and that all appropriate documentation necessary to make up a Body of Evidence (BoE) is provided to the Chief Information Security Officer (CISO), and Authorizing Official (AO) to successfully justify the issuing an Authority to Operate (ATO). 

In this role, a typical day may include:

  • Acting as an appointed Information System Security Officer (ISSO) for IC cyber systems being developed by the engineering team.
  • Reporting, documenting, and briefing the status of systems under development, while assuring their successful and timely progression through the client Risk Management Framework (RMF) to the satisfaction of the appointed Information System Security Manager (ISSM), and/or senior govt leadership.
  • Providing clear justification describing the satisfaction all applicable security control implementation as specified by the IC, AO, or NIST-800-53, rev 4 rev 5.
  • Authoring System Security Plans (SSP).
  • Authoring System Security Test Plans (SSTP).
  • Conducting self-assessments of all systems under development
  • Analyzing security controls and the impact changes would introduce to the environment. 

Preparing for and assisting with formal risk assessments conducted by the AO’s designated Security Control Assessors (SCA) while acting as a member of the security assessment test team.

  • Ensuring the remediation of any findings assigned to engineering as documented in the Security Assessment Report (SAR) and its Plan of Actions and Milestones (PO&AM). 
  • Documenting and defending reasoning when waivers are sought, or non-standard remediation solutions are requested for specific security controls.
  • Assisting with the transition of systems granted an ATO to the Operations branch and the assignment of an operations ISSO.
  • Researching remediation options for vulnerabilities identified for systems under development or already in production under an ATO. 

What you’ll need:

  • Active TS/SCI clearance and ability to obtain and maintain a CI poly
  • Education:  Bachelor of Science Degree, or a related technical discipline, or the equivalent combination of education, technical certifications, training, and work experience.
  • DoD 8570 Information Assurance (Technical) IAT Level II certification compliance.
  • Minimum of 3-years IC (SCI) RMF Assessment and Authorization (A&A) experience and the ability to describe the differences between collateral and SCI authorization requirements as they apply to DoD and IC instructions and guidelines.
  • Ability to speak to the intent of all NIST 800-53 security controls.
  • Minimum 1-year hands on experience with the Xacta application.
  • Excellent oral and technical writing skills.
  • Ability to work both independently and as a member of a team
Work Requirements
Years of Experience

5 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

CompTIA A+ - CompTIA - CompTIA

Travel Required

Less than 10%

Citizenship

U.S. Citizenship Required

About Our Work

We are GDIT. The people supporting some of the most complex government, defense, and intelligence projects across the country. We deliver. Bringing the expertise needed to understand and advance critical missions. We transform. Shifting the ways clients invest in, integrate, and innovate technology solutions. We ensure today is safe and tomorrow is smarter. We are there. On the ground, beside our clients, in the lab, and everywhere in between. Offering the technology transformations, strategy, and mission services needed to get the job done.

COVID-19 Vaccination

GDIT does not have a vaccination mandate applicable to all employees. To protect the health and safety of its employees and to comply with customer requirements, however, GDIT may require employees in certain positions to be fully vaccinated against COVID-19. Vaccination requirements will depend on customer site requirements.

GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.