Summary: Vector Planning & Services (VPSI) presents an exciting opportunity for a systems engineer with experience in IA certification and accreditation.
Primary Responsibilities:
· Providing leadership, team coordination, and subject matter expertise in preparing and validating Certification and Accreditation (C&A) packages. This includes DIACAP or RMF accreditation package and artifact generation, planning and executing security test and evaluation (ST&E), analyzing test results, drafting Risk Assessment Reports (RAR), C&A Plans, Plan of Actions and Milestones (POAM’s), crafting mitigation statements, eMASS entry, and any other documents that are required as part of the NIST 800-53 and 800-37 Information Assurance (IA) Control and Risk Assessments
· Review security requirements, products, configurations and IA architectures for compliance with DoD policies
· Perform penetration testing, analyzing systems for STIG compliance
· Develop and execute security test plans and assessing the IA risk of IT systems.
· Participate in collaboration meetings; act as a trusted agent to program managers and IA practitioners and track critical IA processes
· Maintain and update Technical Standards, checklists, guidelines, and instructions based on new DoD/DON/industry policies and instructions.
· Coordinate with government engineers to oversee, maintain, develop, and implement technical standards within the Human Factor Domain.
· Provide security related advice and assistance to system engineers and program managers on security related matters and develop security related procedures, policies, and technical recommendations, as required
· Provide System Engineering support with acquisition programs of record, including in-depth review of engineering documentation.
· Review how programs plan to ensure human capability is factored into total system performance in the software acquisition process and the systems engineering lifecycle of all NAVWAR systems.
· Conduct independent assessments at technical program elements (e.g., systems engineering technical reviews, milestone decision reviews, certification events, and independent reviews) and develop Risk, Issue and Opportunity (RIO) assessments.
· Review Manpower Personnel Training & Education requirements in conjunction with program requirements.
Qualifications/Skills/Minimum Qualifications:
· Current Secret level clearance
· Experience in assessing a network and/or systems using IA automated tools such as Nessus, SCAP, and any applicable Security Technical Implementation Guides (STIGs) in accordance with DISA requirements
· Knowledge of DoD 8510.01 and the Department of Navy DIACAP Handbook and experience developing Certification and Accreditation (C&A) documentation
· Knowledge of the Department of Navy (DoN) RMF Process Guide.
· In depth knowledge and experience with the NIST 800 series
· Must be familiar with EMASS and C&A package entry
· Familiarity with ACAS, VRAM, HBSS and WSUS
Education and Certifications:
· Bachelor's degree in Computer Science or a related technical field
NQV certification required