This position supports the NUWCDIVNPT in a Junior-Mid Risk Management Framework (RMF) Information Systems Security Engineer (ISSE) role. The primary focus is on performing tasks related to Assess and Authorize (A&A) to maintain Authorizations to Operate (ATOs) for systems, including applications, networks, and devices. The role involves providing a disciplined, structured, and flexible process for managing security and privacy risk, encompassing information security categorization, control selection, implementation, and assessment, system and common control authorizations, and continuous monitoring. The ISSE will become familiar with systems by reviewing Assessment and Authorization (A&A) System Security Plans, identifying issues, executing Security Assessment Plans, processing Security Test Reports, reviewing POA&Ms, and developing/performing Risk Assessment analysis. The role requires staying updated on Navy RMF policies and procedures and reviewing relevant DoD, DON, and NAVSEA CS-related documentation. The ISSE will conduct independent security control assessments according to NIST SP 800-53, 800-53A, CNSSI 1253, and the RMF framework in NIST SP 800-37. Clear articulation of requirements in written documentation such as Security Plans, Contingency Plans, Business Impact Analyses, etc., is essential. Guidance and training in eMASS will be provided to team members. Strong organizational and time-management skills, including multitasking, working individually and with a team, maintaining a positive attitude, being self-motivated, reliable, trustworthy, and possessing strong interpersonal and diplomatic skills, are crucial. The role also involves attending stakeholder meetings, capturing and tracking action items, and ensuring timely completion.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level