DCE Cybersecurity Analyst (IMC00592)
Location: |
Fort Shafter, HI
|
Travel Required: |
Minimal
|
---|---|---|---|
Level/Salary Range: |
Dependent on qualifications
|
Position Type: |
Full-Time
|
Date Posted: |
|
Posting Expires: |
Until filled
|
Mandatory Job Requirements: |
|
||
Applications Accepted By: |
Email: Michelle Might, Corporate Recruiter, michelle.might@imcva.com Email Subject Line: DCE Cybersecurity Analyst (IMC00592) |
The DCE cybersecurity analyst is responsible for all areas of IT cybersecurity and assisting the USARPAC G61 (CSPMO) in managing missions intended to preserve the ability to use blue cyberspace capabilities and protect data, networks, cyberspace-enabled devices, and other designated systems by defeating ongoing or imminent malicious cyberspace activity. This position will serve as the G6 lead for all matters related to the defense of the cyber domain as it pertains to USARPAC.
Duties/Responsibilities: This position will include, but is not limited to, the following tasks:
- Oversee and assume accountability of day-to-day security operations of cybersecurity tasks.
- Develop and maintain compliant security architecture by implementing current policies, procedures, and standards to provide a layered approach to cybersecurity.
- Evaluate policies against applicable standards for regulatory compliance.
- Assess USARPAC physical, personnel, facility, information systems, through policies and controls IAW Army Regulations, Department of Defense (DoD) Directives and Instructions.
- Integrate the current program into existing warfighting functions, plans, and policies.
- Develop and plan for Cyber Mission Forces integration.
- Develop cyber training objectives and maximize use during exercises.
- Manage the Cyber Battle Rhythm.
- Maintain awareness of all cyber activities in the Pacific Area of Responsibility (AOR).
- Identify Cyber Theater Critical Assets (TCA) for USARPAC and Joint leadership awareness.
- Provide COMSEC distribution to appropriate authorized agency and organization in the Pacific Theater.
- Disseminate OPORDs/CVEs from INDOPACOM to USARPAC supporting commands for action and reporting.
- Work with system owners to maintain current Authorities to Operate in a manner compliant with Federal Information Security Management Act (FISMA), DoD Risk Management Framework (RMF) and National Institute of Standards and Technology (NIST) guidance.
- Represent the USARPAC G6 and CG in briefings and meetings regarding cybersecurity posture of the AOR.
- Coordinate with Offensive and Defensive Cyber team in exercise or contingency operations.
The Analyst will:
- Attend technical meetings as requested by the Govt. Cybersecurity Program Manager providing comment and recommendations were required.
- Assist in the review and drafting of policy, SOPs and directives as required.
- Ensure appropriate Secure Technical Implementation Guidelines (STIG) are maintained through monthly POAM review.
- Review Plans of Action & Milestones (POA&M) for currency and mitigations to identified vulnerabilities.
- Provide recommendations on Cybersecurity perspectives for proposed changes, initiatives, and projects.
- Review change requests, system connection requests, and requests for exception to policy to DODIN-AP networks. Determine associated risk and draft Memorandums for Record for all requests with recommendation to the Authorizing Official via CSPMO review.
- Validate assets are in compliance with Army Gold Master configuration, DISA STIG compliant, and meet all requirements of the Change Request process prior to recommending connection to the DODIN-AP network.
- Review all change requests for completeness, accuracy, and residual risk prior to providing approval Memorandum for Request to the Cybersecurity SME.
The Analyst will support C&A activities including:
- Ensure the Network Enterprise Centers and USARPAC controlled assets comply with eMASS and AO direction for all connections to the DODIN-AP NIPR and SIPR in support of their Authority to Connect (ATC) and Authority to Operate (ATO).
The Analyst will support the CCRI and OIP processes including:
- Provide support to the CCRI assessment team during scheduled and unscheduled inspections.
- Ensure Network Enterprise Command’s (NECs) and Regional Cyber Center (RCCs) are in compliance with all applicable CCRI requirements (e.g. Technical, CND Directives, Contributing Factors, etc.), as command team member for the Site Assist Visit (pre-CCRI inspection). Report status, findings, and results.
- Support post-CCRI finding remediation. Assist with the planning, execution, and documentation of CCRI finding remediation activities.
- Provide support to the Organizational Inspection Program (OIP) prior to, during and following all OIP inspections.
- Evaluate command personnel during all OIP inspections. Document all findings; teach and train personnel on how to correct findings and provide recommendations to preclude recurrence of findings.
Cybersecurity support for exercises:
- Review, analyze, and recommend connections for Authorizing Official (AO) approval.
- Work with exercise participants to develop proper documentation for presenting to the AO.
- Participating in pre-exercise meetings as directed by the government.
Basic Required Qualifications and Skills: Note: These are mandatory items that all candidates must have when making application to IMC for this position. Please ensure that your submission addresses each of these requirement items. Candidates without these required elements will not be considered.
- At start date, must possess IAM Level III certification in ACTIVE status. One or more of the following certifications are acceptable:
- GSCL – GIAC Security Leadership Certification
- CISM – Certified Information Security Manager
- CISSP – Certified Information Systems Security Professional (or Associate)
- 7+ years cybersecurity experience preferably working directly with the Army.
- 5+ years knowledge of DoD and Army cybersecurity policy.
- Experience with Mission Partner Environment enclave.
- Experience with USARPAC AOR.
- Experience in presenting and arguing for acceptance of new concepts to senior leadership.
- Strong interpersonal and relationship building skills.
- Ability to evaluate data to quickly identify problems, issues, and gaps.
- Excellent oral, written, and verbal communication skills, with experience addressing senior leaders.
- Pursuant to a government contract, this specific position requires U.S. Citizenship.
- All applicants must have current DoD TS clearance with SCI eligibility day one and prior to entry on duty.
Desired Qualifications and Skills: It is desirable that the candidate has the following qualifications:
- Capable of conducting technical research on cybersecurity issues and products and producing a whitepaper for leadership review.
- Experience working with USARPAC and INDOPACOM AOR and familiar with the command structures.
- Experience in briefing senior executive leaders and General Officers.
- A relevant educational degree in one of the follow fields: Computer Science, Information Systems, Information Technology, Cyber Security, Statistics, Business Administration, Systems Engineering, Computation Science, Computer Engineering, Electrical Engineering, Data Analytics, Information Technology, Information Security and Assurance, Mathematics, Software Engineering, Systems Engineering, or Telecommunications.
- Experience with Cloud Cyber Security.
Background Information:
Innovative Management Concepts, Inc. (IMC), a Service-Disabled, Veteran-Owned Small Business, provides a broad range of information technology services to government and commercial clients. Since its founding in 1989, IMC has offered solutions and expertise in: IT operations and maintenance, cyber security, systems and network engineering and support services, data management, cloud/hosting services, software engineering and development, website services, software quality assurance and testing (including IV&V), and project management. IMC is certified in International Organization for Standardization (ISO) 9001 Quality Management, ISO 27000 Information Security Management System, ISO 20000-1 Information Technology Service Management, and ISO 14001 Environmental Management Systems. Find out more about IMC at www.imcva.com.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law.