The Security Control Assessor (SCA) will fulfill a variety of cybersecurity functions, including System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (PIT) assessment and authorization, Information Assurance and Technical Security for AIS, Information Technology (IT) Network Administration & Support, and Information System Security Officer support. The SCA will perform IA tasks to ensure the DARPA IA program meets National, DoD, and DARPA IA standards, protecting and defending DARPA information and Information Systems (IS) by ensuring confidentiality, integrity, availability, authentication, and non-repudiation. The Senior Cybersecurity Specialist possesses experience in successfully participating in DoD Special Access Program Joint Certification and Accreditation, Assessment, and Approval events for DoD Joint cyber ranges and/or jointly accredited SAP information systems. The DARPA systems to be protected include systems that process and store information from controlled unclassified (CUI) up to Top Secret, including SAP and SCI caveats/compartments. Duties include, but are not limited to: meeting and participating in Defense Information System Agency (DISA), National Security Agency, and USCBYERCOM Computer Network Defense Program (CNDSP) and CBYERCOM Computer Readiness Inspections (CCRI); experience with network security devices, classified Local Area Networks, Wide Area Networks, public key infrastructure (PKI), virtual machines, and end-point security solutions. The SCA must be thoroughly familiar with, understand, and be able to apply numerous DoD and CNSS policies and directives. Ensure system security requirements are addressed during all phases of DARPA program life cycles. Plan, prepare, and execute inspections, authorization and approval (A&A) events for all classifications of networks, including developing and reviewing Automated Information System Authorization and Approval Packages. Develop, review, endorse, and recommend action for system certification documentation. Conduct quality control of system accreditation packages within 3 business days of receipt. Process authorization and approval or denial documentation within 10 business days of receipt of a complete package. Conduct security control assessments to evaluate the extent to which controls are implemented correctly, operating as intended, and producing the desired outcome. Provide an assessment of the severity of weaknesses or deficiencies and recommend corrective actions. Analyze and make recommendations in support of DARPA accredited network Configuration Control Board cases within 10 calendar days of case validation. Monitor activities of DARPA accredited networks and DARPA DAO Accredited performer networks. Provide advice, assistance, and analysis of threats, vulnerabilities, and risk mitigation and acceptance recommendations. Conduct certification tests to verify functional features and assurances. Work collaboratively with the MSO/Information Technology Directorate (ITD) in the authorization and approval and continuous monitoring of DARPA unclassified and classified networks. Review and recommend changes or amplification of policy, procedures, and strategy development. Evaluate Information Assurance (IA) products and provide written recommendations. Evaluate information technology (IT) vulnerabilities to assess whether additional safeguards are prudent. Develop and maintain a formal, written Information Systems Security Program SOP. Ensure all Information System Security Officers (ISSO), network administrators, and other AIS personnel receive necessary training. Ensure development and implementation of an information security education, training, and awareness program. Maintain a repository for all system certification/accreditation documentation and modifications. Coordinate AIS security inspections, tests, and reviews. Prepare policies and procedures for responding to security incidents and for investigating and reporting security violations and incidents. Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered. Assess changes in a system, its environment, or operational needs that could affect accreditation. Ensure configuration management (CM) for security-relevant AIS software, hardware, and firmware is maintained and documented. Perform system audits and work closely with system administrators to ensure current security measures are sufficient and in compliance. Perform, and conduct training as required, for the execution of secure file transfers/trusted downloads. Provide technical advice and assistance, and perform technical oversight on telecommunications requirements. In coordination with ITD Emergency Management, review and provide AIS security relevant input to DARPA Emergency/Disaster plans and procedures.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior