Abile Headquarters

  • Sr. Information Assurance Analyst

    Job Locations US-VA-Lorton
    Posted Date 6 hours ago(11/15/2018 9:28 AM)
    Job ID
    2018-1182
    # of Openings
    1
    Category
    Engineering
  • Overview

    Abile Group has an exciting and challenging opportunity for an Information Assurance Analyst supporting an Intelligence Community Customer.

     

    Abile Group, Inc. was formed in July 2004 to partner with the Intelligence Community and their Contractors in the areas of Enterprise Analytics & Performance Management, IT & Systems Engineering and Program & Project Management. We have significant experience with the Federal Government and are an EDWOSB dedicated to our employees and clients.  We are looking for high performing employees who enjoy providing advice and guidance along with solutions development and implementation support, crafted by combining industry best practices with the clients’ subject matter experience and Abile’s breadth of expertise. Abile Group is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, veteran status, disability, or national origin.

     

    The right candidate will possess the following skills and capabilities and be ready to handle all responsibilities independently and professionally.

    Responsibilities

    • Continuous upkeep, monitoring, analysis, and response to Information System, network and security events.
    • Documents compliance actions within the approved automated compliance tracking system or develops a Plan of Actions and Milestones (POA&M) to address non-compliance in the allotted timeframe.
    • Deveop procedures and documentation to ensure compliance with configuration management (CM) for security-relevant IS software, hardware, and firmware.
    • Author all required information system security-related documentation as required by cognizant security authority and IAW RMF, NIST, SAP/SAR, ICD and published standards.
    • Ensures systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the System Security Plan (SSP), Standard Operating Procedures (SOP), and customer directives.
    • Ensures records are maintained for workstations, servers, software, routers, firewalls, network switches, crypto, and other relevant hardware/equipment throughout the information system's life cycle.
    • Evaluates proposed changes or additions to the information system, and advises senior site leadership of the security relevance.
    • Lead / conduct security IS education and training.
    • Participates in internal/external security audits/inspections; performs risk assessments and Continuous Monitoring.
    • Lead investigations/remediation of computer security violations and incidents, reporting as necessary to both the Facility Security and Senior Program Managers.
    • Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered
    • Working with the Facility Security Officer (FSO) to develop, implement and manage a formal Information Security / Information Systems Security Program.
    • Develop, implement and enforce Information Security Policies and Procedures.
    • Author, review and update IS Authorization documentation (Body of Evidence) to support IS Assessment and Authorization (Certification/Accreditation) activities.

    Qualifications

    Clearance Required: Active TS with SCI eligibility 

    Degree of Years of Experience: Bachelor's degree with 4-7 years experience or 8+ years of IA experience without a degree.

    Required Certifcations: Linux certification (RHCSA, CompTIA Linux, LCFS/LCFE, etc.)

    Desired Certifications: CEH, CHFI or GCIH 

     

    Required Skills:

    • Detailed understanding of the Risk Management Framework (RMF), NIST, ICD, and CNSS standards.
    • Familiarity with network technologies (LAN & WAN) and best practices within a classified environment to include crypto and key management
    • Expert with Microsoft Windows, Linux, and system virtualization (multiple hypervisors) in a secure network environment.
    • Must be able to work in a constantly changing regulatory environment with short, mid, and long term timelines for remediating any non-compliance
    • Must be able to work well within a team environment and able to adapt quickly to change
    • Good writing and verbal presentation skills
    • Must be able to obtain DHS Suitability or EOD

    Desired Skills: 

    • Past or Current ISSM/ISSO experience
    • DoD IS knowledge and experience

    • Background or understanding of System Security Plans (SSP)

    • Security hardening scripting/automation experience

    • Microsoft OS Certification (MCSE Win 7 or other)

    • Understanding of Sensitive Compartmented Information Facility (SCIF) standards

    • Some background in research and analysis

     

     

     

     

    SENS3 Information Assurance

    Options

    Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
    Share on your newsfeed