Lucayan Technology Solutions LLC logo
Lucayan Technology Solutions LLC
Posted 39 days agoVerified live 10h ago

RMF / Cybersecurity Compliance Specialist (Pipeline)

Brief overview

Remote
Clearance requiredU.S. government
DoD Risk Management Framework (RMF)Enterprise Mission Assurance Support Service (eMASS)Vulnerability ManagementContinuous MonitoringACASSCAPDISA STIGsSTIG ViewerPlan of Actions and Milestones (POA&M)CompTIA Security+DoD Cybersecurity RequirementsFISMA Reporting

About the company

Lucayan Technology Solutions LLC logo
Lucayan Technology Solutions LLClucayantechnology.com

Lucayan Technology Solutions LLC is a CVE and Hub Zone Certified, (Disabled) Veteran Owned Small Business offering cutting edge, integrated Information Technology solutions.

Job description

Summary

Lucayan Technology Solutions LLC delivers secure, innovative solutions supporting national defense and intelligence missions. The RMF / Cybersecurity Compliance Specialist will support the U.S. Army Corps of Engineers Walla Walla Business Intelligence program by managing Risk Management Framework documentation, cybersecurity compliance, continuous monitoring, vulnerability management, and authorization artifacts. The role will coordinate with developers, DevSecOps personnel, technical leadership, and Government stakeholders to maintain compliance and support cloud migration.

Responsibilities

  • Develop, update, and maintain WWBI Risk Management Framework authorization documentation, including the System Security Plan (SSP), Continuity of Operations Plan (COOP), Incident Response Plan (IRP), System Design Documents, and related authorization artifacts
  • Manage and document program-specific security controls applicable to the WWBI system, and support security requirements associated with Personally Identifiable Information (PII)
  • Maintain documentation defining the WWBI authorization boundary, including applicable hardware, software, ports, protocols, interfaces, and data flows
  • Coordinate cybersecurity documentation and compliance activities associated with WWBI's migration into the CWBI Cloud and eventual incorporation into the CWBI authorization boundary
  • Maintain WWBI compliance records within the Enterprise Mission Assurance Support Service (eMASS), including uploading, mapping, organizing, and maintaining required RMF documentation, security-control evidence, implementation statements, and supporting artifacts
  • Support execution of the WWBI continuous-monitoring program, including coordinating and/or performing required ACAS and SCAP security scans, and maintaining a compliance score of at least 90% for applicable SCAP scans
  • Import and maintain security-scan results within DISA STIG Viewer and eMASS; analyze identified vulnerabilities and coordinate remediation activities with software developers and Government technical personnel
  • Track Critical and High findings for immediate remediation, Moderate findings for remediation within 60 days, and Low findings for remediation within 120 days; document approved exceptions and outstanding findings within the Plan of Actions and Milestones (POA&M)
  • Develop, maintain, and submit the quarterly POA&M report detailing open, remediated, and outstanding security findings, and support quarterly updates to the RMF documentation package
  • Provide ACAS/SCAP scan results and associated STIG Viewer files following required scans, and maintain current system security, network topology, logical, and data-flow documentation in coordination with the development team
  • Complete and maintain security-control checklists required by the USACE CWBI Cloud environment, and monitor changes to CWBI cybersecurity requirements to coordinate implementation of new or modified requirements
  • Support annual Federal Information Security Management Act (FISMA) reporting requirements and associated forms, checklists, and documentation
  • Support compliance with applicable DoD Security Technical Implementation Guides (STIGs), Army cybersecurity requirements, and USACE policies, coordinating with developers and DevSecOps personnel to ensure applications and infrastructure remain compliant through modernization and cloud-migration activities

Skills

  • U.S. Citizenship required
  • Demonstrated experience supporting the DoD Risk Management Framework (RMF), including developing and maintaining RMF authorization packages and cybersecurity documentation
  • Experience using Enterprise Mission Assurance Support Service (eMASS)
  • Knowledge of DoD, U.S. Army, and/or USACE cybersecurity requirements and processes
  • Experience with vulnerability management, security controls, POA&Ms, and continuous monitoring
  • Experience with ACAS, SCAP, DISA STIGs, and STIG Viewer
  • Ability to interpret technical vulnerability findings and coordinate remediation with software-development and infrastructure teams
  • Strong technical writing and documentation skills, with strong organizational skills and the ability to manage multiple recurring compliance requirements and deadlines
  • Ability to communicate effectively with technical personnel, program leadership, and Government stakeholders
  • Active federal background investigation at the Tier 1 level or higher prior to beginning contract performance
  • Ability to obtain and maintain CompTIA Security+ or a DoD-approved equivalent within six months of the contract start date, as applicable to the assigned DoD 8140 work role
  • Active Tier 1 (or higher) background investigation prior to start
  • CompTIA Security+ or a DoD 8140-approved equivalent required within six (6) months of contract start
  • Previous experience supporting USACE systems or applications
  • Experience supporting DoD systems through ATO authorization and continuous monitoring
  • Experience with AWS GovCloud or other DoD-authorized cloud environments
  • Familiarity with DevSecOps, GitHub, secure software-development pipelines, and application modernization
  • Experience supporting cloud migration of systems operating under an existing RMF authorization
  • Experience with FISMA reporting
  • CISSP or another advanced DoD-recognized cybersecurity certification desired

Qualifications

Must Haves

  • U.S. Citizenship required
  • Demonstrated experience supporting the DoD Risk Management Framework (RMF), including developing and maintaining RMF authorization packages and cybersecurity documentation
  • Experience using Enterprise Mission Assurance Support Service (eMASS)
  • Knowledge of DoD, U.S. Army, and/or USACE cybersecurity requirements and processes
  • Experience with vulnerability management, security controls, POA&Ms, and continuous monitoring
  • Experience with ACAS, SCAP, DISA STIGs, and STIG Viewer
  • Ability to interpret technical vulnerability findings and coordinate remediation with software-development and infrastructure teams
  • Strong technical writing and documentation skills, with strong organizational skills and the ability to manage multiple recurring compliance requirements and deadlines
  • Ability to communicate effectively with technical personnel, program leadership, and Government stakeholders
  • Active federal background investigation at the Tier 1 level or higher prior to beginning contract performance
  • Ability to obtain and maintain CompTIA Security+ or a DoD-approved equivalent within six months of the contract start date, as applicable to the assigned DoD 8140 work role
  • Active Tier 1 (or higher) background investigation prior to start
  • CompTIA Security+ or a DoD 8140-approved equivalent required within six (6) months of contract start

Nice to Haves

  • Previous experience supporting USACE systems or applications
  • Experience supporting DoD systems through ATO authorization and continuous monitoring
  • Experience with AWS GovCloud or other DoD-authorized cloud environments
  • Familiarity with DevSecOps, GitHub, secure software-development pipelines, and application modernization
  • Experience supporting cloud migration of systems operating under an existing RMF authorization
  • Experience with FISMA reporting
  • CISSP or another advanced DoD-recognized cybersecurity certification desired

Benefits

  • US-based remote position
  • Full-Time

More jobs like this