Quantum Sky is searching for a Cybersecurity Engineer to support a Government Program Management Office in Virginia Beach, VA. The work location is on government site in Virginia Beach, Dam Neck Activity (DNA). This role provides cybersecurity engineering support as part of the system development life cycle (SDLC), ensuring security requirements are integrated into the system architecture, design, development, testing, assessment, authorization, delivery, and sustainment. The engineer will apply the cybersecurity risk management framework (RMF) to program information systems in accordance with NIST SP 800-37 and DoDI 8510.01, implementing RMF life cycle steps to achieve system authorization and operation. Responsibilities include building, maintaining, and tracking system’s cybersecurity baselines and security authorization documentation to the Enterprise Mission Assurance Support Service (eMASS), and providing support to cybersecurity architecture and assessment & authorization (A&A) processes, ultimately leading to Authority to Operate (ATO) decisions. The role also involves identifying and employing cybersecurity best practices, creating well-informed plans based on DOD and Navy cybersecurity strategy, managing the adaptation process, and incorporating security management into hardware, software, and applications. Additionally, the engineer will assist Government managers with information security oversight, policy analysis, IT product acquisition, and program execution in accordance with NIST SP 800-39 and DoDI 8500.01. Engagement with Program Office managers and technical stakeholders is crucial for interpreting technical requirements, standards/policies, architectural artifacts, budget development, implementation, auditing, program briefs, and continuous monitoring. The role requires reviewing Assured Compliance Assessment Solution (ACAS) vulnerability scans and analyzing Security Technical Implementation Guides (STIGs) and Security Content Automation Protocol (SCAP) content. Preparation and review of documentation such as Systems Security Plans (SSP), Security Assessment Plans (SAP), Risk Assessment Reports (RAR), A&A packages, and System Requirements Traceability Matrices (SRTMs) are also key responsibilities.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level