About The Position

Sandy Mac Evolution LLC is seeking a qualified Information Systems Security Engineer (ISSE) / Systems Security Analyst to support the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO) in Guam. The selected candidate will provide cybersecurity and Risk Management Framework (RMF) support for NAVFAC Marianas information systems and Facility-Related Control Systems (FRCS). This position supports the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, documentation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools.

Requirements

  • Must be a United States citizen.
  • Must possess an active Tier 5 (T5) security clearance or be able to obtain the required T5 clearance prior to onboarding/hiring.
  • Must meet DoD Manual 8140.03 foundational qualification requirements for: Work Role Code (WRC) 461 – Systems Security Analyst, Intermediate proficiency level or higher.
  • Must possess and maintain at least one qualifying DoD 8140 certification appropriate to the required work role and proficiency level, including: CompTIA Security+, Certified Cloud Security Professional (CCSP), CompTIA Cloud+, GIAC Global Industrial Cyber Security Professional (GICSP), GIAC Information Security Fundamentals (GISF), GIAC Security Essentials (GSEC), Or another approved certification meeting the applicable DoD 8140 qualification requirements.
  • Demonstrated knowledge and experience supporting the Department of Defense Risk Management Framework.
  • Experience developing, maintaining, or supporting RMF authorization packages.
  • Experience with cybersecurity vulnerability assessment and compliance tools.
  • Knowledge of NIST security controls, DoD cybersecurity policies, STIGs, vulnerability management, and continuous monitoring.
  • Strong written and verbal communication skills.
  • Ability to develop professional cybersecurity documentation, reports, policies, procedures, and briefings.
  • Ability to work independently and effectively coordinate with Government personnel, technical teams, system owners, and other stakeholders.

Nice To Haves

  • Five or more years of experience supporting DoD Risk Management Framework activities is recommended.
  • One or more years of experience supporting Facility-Related Control Systems (FRCS), Industrial Control Systems (ICS), Operational Technology (OT), or related cybersecurity engineering activities is recommended.
  • Experience with eMASS
  • ATO packages
  • ACAS
  • Nessus
  • SCAP
  • Evaluate-STIG
  • STIG checklists
  • VRAM
  • POA&M development and management
  • Continuous monitoring
  • Configuration management
  • Cybersecurity engineering for FRCS, ICS, or OT environments
  • Previous experience supporting NAVFAC, the Department of the Navy, Department of Defense, or another federal agency is highly desirable.

Responsibilities

  • Support all phases of the Department of Defense Risk Management Framework (RMF), including RMF Steps 1 through 6.
  • Develop, maintain, and manage RMF authorization packages within the Enterprise Mission Assurance Support Service (eMASS).
  • Support Authorization to Operate (ATO) activities for Facility-Related Control Systems (FRCS).
  • Conduct annual reviews and maintain required cybersecurity authorization documentation.
  • Develop and maintain FRCS cybersecurity policies, procedures, Standard Operating Procedures (SOPs), and supporting documentation.
  • Apply NIST SP 800-53 security controls and applicable Department of Defense cybersecurity requirements.
  • Conduct vulnerability assessments and analyze results using tools such as ACAS and Nessus.
  • Perform Security Technical Implementation Guide (STIG) assessments using SCAP, Evaluate-STIG, manual STIG checklists, and associated compliance tools.
  • Develop, maintain, and track Plans of Action and Milestones (POA&Ms).
  • Support continuous monitoring and Security Lifecycle Management activities.
  • Review vulnerability scan results, system logs, security configurations, and cybersecurity documentation.
  • Utilize Vulnerability Remediation Asset Manager (VRAM) and other DoD cybersecurity tools.
  • Perform on-site RMF validation activities and support RMF Step 4 security assessments.
  • Conduct security impact analyses associated with system configuration changes.
  • Participate in Configuration Management and Configuration Control Board activities.
  • Support cybersecurity incident response and CERT-related activities as required.
  • Participate in applicable cybersecurity on-call or incident-response rotations.
  • Prepare and maintain RMF status reports, cybersecurity documentation, briefings, and other required deliverables.
  • Coordinate with system owners, engineers, administrators, Government personnel, and other cybersecurity stakeholders.
  • Support cybersecurity requirements for industrial control systems, operational technology, and Facility-Related Control Systems throughout the NAVFAC Marianas environment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service