What are the responsibilities and job description for the IT Security Assessment and Authorizations Consultant/SME (SETA) position at Twenty8 Technology, LLC?
Twenty8 Tech is hiring Senior Subject Matter Experts to help direct and advise activities at DARPA in Arlington, VA. If you're looking for a challenging and dynamic environment have a look below. Looking forward to hearing from you!
Job Summary
This role will provide IT Security Assessment and Authorization Support and SME advisory to include:
a. Collaborate with the ITD Chief of Cybersecurity to conduct security assessments and authorizations, providing expertise and support throughout the A&A process.
b. Demonstrate and apply an understanding of various Federal, DOD, and IC policies and implementations of the Risk Management Framework (RMF) for information systems, Committee on National Security Systems (CNSS) 1253, DOD 8510.01, Intelligence Community Directives (ICD) 503, etc..
c. Provide expert advisement on the RMF lifecycle of DARPA information systems between various operations, security, ISSM, ISSO, and SCA personnel.
d. Advise the Chief of Cybersecurity and provide contract oversight of the process of SPA&A activities.
e. Advise the implementation of continuous monitoring of security and privacy control implementations.
f. Provide expert advisement of policy and procedure changes that have occurred since the system was last authorized and recommend appropriate actions to address any deltas.
g. Track and report the life cycle status of all Information System (IS) authorizations to operate, test, and connect as well as subsystems.
h. Provide policy and oversight recommendations on information technology concepts used in the evaluation of security performance, integrity, residual risk, and overall readiness of applications, communication systems, hardware, software, satellite control systems, information processing systems, and Platform Information Systems (PIT).
i. Provide Policy and oversight recommendations on RMF assessment techniques and procedures to assess compliance and security performance of protective measures (e.g., Information Assurance (IA) controls, Security Technical Implementation Guides (STIGs), USCYBERCOM CTOs), etc.
j. Participate and act as a liaison between relevant Defense Industry Base and government cybersecurity, security assessment, and Special Access Program IT conferences and working groups.
k. Provide Assessment and Authorization policy and oversight expertise on Cross Domain Solution (CDS) technologies employing all types of CDS, either in in a classified compartmentalized enterprise environment, or “point to point” in support of isolated IT architectures.
l. Ensure system security requirements are addressed during all phases of DARPA program lifecycles (concept development, Request for Information (RFI), Request for Proposal (RFP), or Broad Agency Announcement (BAA), Proposal, Selection, Award, Closeout, Transition, etc.).
m. Facilitate communication and meetings with DARPA Tech Offices to ensure that Assessment and Authorization services align with agency needs and timelines.
n. Participate in the preparation and oversight of CSSP and CORA external audits (or any internal/external inspection/audit) and ensuring that that all DARPA IT is correct and current in all of their supporting assessment and authorization documentation.
o. Serve as primary liaison between the ITD Government Authorizing Official and the IT Support Services Contract Program Management Teams, to include Classified Support, Unclassified Support and Security Control Assessor teams.
p. Collaborate with Agency stakeholders, including IT staff, program managers, and security officials.
q. Coordinate with other contractors and government agencies to ensure cybersecurity architectures and engineering solutions are integrated and aligned with agency and DOD goals as well as federal mandates.
r. Serve as a Product Manager under the SAFe construct for A&A projects developing acceptance criteria defining desirable, viable, feasible, and sustainable solutions that meet customer needs.
s. Manage the execution of high level ITD projects under the guidance of the Government.
Minimum Requirements
Must have demonstrated 10 years of IT, information systems security, cybersecurity, and security privacy assessment and authorization (SPA&A) experience with increasing responsibilities.
Display at least two (2) years’ experience managing Sensitive Compartmentalized Information (SCI) and Special Access Program (SAP) enclaves with DOD or DARPA specific experience being highly desirable.
Experience and understanding of FedRAMP and cloud services providers. DOD 8140.01, Cyber Workforce Advance qualification (DCWF code 651) required, with Scaled Agile Framework (SAFe) or similar Agile methodology certification preferred.
Minimum Top-Secret clearance, eligible for access to SCI and SAP.
Job Type: Full-time
Pay: $175,000.00 - $200,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Professional development assistance
- Vision insurance
Compensation Package:
- Bonus opportunities
- Performance bonus
Schedule:
- Monday to Friday
Experience:
- SCI and SAP Environments: 2 years (Preferred)
- IT A&A: 10 years (Preferred)
- FedRAMP: 5 years (Preferred)
License/Certification:
- DOD 8140 level cert (Preferred)
- Cyber Workforce Advance qualification (Preferred)
Security clearance:
- Top Secret (Preferred)
Work Location: In person
Salary : $175,000 - $200,000