Cybersecurity A&A Analyst
Location: Kansas City, Missouri or Quantico VA
Overview:
We are seeking a Cybersecurity A&A Analyst to:
- Support US Marine Corps (USMC) enterprise-level hybrid cloud data center operations
- Enable USMC world-wide customers to execute critical missions
What you will do:
As a Cybersecurity A&A Analyst, you will work with a team responsible for all aspects of cybersecurity support to the hybrid-cloud enterprise hosting environment. In addition you will conduct ATO package development for the data-center. Finally, you will manage in the continuous monitoring program supporting data-center operations. In addition, you will support vulnerability analysis and self- assessment technical analysis, monitor and report compliance status, manage and maintain the accreditation packages and support plan of action and milestone (POA&M) for known security vulnerabilities. You will support 2 ISSM and an ISSO.
Responsibilities include:
- Providing technical and authorization and accreditation support
- Developing POA&M for identified vulnerabilities and developing remediation, mitigation and criticality downgrade strategies
- Supporting accreditation activities for installed and in-deployment infrastructure as well as requirements in development and engineering change proposal/pipeline processes such as developing supporting documentation and completing cybersecurity self-assessments
- Conducting vulnerability management assessments using ACAS (Tenable Nessus) and other tools including mitigation development and POA&M and documentation support
- Coordinating and collaborating with operations teams to identify solutions for vulnerability mitigation and preparing cybersecurity documentation to obtain support and approval to operate
- Preparing systems for review and independent verification and validation (self-assessments)
- Developing POA&M for identified vulnerabilities and developing remediation, mitigation and criticality downgrade strategies
- Supporting accreditation activities for installed and in-deployment infrastructure as well as requirements in development and engineering change proposal/pipeline processes such as developing supporting documentation and completing cybersecure