Lead Information Systems Security Engineer (ISSE) - Navy Yard - Washington, DC
Serco North AmericaAbout the role
Position Description
Are you an ISSE looking for a place where you can make a difference every day? Serco is the place for you! We have an exciting opportunity supporting the United States Navy and our CNIC N6 program at the Navy Yard in Washington, DC - (On-site 5 days a week, Mon-Fri)
CNIC Regional Offices enable improving operational performance and cost reductions through business process definition, analysis, and development of technical capabilities which automate process or improve transparency for analytics and decision making.
This CNIC N6 Lead Information System Security Engineer (ISSE) for the Risk Management Framework (RMF) Assessment and Authorization (A&A) process, is tasked with developing RMF security authorization packages to obtain Authorizations to Operate (ATOs) for various isolated enclaves that support the NDW Region. These enclaves support many different missions, including, but not limited to, Anti-Terrorism/Force-Protection (AT/FP), access control, video monitoring, and mobile radio systems.
This position is contingent upon your ability to transfer & maintain your DoD Secret security clearance.
In this role, you will:
- Support CNRNDW ISSM / CIO with RMF package development as the lead ISSE.
- Assemble and review all required documentation as outlined by the ISSM and CNIC for the RMF packages.
- Tailor security controls out of National Institute of Standards and Technology (NIST) SP 800-53 rev 4 for the systems.
- Assist with updating policy and documentation along with maintaining compliance with NIST SP 800-53 rev 4 throughout the RMF lifecycle.
- Develop a Security Assessment Plan (SAP) in accordance with the Navy RMF Process Guide ver. 3.1 and using the templates provided in the RMF Knowledge Service (KS).
- Assess and implement security controls, Security Technical Implementation Guides (STIGs), and Assured Compliance Assessment Solution (ACAS) scans in accordance with the SAP.
- Gather ACAS, STIG, Security Content Automation Protocol (SCAP) files, and other related package artifacts and report any discrepancies to the program.
- Build risk assessment report (RAR) incorporating all findings discovered in testing and documenting an analysis of each finding.
- Verify traceability between system authorization data flow, boundary diagrams, Hardware, Firmware, Software, Ports, Protocols and Services (PPS) lists, and ACAS scan.
- Update and help implement the status of all security controls, enhancements, and control correlation identifiers (CCIs) in eMASS.
- Make data entries into eMASS record for assigned systems and track RMF process timelines.
- Prepare for and conduct RMF-related briefings at meetings with internal and external representatives.
- Interact frequently with internal personnel and outside representatives at various levels.
- Assist in developing schedules and plans of actions and milestones (POA&M) for producing deliverable products and reports within customer-directed timelines.
- Coordinate with field activities, obtaining statuses and providing RMF guidance for all CNIC CNRNDW packages.
GET TO KNOW YOUR RECRUITER!
https://serco.kzoplatform.com/player/medium/2794495008890164823Qualifications
To be successful in this role, you will have:
- An active DoD Secret security clearance
- 8570 IAT Level II compliant certification
- A Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related discipline
- Minimum 8 years of experience in an Information Technology or Cybersecurity environment supporting the Department of Defense
- Minimum 5 years of experience with EMASS, RMF, ACAS, STIG's, & VRAM
- Recent experience with the RMF and NIST SP 800-53 rev 4 as an ISSE
- Recent experience with developing A&A documentation & obtaining ATO's
- Knowledge of US naval communication suites in areas such as LAN, WAN, and RF paths
- Familiarity with the DoD Information Technology Portfolio Repository-Navy (DITPR-DON)/DON Application and Database Management System (DADMS) and the requirements for their use
- Proficiency in at least 2-3 of the following disciplines
- Microsoft operating systems
- Microsoft SQL
- Red Hat Linux
- Cisco
- Aruba Wireless
- Lenel (preferred)
Additional desired experience and skills:
- 8570 IAM Level III compliant certification
If you are interested in supporting and working with passionate Serco team- then submit your application now for immediate consideration. It only ta
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s